Resources

Certificate management in practice: guides for IT teams and compliance managers

Articles for those responsible for certificates, TLS compliance, and supplier documentation — written by people who know the pain of manual processes and audit pressure.

Compliance & regulation

DORA, NIS2, ISO 27001 and GDPR — what auditors expect from certificate management.

DORA

DORA for Banks: What Compliance Requires in Practice

Published May 25, 2026

Banks are core entities under DORA. What compliance requires in practice — from ICT risk management and third-party risk to certificate and TLS documentation.

Read article →
DORA

DORA Audit Requirements: What Auditors and Supervisors Expect

Published May 20, 2026

DORA requires documentable ICT risk management. What auditors and supervisors typically ask for — and how certificate documentation fits a DORA audit.

Read article →
DORA

DORA Implementation: How Financial Entities Get Started

Published May 14, 2026

A practical sequence for DORA implementation — from an ICT asset overview and gap analysis to ongoing documentation and testing.

Read article →
DORA

DORA Requirements: The Five Pillars Explained

Published April 30, 2026

DORA's requirements pillar by pillar — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing — and where certificates fit in.

Read article →
DORA

What Is DORA? A Guide to the EU Regulation for Financial Entities

Published April 16, 2026

DORA (Regulation EU 2022/2554) sets requirements for financial entities' digital operational resilience from 17 January 2025. What it is, who it covers, and what it requires.

Read article →
CISO · NIS2

NIS2 Supervision: The Technical Certificate Documentation Your CISO Must Have Ready

Published April 15, 2026

Supervisory authorities have a checklist. Here is what they specifically ask about certificates and TLS — and what you should have documented before they come knocking.

Read article →
Finance · DORA

DORA and NIS2 for Financial Services: TLS Certificate Requirements in One Overview

Published April 8, 2026

Banks and insurers must comply with both DORA and NIS2 — with overlapping and at times conflicting requirements. Here is what specifically applies to TLS certificates and cryptography management.

Read article →
Compliance

Expired Certificate, Disabled Encryption: When It Becomes a GDPR Incident

Published March 27, 2026

If TLS encryption fails in transit because of an expired certificate, it can trigger a 72-hour notification obligation under GDPR — and this is not a hypothetical situation. Here is when that line gets crossed.

Read article →
Audit · Compliance

Certificate Audits: Exactly What ISO 27001 and NIS2 Auditors Check

Published March 25, 2026

ISO 27001, NIS2, and internal audits ask concrete questions about TLS certificates. Here is the checklist and what leaves a strong impression.

Read article →
Compliance · ISO 27001

ISO 27001 and TLS: Which Controls Auditors Test — and What Impresses Them

Published March 13, 2026

Annex A controls on cryptography (A.10) and asset management (A.8) have direct implications for certificate management. Here is what auditors test — and the documentation that makes the difference.

Read article →
Compliance · NIS2

NIS2 and Certificate Management: Three Requirements That Directly Affect Your TLS Setup

Published March 6, 2026

NIS2 requires documented asset inventory, incident response, and supply chain security. TLS certificates sit at the intersection of all three — and are the area most often unprepared at audit time.

Read article →

Certificate management & operations

Inventory, monitoring, renewal and avoiding outages at scale.

Product · Operations

ACME Server and ARI: Zero-Touch Certificate Renewal for Internal Servers

Published May 20, 2026

CertControl now ships an ACME Server (RFC 8555) and ARI (RFC 9773). Internal Linux and Windows servers running certbot, acme.sh, or win-acme renew automatically — with coordinated fleet renewals and one-click mass-revocation signalling.

Read article →
Operations

Certificate Expiry Alerts: How to Set Up Notifications That Actually Work

Published April 24, 2026

Most expiry outages happen not because no alert was set up — but because it reached the wrong person, or nobody at all. Here is the three-layer alert strategy that actually holds.

Read article →
Guide

TLS Certificate Monitoring: What It Is, Why It Matters, and How to Automate It

Published April 24, 2026

TLS monitoring is not the same as a calendar reminder for expiry dates. It is continuous automated scanning that covers all the ways a certificate and TLS configuration can fail — and alerts you before it happens.

Read article →
PKI · Economics

47-Day Certificate Lifetimes: Calculate the Real Process Cost for Your Organisation

Published April 22, 2026

By 2029 every certificate expires after 47 days. For organisations relying on manual renewal, that means 7–8x more work. Here is the calculation — and when automation pays for itself.

