Transport Layer Security (TLS) certificates, often known as SSL certificates, secure Internet connections by encrypting data to protect it against modification or theft. The technology is essential but is also the root cause of outages when certificates expire without being renewed.
When TLS certificates were initially introduced renewal was a manual process with certificates often having yearly expiration periods. Now the certificate industry has recognised that shorter lifespans make it harder for attackers to compromise certificates, but with shorter lifespans the risk with manual certificate renewals increases.
Looking ahead, Let’s Encrypt, one of the key players in the certificate market, has announced that in 2025 it plans to make certificates with a lifetime of six days available. “This is a big upgrade for the security of the TLS ecosystem because it minimizes exposure time during a key compromise event,” says Let’s Encrypt Executive Director, Josh Aas.
How should organizations response to this resilience opportunity and challenge? The answer is to scrap manual renewals completely and embrace automation, says Kevin Bocek, Chief Innovation Officer, at Venafi, a CyberArk company.
Here, Kevin explains more about the Let’s Encrypt announcement and its implications:
“Let’s Encrypt announcing that it will be offering 6 day certificates from next year is a clear signal to where the market is moving. There has been growing momentum around shorter certificate lifecycles – with Google having stated its intention to shorten the lifespan of public TLS certificates used with Chrome from 398 days to 90 days, and Apple directing a vote among Certification Authority Browser Forum (CA/B Forum) members, to cut certificate lifespans to 47 days by 2028. And with good reason. Certificate lifespans are currently far too long, which increases the likelihood that they will be compromised – over half (57%) of organizations have experienced security incidents involving compromised TLS certificates in the past year. Shortening certificate lifespans will help businesses reduce that risk.
“Let’s Encrypt has boomed in popularity with developers over the last few years, as it gives developers a quick, free and easy way to issue TLS machine identities for all manner of critical web services – from websites to customer applications. In offering this new service, Let’s Encrypt is throwing down the gauntlet to other Certificate Authorities (CAs) to follow suit. Yet to take advantage of this new service and others like it, businesses will need the right processes and tools in place. Automation is essential if you want to rotate certificates every six days. However, recent research shows that many aren’t. When asked recently about their views on Google’s proposal to reduce certificate lifespans to 90 days, 81% of security leaders believe it will amplify existing challenges they have around managing certificates, with nearly three-quarters (73%) saying it could cause ‘chaos’ and a further 75% saying it could even make them less secure. Worryingly, 77% think more outages are ‘inevitable’.
“One of the reasons that so many companies are feeling alarmed is that they do not have the right tools and resources in place to manage their machine identities at scale. Just 8% of organizations fully automate all aspects of TLS certificate management across the entire enterprise – with almost a third (29%) still relying on their own software and spreadsheets to manage the problem. As a result, organizations take 2-3 working days (21 and ¾ hours) to manually deploy a certificate. While shortening certificate lifecycles helps reduce some risks and is a step in the right direction, it also brings added complexity for security teams. We’re not just dealing with minor red flags here – we’re seeing problems everywhere, from the cloud to virtual machines and Kubernetes clusters. It’s not just one vendor’s issue; it’s the entire Internet at stake. The good news is this is a solvable problem. Security teams can get certificate lifecycle management (CLM), PKI-as-a-service and workload identity issuers all on one control plane now.”






