Foundational practices (every tier)
- Inventory first. One source of truth (CLM tool or spreadsheet): FQDN/SANs, device, owner, rotation method, expiry, last rotation, dependencies. External attack-surface scans and CT-log monitoring catch what the inventory misses.
- Plan for 200 days now, 47 days later. Public certs issued after 15 March 2026 max out at 200 days, dropping to 100 (2027) and 47 (2029). Anything that cannot be automated by 2027 should be re-architected or accepted as a recurring manual cost.
- New key pair every renewal. Never reuse private keys; never renew by CSR reuse on appliances that permit it.
- Install the full chain, not the root. Leaf + intermediates. Missing intermediates are the top cause of "works in Chrome, fails on mobile/Java".
- Prefer SAN certs over wildcards on edge appliances. Wildcards sprawl and leave one private key on many devices. Reserve them for dynamic hostnames (Kubernetes ingress, PaaS, S3 virtual-host style).
- Key type. RSA 2048 for VPN clients, RADIUS supplicants and legacy UC; ECDSA P-256 for pure web.
- CAA records limiting issuance to your CAs; DNS-01 API tokens scoped and vaulted.
- Staging and rollback. Test in lab or on the standby HA node first; vault the previous PFX/key (Secret Server) for 30 days; do not revoke the old cert unless the key was exposed.
- Monitoring. Alert at 30/14/7 days on every exposed endpoint, independent of the CLM tool; validate externally after each change (SSL Labs, openssl s_client, a mobile device).
- Change control. Multi-surface devices get a dedicated window and written runbook; single web servers can be standing changes.
Cross-cutting runbook checklist
- Pull the new PFX/PEM from the vault; never generate keys on operator laptops.
- Confirm SANs against every hostname the device answers for (portal, gateway, autodiscover, cluster peers).
- Import the intermediate chain.
- Rebind on every surface listed in the device runbook.
- Repeat on the HA peer or every cluster node.
- Restart only what the runbook requires, inside the change window.
- Verify from outside the network and from a mobile device; compare served fingerprint to the issued cert.
- Remove the old certificate after 24–72 hours.
- Update the inventory / CLM record and close the ticket.
Maximum public certificate lifetime (CA/Browser Forum)
Recommended sequencing
- Inventory and tag every endpoint with a tier (one to two weeks).
- Convert Tier A candidates to ACME: quick wins, low risk.
- Stand up or extend a CLM platform; onboard Tier B appliances, starting with HA pairs that carry the most bindings (F5/NetScaler, PAN-OS, FortiGate, ISE).
- Pull OOB/OT devices off the public edge; front remaining Tier C apps with a Tier A/B proxy where possible.
- Write and dry-run Tier C runbooks; vault all keys.
- Audit Tier D for CAA and validation-record dependencies and monitoring coverage.
- Set a 2027 deadline: anything still in Tier C either has a signed-off runbook with monthly capacity or is re-architected before 100-day lifetimes land.