Designing A Secure Vendor Certificate Workflow
A secure vendor workflow needs more than a login screen. Identity, network restrictions, domain scoping, one-time key handling and audit should reinforce each other.
Read Article →Practical field notes for PKI, infrastructure, security and platform teams working through shorter TLS lifetimes, segmented networks, appliance automation, private PKI and delegated certificate operations.
Focused guidance on the operational details that determine whether certificate automation works reliably in production.
A secure vendor workflow needs more than a login screen. Identity, network restrictions, domain scoping, one-time key handling and audit should reinforce each other.
Read Article →A vendor portal should reduce certificate support work without becoming a warehouse of third-party private keys. One-time key delivery and non-retention materially reduce the blast radius of a control-plane compromise.
Read Article →Public TLS validity is already shrinking. The move to 200-day certificates in 2026, 100 days in 2027 and 47 days in 2029 turns renewal automation from a convenience into core infrastructure.
Read Article →F5 BIG-IP already exposes the management surface needed for certificate automation. The safer architecture is often to orchestrate the appliance through iControl REST rather than install another agent.
Read Article →Certificate lifecycle platforms cross boundaries that application teams usually do not. Segmentation is not the problem; unclear flow ownership is. A good design keeps VLAN boundaries while permitting only the management paths the automation actually needs.
Read Article →IIS certificate renewal at scale is a Windows management problem as much as a PKI problem. Standardising WinRM, service identities and bindings turns it into repeatable infrastructure automation.
Read Article →Universities and large institutions combine decentralised ownership, old systems, research networks, vendors and modern cloud platforms. Certificate lifecycle management has to work across that diversity without centralising every application team.
Read Article →Network and virtualisation platforms each have their own certificate workflow. A central control plane can unify governance while still using each platform’s native management API and private-key model.
Read Article →New engineering articles are released on a steady cadence as we document the certificate-management problems we encounter, test and automate.