Read article →
Operations

Supplier Certificates: The Third-Party Risk That Falls Into No Man's Land

Published April 16, 2026

When a supplier's certificate expires, your integration breaks — and your on-call phone rings. You got no warning and cannot renew it for them. Here is how you get visibility anyway.

Read article →
Operations · CDN

Why an Expired CDN Certificate Hits Harder Than a Server Certificate

Published April 10, 2026

An expired certificate on your CDN edge takes down all traffic behind it — not just one endpoint. Here is why edge certificates are systematically overlooked, and what you do about it.

Read article →
Operations

Postmortem: The Certificate That Took Down a Login Flow — and What It Cost

Published April 10, 2026

A realistic postmortem analysis: how certificate expiry gets past every warning, what it costs to discover in production, and which process changes prevent a recurrence.

Read article →
Operations

How to Manage Certificates During a Cloud Migration

Published April 3, 2026

During a cloud migration, endpoints, tooling, and ownership all change — while certificates quietly keep expiring. Here is how to handle the certificate dimension without causing outages mid-migration.

Read article →
Guide

What Is Certificate Lifecycle Management? A Plain-Language Guide

Published March 19, 2026

CLM covers the end-to-end process of managing TLS certificates — from discovery and issuance through monitoring and renewal. This guide explains what the category actually includes and what to look for when evaluating CLM software.

Read article →
Operations

47-Day Certificate Lifetimes: What Your Processes Need Before 2029

Published January 23, 2026

The CA/Browser Forum has voted: from 2029 certificates are valid for a maximum of 47 days. Manual renewal will not hold. Here is what the transition requires — and how ACME automation makes it manageable now.

Read article →
Guide

Build a Complete TLS Certificate Inventory: What Most Organisations Are Missing

Published January 9, 2026

Most teams think they have an overview — then discover blind spots during audits or outages. Here is the methodology for a complete inventory that actually keeps pace with infrastructure changes.

Read article →
Guide

Automatic Supplier Certificate Tracking: From Spreadsheet to a Process That Holds

Published December 11, 2025

Spreadsheets tracking supplier certificates become stale faster than they get updated. Here is how to build a process that automatically keeps pace — and gives auditors the documentation they ask for.

Read article →
Comparison

Manual vs. Automated Certificate Management: What It Actually Costs to Choose Wrong

Published December 4, 2025

Manual certificate tracking does not scale and fails predictably under pressure. Here is a direct comparison of workload, risk profile, and what is genuinely saved by automating.

Read article →
Guide

Avoiding Certificate Expiry: The Structured Approach That Actually Prevents Outages

Published November 27, 2025

Certificate expiry is almost always a process failure, not a technical one. Here is the structured system that ensures no certificate slips through the cracks — in day-to-day operations or at audit time.

Read article →

Automation & DevOps

ACME, cert-manager and TLS on nginx, Apache, Azure and F5 — issuing and rotating certificates without downtime.

DevOps · Load balancing

TLS on F5 BIG-IP

Published May 2, 2026

Client SSL and Server SSL profiles, cert-key objects, offloading vs bridging — and where the certificates live.

Read article →
DevOps · Cloud

TLS on Azure

Published April 30, 2026

Application Gateway and Front Door: managed certificates, custom domains, listeners and end-to-end TLS.

Read article →
DevOps · Architecture

Offloading vs passthrough vs bridging

Published April 28, 2026

Where TLS is decrypted with offloading, passthrough and bridging — and what it means for certificates and security.

Read article →
DevOps · Servers

TLS on Apache httpd

Published April 26, 2026

SSLCertificateFile, SSLProtocol, SSLCipherSuite, stapling and HSTS — a commented VirtualHost.

Read article →
DevOps · Servers

TLS on nginx: best-practice setup

Published April 24, 2026

Fullchain, modern protocols and ciphers, OCSP stapling and HSTS — a commented nginx configuration.

Read article →
DevOps · Kubernetes

cert-manager explained

Published April 22, 2026

Issuer, ClusterIssuer, Certificate and Secret — and ACME HTTP-01 vs DNS-01 — with YAML examples.

Read article →
DevOps · Operations

Certificate rotation without downtime

Published April 20, 2026

Reload vs restart, graceful reload, rotation behind load balancers and Kubernetes secrets — without dropping connections.

