Blog about digital certificates, CAs, and security

Security

Trust Lifecycle Manager: Certificate Management as a Jigsaw Puzzle

Certificate management follows the same old pattern in many organizations: an Excel spreadsheet tracking expiration dates, email reminders nobody reads, and the occasional panic when a certificate expires on a production service no one even knew existed.…

Jul 29, 2026 | Jindřich Zechmeister

From the latest articles

Recently

The ACME CAA extension becomes mandatory

Starting in March 2027, all certificate authorities will be required to support the ACME CAA extension. What does this mean for TLS/SSL certificate issuance, and how does the extended CAA record work in practice?

Jun 26, 2026 | Petra Salašová

Recently

Mandatory record in Certificate Transparency for all new TLS certificates

Starting June 1, 2026, DigiCert will log all newly issued public TLS certificates, including reissued certificates, to Certificate Transparency (CT) logs. This change applies to all certificates issued by DigiCert certificate authorities, regardless of validation…

Jun 5, 2026 | Petra Salašová

Recently

Spring changes in root/intermediate certificates

During April and May 2026, selected root and intermediate certificates within the Mozilla and DigiCert ecosystems will be revoked. This article summarizes the reasons for these changes and their practical implications.

Apr 8, 2026 | Jindřich Zechmeister

SSLmarket news

Shortening Certificate Validity: Automation is a Must

The TLS certificate landscape is changing rapidly. Shorter lifetimes and increased pressure for automated validation are reshaping current practices. With early changes from DigiCert and Google pushing automatic domain validation, automation is no longer…

Jan 23, 2026 | Jindřich Zechmeister