SSL articles
Articles on SSL/TLS certificates: expiry, rotation, automation, and monitoring so a lapsed cert never takes you offline.
-
Post-quantum TLS migration: you're probably already doing it
Post-quantum key exchange is already in a third of real HTTPS traffic and most operators never noticed. What X25519MLKEM768 actually changes, why 'harvest now, decrypt later' makes key exchange urgent today, and a practical migration path — plus the half of the problem nobody has solved yet.
-
ACME + ARI: automation that survives 47-day certificates
Surviving short-lived certificates means renewal automation that never blinks. A deep dive into ACME's challenge types and the ARI extension (RFC 9773) — how CAs now tell your client exactly when to renew, how to avoid thundering herds, and how mass revocation stops being a fire drill.
-
The 47-day certificate era
Public TLS certificate lifetimes are collapsing: 200 days today, 100 in 2027, 47 by 2029. Here's the schedule, why it's happening, and what an 8x jump in renewal frequency actually changes for the teams who run certificates.
-
Your SSL certificate is about to expire: a calm checklist
An expired TLS certificate throws a full-page security warning and can take a site down outright. Here's what to check, and how to stop it from happening by surprise.