Start with Identity
← Glossary
Concept

Certificate Lifecycle Management

Discovering, issuing, renewing, and revoking TLS and other certificates across an organization. Automation matters because expired or unmanaged certificates cause outages and create machine-identity risk.

Certificate expiry is one of the few identity failures that causes a visible outage rather than a quiet compromise, which is why it gets budget. As lifetimes shorten toward 47 days under the CA/Browser Forum schedule, manual renewal stops being viable and automation becomes mandatory. The identity angle is that a certificate is a machine credential: the same questions about ownership, rotation, and revocation apply as for any other non-human identity.

See also: PKI, X.509, mTLS, what is machine identity

Related terms
Last reviewed By SWI Community TeamSuggest a correctionHow we research