Prepare for 47-day TLS certificates
Publicly trusted certificates are limited to 200 days since March 2026, 100 days from March 2027 and 47 days from March 2029. A process that worked once a year has to work eight times a year - on every server, appliance and service that terminates TLS.
The problem
CA/Browser Forum ballot SC-081v3 shortens the maximum validity of public TLS certificates in three steps and, in 2029, limits domain-validation reuse to 10 days. Manual renewal does not get slower; it stops fitting into the calendar.
15 March 2026
Maximum validity 200 days - about two renewals a year. In effect today.
15 March 2027
Maximum validity 100 days - about four renewals a year.
15 March 2029
Maximum validity 47 days, domain validation reuse 10 days - about eight renewals a year, each with fresh validation.
Business impact
More chances to miss one
Every renewal is an opportunity for an outage. Eight per certificate per year multiplies that across the estate.
Hours that do not scale
Request, validate, install and verify - repeated per certificate - turns into a standing workload rather than an annual task.
Hidden certificates
Certificates nobody tracks are the ones that expire first. Shorter lifetimes bring that day closer.
The technical problem
Automating issuance is the easy half. ACME clients have done that for years. The hard half is everything after: getting the certificate into IIS bindings, Exchange services, NetScaler certkeys, firewall certificate stores and Kubernetes secrets, and confirming the service actually uses it.
In 2029 the 10-day validation reuse means domain control must be proven on practically every renewal. Email and manual DNS validation stop being workable; DNS-01 or HTTP-01 automation becomes the only realistic path.
The aethercert approach
Treat renewal and deployment as one job that runs without a person, on every system the certificate is used on.
- 01
Find what exists
Agents report every certificate installed on their hosts, so the inventory includes the ones nobody remembered.
- 02
Automate validation
DNS-01 through 217 DNS providers, HTTP-01 or TLS-ALPN-01 - on every issuance, without stored manual steps.
- 03
Renew on a schedule
Each certificate renews a configurable number of days before expiry; shorter lifetimes just mean more frequent unattended runs.
- 04
Deploy where TLS terminates
Signed packages install the certificate into 29 kinds of target and reload or commit them.
- 05
Watch the result
Failures and certificates nearing expiry become events and alerts.
Related features
Architecture
A hosted control plane schedules; agents on your network do the work.
Outbound-only agents
Agents poll the control plane over HTTPS. No inbound firewall rules.
Keys on your hosts
Keys are generated on the agent for every renewal and never sent to the control plane.
Appliances over their APIs
An agent on your network reaches load balancers and firewalls through their management APIs.
Integrations
Security
Fresh key per renewal
Shorter lifetimes combined with a new key each time limit the exposure of any single key.
Encrypted credentials
DNS and appliance credentials are encrypted at rest and released to agents only for the job that needs them.
Audit trail
Every issuance, deployment and configuration change is recorded with its actor.
Implementation considerations
Start with inventory
Install agents on the servers that matter and let discovery show which certificates exist before changing anything.
Move validation to DNS-01
Connect the DNS provider for each domain; it also enables wildcards.
Pick a renewal window
30 days before expiry is the default. With 47-day certificates, a shorter window such as 15 days keeps renewals from running back to back.
Cover appliances explicitly
Load balancers and firewalls are usually where manual steps hide. Check each against the integrations list.
Frequently asked questions
47-day certificates
Do internal certificates have to follow the 47-day schedule?
No. SC-081v3 applies to publicly trusted TLS certificates. Certificates from your own CA - for example AD CS through the CA connector - follow your own policy, and aethercert renews them the same way.
What renewal window should I use for 47-day certificates?
A window shorter than the default 30 days - for example 15 days - so that a certificate is not renewed again almost immediately after issuance. The window is configurable from 1 to 90 days.
Do I need to change anything when the limits drop?
Not in aethercert. Renewal is driven by each certificate's actual expiry date, so shorter certificates simply renew more often.
Get ahead of the 2027 deadline
Start with an inventory of what you have, then automate it one target at a time.
Community plan, no card required. Open registration - your account is ready in a few minutes.