Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

47-day certificates: are your machine identity controls ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19453
Topic starter  

TL;DR: The CA/Browser Forum’s phased move to 47-day TLS certificates turns machine identity management from a renewal task into an operational resilience problem, according to Thryam. Manual tracking, partial automation, and incomplete visibility cannot sustain the new cadence, which makes discovery, inventory, and end-to-end automation the real control plane.

NHIMG editorial — based on content published by Thryam: 47-Day Countdown: Why Machine Identity Is Critical Now

By the numbers:

Questions worth separating out

Q: What breaks when machine identity lifecycle management is still partly manual?

A: Manual lifecycle management breaks first at scale.

Q: Why do shorter certificate lifetimes matter for workload identity governance?

A: Shorter lifetimes matter because they force teams to manage trust as a continuous identity lifecycle rather than a periodic admin task.

Q: How do you know if machine identity automation is actually working?

A: Automation is working when it reduces manual intervention, shortens renewal and revocation latency, and produces continuous evidence of control.

Practitioner guidance

  • Build a complete machine identity inventory Enumerate certificates, SSH keys, and other cryptographic assets across on-prem, cloud, containers, and edge systems, then assign durable ownership for each asset.
  • Automate end-to-end certificate lifecycle operations Connect discovery, renewal, deployment, and revocation so that known certificates are handled without manual handoffs or spreadsheet tracking.
  • Separate known assets from unknown exceptions Track orphaned certificates, wildcard reuse, and undocumented deployments as explicit remediation items with service owners and deadlines.

What's in the full article

Thryam's full article covers the operational detail this post intentionally leaves for the source:

  • The phased CA/Browser Forum timeline for March 2026, March 2027, and March 2029 certificate validity changes.
  • The staffing math behind renewals at scale, including the 1,000-certificate example and manual effort growth.
  • The distinction between TLS certificate risk, SSH key sprawl, and broader cryptographic discovery gaps.
  • The article's practical guidance on end-to-end automation across discovery, monitoring, procurement, and deployment.

👉 Read Thryam’s analysis of the 47-day TLS certificate transition and machine identity risk →

47-day certificates: are your machine identity controls ready?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19044
 

47-day certificate validity is really a machine identity governance deadline: The reduction in TLS lifespan is not the central story. The real issue is that machine identity governance now has to operate at a cadence that exposes every ownership gap, every undocumented dependency, and every missed renewal path. That makes discovery and lifecycle control the decisive controls, not the certificate format itself.

A few things that frame the scale:

  • Only 38% have automated certificate lifecycle management in place, according to The Critical Gaps in Machine Identity Management report.
  • Manual handling remains the norm for machine identity operations, which is why renewal pressure turns into outage risk instead of routine maintenance.

A question worth separating out:

Q: Who is accountable when an expired certificate causes a service outage?

A: Accountability sits with the team that owns certificate lifecycle governance, not only with infrastructure operations. The failure usually reflects missing ownership, weak inventory, and lack of automated renewal controls, which makes the issue a programme problem as much as a technical one.

👉 Read our full editorial: Machine identity management breaks under 47-day certificate cycles



   
ReplyQuote
Share: