Skip to main content

Certificate Lifecycle

Issue, deploy, rotate, revoke, recover, and retire certificates and private keys without breaking name or trust validation.

Lifecycle states

A certificate binds a public key to names or other identities under an issuer and validity period. Its lifecycle includes key generation, request and proof, issuance, distribution, activation, monitoring, renewal, rotation, revocation, compromise recovery, expiry, and retirement.

Protect the key

Generate private keys in the intended protection boundary. Limit export and use. Separate certificate publication from private-key custody. Authenticate automation and restrict which names it can request. Record issuer, subject names, key algorithm, serial number, deployment targets, owner, and expiry.

Rotate safely

Deploy trust before use when a new issuer or key is introduced. Support a bounded overlap, verify every endpoint, then remove old trust and key material. Test rollback without restoring a compromised key. Alert before expiry and on unexpected issuance.

Failure and residual risk

Automation can issue for the wrong name, deploy a key to the wrong host, omit a replica, or preserve an old trust anchor. Revocation checking can be unavailable or delayed. A renewed certificate does not repair a compromised endpoint. Excessive lifetime increases exposure; excessive rotation complexity creates outages.

Pomerium boundary

Pomerium uses certificates for client-facing and upstream TLS according to deployment configuration. Operators own issuer trust, names, key custody, rotation, and recovery. Pomerium route policy does not compensate for an unauthenticated upstream channel.

Evaluation checklist

  • Is each certificate tied to an owner, names, issuer, key, target, and expiry?
  • Can automation request only approved identities?
  • Does rotation cover every replica and remove old keys and trust?
  • Can compromise recovery revoke and replace without restoring the old key?
  • Are expiry, unexpected issuance, validation failure, and deployment gaps observable?

Sources and further reading

Keep learning

Standards and ProtocolsNetwork and Infrastructure

HTTPS and TLS

Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo