Home › Blog

**Every Certificate You Own Expires Six Times A Year Now** Meanwhile, In The Part Of The I

**EVERY CERTIFICATE YOU OWN EXPIRES SIX TIMES A YEAR NOW**

MEANWHILE, in the part of the internet nobody photographs.

April 2025. The CA/Browser Forum passed Ballot SC-081v3. Twenty-nine votes in favour, none against. Proposed by Apple, sponsored by Sectigo, backed by every browser root programme.

Public TLS certificate lifetimes go from 398 days to 47.

15 March 2026 — 200 days. This is live. You are in it now.
15 March 2027 — 100 days. Seven months out.
15 March 2029 — 47 days.

47 is not a round number on purpose. Round numbers get renewed by a person with a spreadsheet and a calendar invite. Renew at two thirds of life and you land on day 30, which is a monthly cadence, which is a cron job. The number was chosen to make manual management impossible rather than merely unpleasant.

The reasoning is unglamorous. Revocation does not work. CRLs are too large to distribute, OCSP leaks browsing behaviour, and browsers soft-fail when the check times out — so a revoked certificate stays useful. Nobody fixed revocation. They shortened validity until revocation stopped mattering. Expiry is now the control.

The second half of the ballot gets less attention and will hurt more. Domain control validation reuse falls from 398 days to 10. You are not only reissuing certificates. You are re-proving domain ownership, continuously, forever, including for the zones administered by a supplier who answers email on Tuesdays.

The arithmetic: a hundred public certificates is roughly eight hundred renewals a year. That is not a PKI workload. That is a platform.

None of it applies to internal PKI. The Baseline Requirements cover servers reachable from the internet. Your private CA is untouched — worth establishing early, before somebody scopes the whole estate.

Three questions before March.

Do you have an inventory, or do you have a list someone maintains?

Does it include appliances, load balancers, service-to-service mutual TLS, and the integration a supplier installed in 2019?

What is the longest-lived certificate you own that cannot be automated, and who owns the box it lives on?

The last one is the finding. Every estate has a device where the renewal procedure is a named individual, a laptop, and a login that only works from the office. It has survived this long because the interval was a year and the year was somebody else's problem. The interval is now measured in weeks.

Nobody will announce this. It arrives as an outage, on a Sunday, on the thing you forgot was public.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing