Abstract

On March 15, 2027, the maximum lifetime of a public TLS certificate drops from 200 days to 100. That is only five months away. A certificate you used to renew once a year will need renewing five times a year, and when the cap hits 47 days in 2029, twelve.

The number of certificates most Windows shops are renewing by hand is higher than the number they would guess. Always On VPN SSTP, DirectAccess IP-HTTPS, RD Gateway, IIS, Exchange, ADFS, and whatever is sitting in front of them in the rack. Most of those can’t run an ACME client on their own, and each renewal touches a binding, a service restart, or on some appliances a reboot. Doing that on a maintenance window once a year is a chore. Doing it eight times a year across forty certificates is a job nobody has.

On October 6, Richard Hicks and I are doing a live session on what to do about it. Sign up here.

What we’re covering

100-Day Certificates Arrive in March: Renewal Automation for Windows Servers, VPN, and Everything Else With a Certificate October 6, 2026 | 11:00 AM Central | 60 minutes | Free

Richard is a Microsoft MVP and the person people call when Always On VPN or DirectAccess breaks. He’ll go through which Windows workloads carry public certificates, what a failed or late renewal looks like to users on each one, and what a renewal touches on each. That last part is the point. It’s why a manual process that works today stops working somewhere between 100 days and 47.

I’ll run CertKit live. Discovery from CT logs to find the certificates issued for your domains, including the ones nobody remembers requesting. Issuance with DNS validation delegated to a subdomain so no server holds zone credentials. The agent deploying to a Windows workload end to end, restarting what needs restarting. The appliance path for the things that can’t run an agent. And what renewal timing looks like when the lifetime is short enough that “renew at 30 days” is a third of the way through.

We’ll close with the certificates that aren’t on this timeline at all. Internal CA certificates don’t get shorter, they expire on their own calendar with nobody watching. Richard will name the ones that cause outages in his engagements, and I’ll show monitoring them through the agent so internal and public sit on one dashboard.

Then questions. When you register, you can submit a scenario or a question. If you’ve got an appliance we haven’t seen or a setup you couldn’t get a straight answer on, put it in and we’ll work it into the session.

Register here. Free, 60 minutes, on Teams.


CertKit automates certificate lifecycle management on Windows servers, IIS, and vendor appliances, so 100-day renewals are someone else’s problem.

Keep reading