Urgent.News

What's breaking now, across thousands of outlets.

Tech

Internal certificate authorities fail on lifecycle, not on cryptography

Internal certificate authorities fail on lifecycle, not on cryptography The Monday morning outage that follows a certificate expiry is almost never a cryptographic failure. It is an ownership failure. A RADIUS certificate on a Wi-Fi authentication server expires over a weekend, nobody knows it exists, and the first shift cannot connect. Why internal PKI drifts Public certificate rules do not…

Internal certificate authorities often fail due to lifecycle management issues, not cryptographic problems. When a certificate expires over the weekend without anyone noticing, the first shift can't connect to the network. Public PKI rules don't apply to internal PKI, giving organisations complete control over validity periods and verification policies.

This freedom, however, leads to certificate sprawl as each team operates independently without a complete picture of the estate. Internal CAs also inherit the challenge of updating trust stores when the root changes, affecting not just the CA team but all clients, operating systems, appliances, and third-party services. The most common failure modes are invisible certificates, incomplete renewals, and trust store lag.

To reduce risks, set validity periods from the endpoints, plan root changes as a programme, automate leaf renewal, control the root, and ensure the inventory includes owners, service dependencies, and expiry dates. Monitoring and revocation are crucial, but limited by the lack of a distribution path. Overall, a structured approach to internal PKI governance, with clear ownership, automated processes, and deliberate planning, can mitigate these risks.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Saturday 10 October →