Read article →
DevOps · Automation

Automate certificates with ACME

Published April 18, 2026

Why 90-day lifetimes make automation mandatory — and how certbot, win-acme, lego and cert-manager solve it.

Read article →

Risk & attack surface

Shadow IT, supplier risk and how attackers use your certificate data.

Security

How Attackers Map Your Infrastructure Using Certificate Data — and What You Do About It

Published April 3, 2026

Before sending a single packet, attackers have a complete picture of your subdomains, exposed services, and forgotten infrastructure — all from public certificate logs. Here is the method, and the counter-move.

Read article →
Security

Detect Phishing Sites Abusing Your Domain — Before Your Users Reach Them

Published March 20, 2026

A phishing site targeting your brand can be live within the hour. The TLS certificate it is issued with is logged publicly the moment it appears — that is the early warning most teams never set up.

Read article →
Security

Shadow IT Certificates: Find What Your IT Department Doesn't Know About

Published February 20, 2026

Developers spin up services and obtain certificates without informing IT. Certificate Transparency logs keep the receipts — and so does CertControl.

Read article →
Security

Dangling DNS: How Forgotten Subdomains Become Security Incidents

Published February 6, 2026

Your team removed the cloud resource but forgot the DNS record. Now anyone can claim it and serve content under your domain — including phishing and malware. Here is how subdomain takeover works and how to find your exposure.

Read article →

Certificates & CAs explained

The fundamentals: certificate types, CAs, chains and how trust works.

Explainer

Which CA Should You Choose? The Let's Encrypt Misconception

Published June 1, 2026

Is Let's Encrypt less secure than an expensive CA? No. Understand DV, OV and EV, the pros and cons of the major certificate authorities — and why the priciest CAs are historically the ones that got distrusted.

Read article →
Explainer · CA

How Much Does an SSL Certificate Cost?

Published May 27, 2026

Most certificates are free. What you actually pay for with OV/EV, why free is just as secure, and where the real cost hides.

Read article →
Comparison · CA

Best Free SSL/TLS Providers

Published May 20, 2026

Let's Encrypt, ZeroSSL, Buypass, Google Trust Services and SSL.com compared — all free, all ACME, all equally trusted.

Read article →
Comparison · CA

Let's Encrypt vs ZeroSSL

Published May 13, 2026

Two popular free CAs compared on price, ACME/EAB, OV/EV, API and support — and when each one wins.

Read article →
CA guide

SSL.com Explained

Published May 6, 2026

The full range under one roof: ACME with EAB, free DV plus OV/EV, and code and document signing. When SSL.com makes sense.

Read article →
CA guide

Google Trust Services Explained

Published April 29, 2026

Free DV certificates from Google's own CA via ACME (with EAB) — available to everyone, not just Google Cloud.

Read article →
CA guide

Buypass Go SSL Explained

Published April 22, 2026

The European free CA: free DV via ACME from a Norwegian CA, historically longer lifetimes, and when EU roots matter.

Read article →
CA guide

ZeroSSL Explained

Published April 15, 2026

Free DV via ACME (with EAB) plus paid OV/EV plans and a REST API. What ZeroSSL offers, and how it differs from Let's Encrypt.

Read article →
CA guide

Let's Encrypt Explained

Published April 8, 2026

The world's most widely used CA: free DV via ACME, wildcard via DNS-01, and what the rate limits mean in practice.

Read article →
Explainer · Expiry

Why Do Certificates Expire?

Published April 2, 2026

Expiry is not a bug but a security feature. Why certificates expire, why lifetimes are shrinking, and how to avoid downtime.

Read article →
Explainer · Fundamentals

What Is a CSR?

Published March 31, 2026

The file you send a CA to get a certificate: what it contains, why the private key stays home, and how ACME makes it invisible.

Read article →
Explainer

OCSP and Certificate Revocation: Why It Does Not Work the Way Most People Think

Published March 27, 2026

Revocation sounds like an instant security valve. In practice, most browsers choose to fail open when the OCSP responder is unreachable — and compromised certificates remain functional. Here is what revocation actually gives you.

Read article →
Explainer · Certificate types

DV vs OV vs EV Explained

Published March 17, 2026

Three validation levels, same encryption. What DV, OV and EV each prove — and why the EV badge disappeared from the browser.

Read article →
Explainer · Certificate types

Single-Domain vs Wildcard vs SAN

Published March 11, 2026

One domain, all subdomains, or a list? What each coverage type covers, the blast-radius trade-off, and when to choose which.

