Public Certificate Rotation Dashboard

Inventory, rotation tiers and per-device runbooks for every internet-facing TLS surface

Foundational practices (every tier)

Cross-cutting runbook checklist

  1. Pull the new PFX/PEM from the vault; never generate keys on operator laptops.
  2. Confirm SANs against every hostname the device answers for (portal, gateway, autodiscover, cluster peers).
  3. Import the intermediate chain.
  4. Rebind on every surface listed in the device runbook.
  5. Repeat on the HA peer or every cluster node.
  6. Restart only what the runbook requires, inside the change window.
  7. Verify from outside the network and from a mobile device; compare served fingerprint to the issued cert.
  8. Remove the old certificate after 24–72 hours.
  9. Update the inventory / CLM record and close the ticket.

Maximum public certificate lifetime (CA/Browser Forum)

Recommended sequencing

  1. Inventory and tag every endpoint with a tier (one to two weeks).
  2. Convert Tier A candidates to ACME: quick wins, low risk.
  3. Stand up or extend a CLM platform; onboard Tier B appliances, starting with HA pairs that carry the most bindings (F5/NetScaler, PAN-OS, FortiGate, ISE).
  4. Pull OOB/OT devices off the public edge; front remaining Tier C apps with a Tier A/B proxy where possible.
  5. Write and dry-run Tier C runbooks; vault all keys.
  6. Audit Tier D for CAA and validation-record dependencies and monitoring coverage.
  7. Set a 2027 deadline: anything still in Tier C either has a signed-off runbook with monthly capacity or is re-architected before 100-day lifetimes land.