It usually starts the same way.
An application suddenly goes offline. Customers cannot log in, checkout pages fail to load, or an internal system that dozens of teams rely on grinds to a halt. Alerts start firing. A war room forms. Engineers dig through logs, checking DNS, checking the network, checking the code that was deployed last week.
Then someone finds it: an SSL/TLS certificate expired on a server nobody remembered existed.
The certificate itself wasn’t the problem. It was the fact that no one knew it was there.
This scenario plays out in IT environments every day, and as certificate lifespans continue to shrink, it is only going to happen more often — unless organizations fix the underlying issue: a lack of visibility into their own certificate ecosystem.
In our previous post, “From 398 Days to 47 Days: Why Certificate Management Can No Longer Be a Manual Process,” we covered how the CA/Browser Forum’s move to progressively shorter certificate validity periods is making manual certificate tracking untenable. This post picks up where that one left off, and addresses the question every organization should be asking next: “before we can automate certificate management, do we even know what we are managing?”
The Hidden Certificate Problem
Most organizations dramatically underestimate how many certificates they actually have in production. That is because certificates rarely live in one place, and they are rarely provisioned by one team. In a typical enterprise, certificates are scattered across:
- Web servers — public-facing and internal
- APIs and API gateways
- Load balancers and reverse proxies
- Kubernetes clusters and containerized workloads
- Cloud workloads across AWS, Azure, and Google Cloud
- Internal applications and legacy systems
- IoT devices and edge infrastructure
- Development and test environments, which are frequently forgotten once a project moves to production
Each of these is often provisioned independently — by a developer spinning up a test environment, a DevOps engineer configuring a new Kubernetes ingress, or a network admin renewing a certificate on a load balancer years ago and never documenting it. Without a centralized system of record, these certificates exist in silos, invisible to the security and IT teams who are ultimately accountable when something breaks.
This is the essence of the **certificate discovery** problem: you cannot manage, monitor, renew, or automate what you don’t know exists.
Why This Risk Is Growing
This is not a new problem, but it is becoming a far more urgent one — for two compounding reasons.
First, certificate validity periods are shrinking fast. As we discussed in our last post, the industry is moving from a 398-day maximum certificate lifespan toward a future of 47-day certificates. That is not a marginal change — it is an order-of-magnitude increase in the frequency of renewals across your entire certificate estate. A certificate you could once “set and forget” for over a year now needs attention roughly eight times a year.
Second, the number of machine identities organizations manage is exploding. Every microservice, container, API integration, and cloud workload typically needs its own certificate or machine identity. As infrastructure becomes more distributed and dynamic — especially with Kubernetes and cloud-native architectures — the sheer volume of certificates in play has grown far faster than most teams’ ability to track them manually.
Put those two trends together, and the math is unforgiving: more certificates, renewed more often, tracked by fewer people using spreadsheets and calendar reminders. That approach was already fragile at 398 days. At 47 days, it collapses.
Discovery Before Automation
It is tempting to jump straight to automation as the fix — and automation is absolutely part of the answer. But automating a process you cannot fully see just means you will efficiently miss the certificates you did not know about even faster. Discovery has to come first. A mature certificate lifecycle management (CLM) strategy typically follows this sequence:
- Discover every certificate across your environment — public and private, cloud and on-premises, production and development.
- Build a centralized inventory that serves as a single source of truth for every certificate, its location, and its expiration date.
- Identify ownership so that every certificate has a responsible team or individual attached to it — not an orphaned asset nobody is watching.
- Monitor expiration dates continuously, rather than relying on periodic manual audits.
- Classify risk based on factors like certificate exposure, criticality of the system it protects, and issuing authority.
- Automate renewals where appropriate, prioritizing high-volume, low-risk certificates first, and layering in more oversight for sensitive or customer-facing systems.
Skipping straight to step six without doing the work in steps one through five is how organizations end up automating around blind spots instead of eliminating them.
How LikeMinds Can Help
At LikeMinds, we help organizations modernize their certificate lifecycle management through assessment, discovery, automation, and ongoing managed services. As a DigiCert Managed Service Provider (MSP) Partner, we help enterprises gain complete visibility into their certificate ecosystem, automate certificate operations, and prepare for increasingly shorter certificate validity periods.
Whether you are managing certificates across on-premises infrastructure, cloud platforms, or Kubernetes environments, our team can help reduce operational risk while improving security and compliance — starting with the discovery work that makes every subsequent step possible.
Conclusion
The move to 47-day certificate lifecycles isn’t just another compliance change — it is a catalyst for modernizing how organizations manage machine identities altogether. But the first step isn’t automation. It is visibility.
Once you know what you have, you can build a secure, automated, and resilient certificate management strategy. Until then, every unmonitored certificate is a countdown timer to the next unexpected outage.
—
Need Help Discovering and Managing Your Certificates?
LikeMinds is a DigiCert Managed Service Provider (MSP) Partner with expertise in PKI, certificate lifecycle management, and machine identity security. Our team can help you assess your current environment, discover hidden certificates, implement automation, and ensure your organization is ready for the industry’s move to shorter certificate lifecycles.
Get in touch with LikeMinds to learn how we can simplify certificate management while reducing security and operational risk.