{
  "id": 13484427,
  "title": "Internal certificate authorities fail on lifecycle, not on cryptography",
  "url": "https://urgent.news/2026/10/10/internal-certificate-authorities-fail-on-lifecycle-not-on-cryptography",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T18:00:43.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/stark_zhuang_df5076f35c68/internal-certificate-authorities-fail-on-lifecycle-not-on-cryptography-27ac"
  },
  "original_language": "en",
  "account": "Internal certificate authorities often fail due to lifecycle management issues, not cryptographic problems. When a certificate expires over the weekend without anyone noticing, the first shift can't connect to the network. Public PKI rules don't apply to internal PKI, giving organisations complete control over validity periods and verification policies. This freedom, however, leads to certificate sprawl as each team operates independently without a complete picture of the estate. Internal CAs also inherit the challenge of updating trust stores when the root changes, affecting not just the CA team but all clients, operating systems, appliances, and third-party services. The most common failure modes are invisible certificates, incomplete renewals, and trust store lag. To reduce risks, set validity periods from the endpoints, plan root changes as a programme, automate leaf renewal, control the root, and ensure the inventory includes owners, service dependencies, and expiry dates. Monitoring and revocation are crucial, but limited by the lack of a distribution path. Overall, a structured approach to internal PKI governance, with clear ownership, automated processes, and deliberate planning, can mitigate these risks.",
  "summary": "Internal certificate authorities fail on lifecycle, not on cryptography The Monday morning outage that follows a certificate expiry is almost never a cryptographic failure. It is an ownership failure. A RADIUS certificate on a Wi-Fi authentication server expires over a weekend, nobody knows it exists, and the first shift cannot connect. Why internal PKI drifts Public certificate rules do not…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}