Read article →
Explainer · PKI

What Is a Certificate Authority (CA)?

Published March 5, 2026

The trusted third party behind every certificate: what a CA does, how roots and intermediates connect, and what happens when trust is lost.

Read article →
Explainer

The Certificate Chain: What Actually Happens When an Intermediate Is Missing

Published February 27, 2026

Missing intermediate certificates, expired chain links, and cross-signed roots produce errors that work in Chrome, fail in curl — and are nearly impossible to debug without understanding the chain. Here is the model.

Read article →
Explainer · Fundamentals

SSL vs TLS: What's the Difference?

Published February 24, 2026

SSL is obsolete, TLS is current — yet we still say 'SSL certificate'. Here is the difference and which versions are safe today.

Read article →
Guide

CAA DNS Records: Five Minutes of Work That Blocks Unauthorised Certificate Issuance

Published February 13, 2026

Without a CAA record, any of the 100+ publicly trusted CAs can issue certificates for your domain. It takes five minutes to close that gap. The vast majority of organisations have not done it yet.

Read article →
Explainer · Fundamentals

What Is a TLS/SSL Certificate?

Published February 12, 2026

The small data file behind the padlock: what a certificate contains, how trust is established, and why it always has an expiry date.

Read article →
Explainer · Certificate types

Types of SSL/TLS Certificates

Published February 5, 2026

Validation vs coverage: DV/OV/EV, single/wildcard/SAN, plus self-signed and signing. The full picture and when to use which.

Read article →
Explainer

Wildcard Certificates: Convenient but Riskier Than You Think

Published January 30, 2026

One certificate, one private key, every subdomain. The convenience is real — but if that key is compromised, your entire subdomain surface is exposed at once. That is the price of simplicity.

Read article →
Explainer

What Is Certificate Transparency — and Why Your Certificates Are Public

Published January 16, 2026

Every TLS certificate issued for a public domain is logged permanently and publicly — by design, not by accident. Here is how CT logs work, and how to use them to monitor your attack surface.

Read article →

TLS, HTTPS & protocols

How TLS actually works — handshake, versions, HSTS, SNI and stapling.

Protocols · TLS

OCSP stapling explained

Published June 1, 2026

The server delivers a fresh revocation response in the handshake itself — faster for the user and without leaking to the CA who visits the site.

Read article →
Protocols · TLS

What is HSTS?

Published May 31, 2026

Always force HTTPS — how the header works, what includeSubDomains and preload mean, and the pitfalls that can lock a domain out.

Read article →
Protocols · TLS

What is SNI?

Published May 29, 2026

How one IP can present the right certificate for many domains — and why SNI still reveals which domain you visit.

Read article →
Protocols · TLS

Perfect Forward Secrecy

Published May 27, 2026

Why a leaked private key cannot decrypt past traffic — ephemeral ECDHE explained, and how to ensure it.

Read article →
Protocols · TLS

HTTPS explained

Published May 25, 2026

HTTP on top of TLS — what the padlock protects (confidentiality, integrity, identity) and the four things it does not guarantee.

Read article →
Protocols · TLS

Disable TLS 1.0 and 1.1

Published May 23, 2026

Obsolete, vulnerable and excluded from compliance — why the old protocols must be turned off, and the config that does it.

Read article →
Protocols · TLS

TLS 1.2 vs TLS 1.3

Published May 21, 2026

A faster handshake, always-on forward secrecy and a stack of removed weak algorithms — and what you should configure.

Read article →
Protocols · TLS

TLS handshake explained

Published May 19, 2026

Client Hello, Server Hello, key exchange and session keys — step by step, plus why TLS 1.3 does it in a single round-trip.

Read article →

mTLS & Zero Trust

Mutual TLS for service-to-service identity, Kubernetes and Zero Trust.

mTLS · API Security

mTLS vs OAuth2 client credentials

Published May 17, 2026

Transport layer vs application layer for machine-to-machine — and when to combine them.

Read article →
mTLS · Browsers

Client certificates in browsers

Published May 16, 2026

Installation, the .p12 format, the certificate prompt and why the UX rarely scales.

Read article →
mTLS · Troubleshooting

Troubleshooting mTLS

Published May 14, 2026

Wrong CA, expired client cert, missing EKU, incomplete chain — five causes and the fix.

