Skip to content

Automation of certificate management

Nameshield is at the heart of digital certificate automation.

Driven by the CA/B Forum to strength­en web secu­ri­ty, the fre­quen­cy of SSL/TLS cer­tifi­cate renewals will accel­er­ate dras­ti­cal­ly in the com­ing years.

The new reg­u­la­to­ry timetable and its impacts:

  • Since March 15, 2026: the max­i­mum dura­tion of TLS cer­tifi­cates is lim­it­ed to 200 days.
  • On March 15, 2027: this peri­od will be reduced to 100 days
  • March 15, 2029: fur­ther reduc­tion to 47 days
  • Between March 2026 and March 2029: the dura­tion of the DCV chal­lenge (domain val­i­da­tion) will be lim­it­ed to 10 days, requir­ing mas­tery of the DNS com­po­nent.
Reduction of the certificate validity period to 47 days

Operational impact: The reduc­tion to 47 days for cer­tifi­cates and to 10 days for the DCV chal­lenge will mul­ti­ply the admin­is­tra­tive and tech­ni­cal work­load by eight.

Manual man­age­ment is now obso­lete: cer­tifi­cate automa­tion is the only sus­tain­able solu­tion to avoid acci­den­tal expi­ra­tions and ser­vice out­ages.

Simultaneously connecting the three essential building blocks for automating public certificates

Certificate Lifecycle Management (CLM) is the ide­al soft­ware solu­tion to man­age the entire life­cy­cle of dig­i­tal cer­tifi­cates (inven­to­ry, man­age­ment strat­e­gy, order­ing and deploy­ment) in order to secure process­es and pre­vent ser­vice inter­rup­tions.

For com­pa­nies man­ag­ing com­plex IT sys­tems, the automa­tion of cer­tifi­cate man­age­ment relies on a per­fect syn­er­gy between the CLM soft­ware and our infra­struc­ture:

  • Complete map­ping of pub­lic and pri­vate cer­tifi­cates
  • Centralized man­age­ment of the man­age­ment strat­e­gy
  • Seamless inter­con­nec­tion between your IT sys­tems and Nameshield
  • Automatic order­ing of your pub­lic cer­tifi­cates at Nameshield
  • Deployment across all instances

Our CLM pub­lish­er net­work:

CLM (Certificate Lifecycle Management)

The ACME pro­to­col is the stan­dard that enables secure and auto­mat­ed exchanges between your servers and Certification Authorities (CAs).

The advan­tages of Nameshield’s ACME ser­vice:

Nameshield offers Domain Control Validation (DCV) as a ser­vice to auto­mate cer­tifi­cate man­age­ment by pro­vid­ing cen­tral­ized val­i­da­tion, elim­i­nat­ing man­u­al tasks, and ensur­ing real-time automa­tion for issuance and renew­al. This ensures the com­pli­ance with new indus­try stan­dards and the reduced valid­i­ty peri­ods imposed by the CA/Browser forum reg­u­la­tor.

The chal­lenge of the DNS com­po­nent: with the DCV chal­lenge reuse peri­od reduced to 10 days in 2029, pre-val­i­da­tion of domain names will be very lim­it­ed and their reval­i­da­tion will be almost manda­to­ry with each order.

Nameshield’s advan­tages for man­ag­ing the DCV chal­lenge:

  • The deposit of con­trol tokens (TXT or CNAME) on your DNS zone is done auto­mat­i­cal­ly, avoid­ing man­u­al manip­u­la­tions.
  • Since proof of domain own­er­ship is val­i­dat­ed in a sec­ond, the issuance of your OV/DV cer­tifi­cates is imme­di­ate and obtain­ing EV cer­tifi­cates is great­ly accel­er­at­ed.
Maîtrise de la brique DNS pour le challenge DCV