The Race to Shorter Maximum TLS Certificate Validity

January 13, 2025

90-day (and even 45-day) maximum TLS validity may not be official yet, but proposals are being actively discussed. When browsers do enforce shorter TLS certificates – whether with CA/B Forum approval or without – the changeover will impact all public-facing certificates. With this change, manual approaches to TLS certificate management will become even more unsustainable than they already are.  

To help you prepare, we partnered with Ryan Hurst, a former Microsoft and Google Security leader, to create this guide. Through firsthand insights gleaned from his illustrious three-decade career, you’ll learn:  

  • Why the transition to 90-day TLS certificates is happening 
  • A timeline of decreasing certificate lifespans – and when we can expect shorter TLS validity to go into effect 
  • Specific reasons browsers can enforce this change (even without CA/B Forum approval) 
  • 4 steps to prepare for a shorter TLS certificate standard 
Previous Article
The Identity Security Imperative
The Identity Security Imperative

The Identity Security Imperative is a clear guide to understanding and implementing identity security, enab...

Next Video
Quantum-Proofing Your Data: Are You Ready for the Future of Cryptography?
Quantum-Proofing Your Data: Are You Ready for the Future of Cryptography?

Gain the knowledge needed for a successful PQC migration – including recommended quantum frameworks from re...