Read article →
mTLS · Zero Trust

mTLS and Zero Trust

Published May 12, 2026

Why "never trust the network" requires cryptographic identity on every connection.

Read article →
mTLS · Architecture

mTLS: gateway to backend

Published May 10, 2026

So the backend only accepts traffic from the gateway. Concrete setup in nginx and Envoy.

Read article →
mTLS · Kubernetes

mTLS in Kubernetes

Published May 8, 2026

Service mesh, cert-manager and SPIFFE — three routes to mTLS in a cluster, with YAML that works.

Read article →
mTLS · Fundamentals

mTLS vs ordinary TLS

Published May 6, 2026

Same encryption, different trust model. Who authenticates whom, and when to choose each.

Read article →
mTLS · Zero Trust

What is mTLS (mutual TLS)?

Published May 4, 2026

Both parties prove identity with a certificate. How mTLS works, when to use it, and how to set it up.

Read article →

Ciphers & cryptography

Cipher suites, key exchange, RSA vs ECDSA and testing your TLS configuration.

Cryptography · Tools

How to test your TLS ciphers

Published June 1, 2026

openssl, nmap, testssl.sh and SSL Labs — concrete commands and when to use which.

Read article →
Cryptography · Security

Why RC4, 3DES and old ciphers are dangerous

Published May 31, 2026

The concrete attacks — SWEET32, BEAST, POODLE, FREAK — and how to remove the weak ciphers.

Read article →
Cryptography · TLS

Diffie-Hellman and ECDHE explained

Published May 29, 2026

How two parties agree a secret key over an open line — and what forward secrecy protects.

Read article →
Cryptography · Certificates

SHA-1, SHA-256 and signature algorithms

Published May 27, 2026

Why SHA-1 was broken and retired — and how to check your certificates use SHA-256.

Read article →
Cryptography · TLS

AES-GCM vs ChaCha20-Poly1305

Published May 25, 2026

Why the answer depends on AES-NI — and why you should offer both ciphers.

Read article →
Cryptography · Certificates

RSA vs ECDSA certificates

Published May 23, 2026

Performance, compatibility and security compared — and why dual-cert is often the answer.

Read article →
Cryptography · TLS

The best TLS cipher suites today

Published May 21, 2026

Mozilla's modern and intermediate profiles with ready-made nginx and Apache configurations.

Read article →
Cryptography · TLS

What is a cipher suite?

Published May 19, 2026

TLS_AES_128_GCM_SHA256 decoded part by part — key exchange, authentication, cipher and MAC.

Read article →

Troubleshooting

Diagnosing and fixing the most common TLS and certificate errors.

Troubleshooting · TLS

Debug TLS with openssl s_client

Published June 1, 2026

The practical guide: protocol, cipher, chain, SAN, expiry and client cert — from one command.

Read article →
Troubleshooting · TLS

Works in browser, not in Java/.NET

Published May 30, 2026

Separate trust stores (cacerts, Windows store) and missing intermediates — find the cause and fix it.

Read article →
Troubleshooting · TLS

ERR_CERT_COMMON_NAME_INVALID

Published May 28, 2026

Chrome's name for a hostname mismatch — why CN is dead, and how to fix it with SAN.

Read article →
Troubleshooting · TLS

"self signed certificate in chain"

Published May 26, 2026

TLS inspection, internal CAs and the right way to fix it — without turning validation off.

Read article →
Troubleshooting · TLS

"unable to get local issuer certificate"

Published May 24, 2026

The most common production TLS error: a missing intermediate — and the permanent fix.

Read article →
Troubleshooting · TLS

SSL hostname mismatch explained

Published May 22, 2026

Why a valid certificate gets rejected — SAN vs CN, www vs apex and wildcard limits.

Read article →
Troubleshooting · TLS

"Certificate has expired" explained

Published May 20, 2026

What the error means, how to confirm the dates, and the trap of an expired intermediate.

Read article →
Troubleshooting · TLS

"SSL handshake failed": causes and fixes

Published May 18, 2026

Six causes of a failed TLS handshake — and the commands that reveal which one you are facing.

Read article →
Why we write this

Most teams find out the hard way. You do not have to.

Certificates, supplier documentation, and audit readiness typically land on whoever said yes once five years ago. These articles are for you — to make the process clearer and the outcome defensible.

What is next

Already feeling the pain? See what the product concretely solves — or book 20 minutes and talk to us about your setup.