Certificate Lifecycle Management

Renewal, rotation, audit,
automated.

From 2029 TLS certificates only live for 47 days. Manual processes don't scale. NextPKI orchestrates the lifecycle across any CA, with a policy gate before every issuance.

ACME · REST API · manual approvalDigiCert · Sectigo · Let's Encrypt · GlobalSign · ZeroSSL · SwissSignPer domain, per team, per risk class
Zertifikats-LebenszyklusEin durchgängiger Prozess je Zertifikat1AusstellenCA-Request2ÜberwachenAblauf-Tracking3ErneuernAuto · T-144AusrollenDeploy + ReloadAnstehende ErneuerungenAuto anapi.example.comin 14 Tagenapp.example.comin 41 Tagencdn.example.com✓ erneuertErneuerung 14 Tage vor Ablauf · ACME · API · manuell
Protocols ACME · REST API · manual approval
Public CAs DigiCert · Sectigo · Let's Encrypt · GlobalSign · ZeroSSL · SwissSign
Policies Per domain, per team, per risk class
Audit Full issuance trail
Lifecycle in practice

From request to rotation, fully automated.

Every certificate follows a documented policy. Every step is auditable.

01

Auto-renewal over ACME

The default path for ~80 % of all workloads: NextPKI acts as an ACME client against every supported CA.

02

REST API & connector plugins

For CAs without ACME (DigiCert CertCentral, Sectigo, GlobalSign Reseller) we ship robust integrations with retry and rate limiting.

03

Manual approval gate

Two-person sign-off for EV certificates, domain validation over email or Slack, audit trail by default.

04

Policy as code

Which domain may use which CA, which key size, which SAN list, versioned as YAML.

05

Algorithm agility

ECDSA today, ML-DSA tomorrow. Policy migration without code changes in your workloads.

06

Smart renewal timing

Respects maintenance windows, CA rate limits and business-critical time windows.

Rollout in 4 phases

Pilot, scale, auto-mode.

Start small, with one domain and one team, and expand to the whole portfolio step by step.

01
Week 1 Pilot domain

One controlled scope, one CA. Verify end-to-end renewal, calibrate alerts.

02
Week 2 Policy model

Risk classes, approval paths, ownership, in code, not in heads.

03
Week 3-4 Multi-CA connectors

Connect further CAs, authenticate reseller accounts, activate quota management.

04
From month 2 Auto mode

Renewal runs hands-off. People are only called on policy violations or new workloads.

Own the lifecycle

Short certificate lifespans demand an automated lifecycle.

Talk to us when your first ACME scripts are already groaning and forgotten renewals are the top incident cause.