Choose the next certificate operation from observed chain, name, loaded key, client behavior, and identity policy. A renewed file or a successful handshake alone does not prove all relying paths are safe.
Review these lessons
- TLS chain delivery: test the clients that actually connect
- Private CA rotation: overlap trust before changing issuers
- TLS names: verify SNI selection and peer identity independently
- Certificate reloads: distinguish file delivery from active TLS state
- ACME issuance: test challenge reachability without burning production orders
- Certificate revocation: test the client behavior and status-service dependency
- TLS key compromise: replace authority and end stale sessions
- mTLS workload identities: test both authentication and authorization on rotation
Other checks
- DevOps checks
- DevOps GitOps operating-boundary decisions
- DevOps cloud authorization and audit decisions
Common Mistakes
- Do not treat issuance as deployment.
- Do not treat a valid mTLS chain as broad API authorization.
