One SSL certificate on multiple servers
Generating the private key on the server it protects is the textbook answer. Then someone asks for a wildcard, or a second server, and the textbook doesn’t have a chapter for that.
Generating the private key on the server it protects is the textbook answer. Then someone asks for a wildcard, or a second server, and the textbook doesn’t have a chapter for that.
Certificate lifetimes are shrinking to 47 days. Manually updating SSL certificates through the SonicWall Administration UI is no longer an option. We automate the process, but SonicOS doesn’t make it easy.
CertKit now ships centrally managed deployment scripts that push certificates directly to appliances, cloud platforms, and custom infrastructure, with a template library and encrypted variable storage.
Any sufficiently complicated SSL certificate renewal system contains an ad hoc, informally-specified, bug-ridden, slow implementation of half a certificate lifecycle manager. I’m taking credit for this one.
New writing on certificate management, sent when there is something worth your time. Shrinking lifetimes, ACME on real infrastructure, the occasional outage post-mortem.