Lifecycle states
A certificate binds a public key to names or other identities under an issuer and validity period. Its lifecycle includes key generation, request and proof, issuance, distribution, activation, monitoring, renewal, rotation, revocation, compromise recovery, expiry, and retirement.
Protect the key
Generate private keys in the intended protection boundary. Limit export and use. Separate certificate publication from private-key custody. Authenticate automation and restrict which names it can request. Record issuer, subject names, key algorithm, serial number, deployment targets, owner, and expiry.
Rotate safely
Deploy trust before use when a new issuer or key is introduced. Support a bounded overlap, verify every endpoint, then remove old trust and key material. Test rollback without restoring a compromised key. Alert before expiry and on unexpected issuance.
Failure and residual risk
Automation can issue for the wrong name, deploy a key to the wrong host, omit a replica, or preserve an old trust anchor. Revocation checking can be unavailable or delayed. A renewed certificate does not repair a compromised endpoint. Excessive lifetime increases exposure; excessive rotation complexity creates outages.
Pomerium boundary
Pomerium uses certificates for client-facing and upstream TLS according to deployment configuration. Operators own issuer trust, names, key custody, rotation, and recovery. Pomerium route policy does not compensate for an unauthenticated upstream channel.
Evaluation checklist
- Is each certificate tied to an owner, names, issuer, key, target, and expiry?
- Can automation request only approved identities?
- Does rotation cover every replica and remove old keys and trust?
- Can compromise recovery revoke and replace without restoring the old key?
- Are expiry, unexpected issuance, validation failure, and deployment gaps observable?
