Session
Surviving 47-Day Certificate Lifetimes with PowerShell
By March 2029, public TLS certificates will live at most 47 days. That is twelve renewals a year for every certificate you own, and renewing by hand stops being an option long before then. To understand why this is happening, and what to do about it, you need to know how public PKI actually works and how badly it's been misbehaving.
The first half of this session is the story of the certificate authorities. The deal we all made with the CAs and how it went wrong, the failures that broke trust, and why the CA/Browser Forum is being forced to shorten lifetimes no matter how much everyone complains.
The second half is what you can do about it with PowerShell, live. We issue and renew a certificate with Posh-ACME, and delegate DNS challenges so validation does not require handing over your whole zone. Then we map what stands between that demo and real automation. Getting renewed certificates onto IIS, Exchange, and the appliances that fight back. Keeping private keys safe. Catching the renewal that silently fails. You will leave with working issuance, a map of the remaining problems, and a fair sense of how much of this lifecycle you want to own yourself.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top