How IT pros should approach certificate inventory management
“It’s a question of understanding and defining the risks attached to each certificate,” security exec tells IT Brew.
• 3 min read
AI agents are starting to do more than access systems. They can invoke tools, execute workflows, and take action across business applications. As that autonomy grows, IT needs visibility into what each agent is allowed to do, what it actually did, who owns it, and how to revoke access when needed. Learn how JumpCloud helps govern AI agents alongside human and device identities.
When it comes to managing certificate inventory, IT pros need to be aware of the importance of a changing environment—and identities.
Many organizations and enterprises are facing challenges in keeping up with a rapidly changing and evolving certification space.
But changes in certificate inventory validity adds a sense of chaos to how teams approach management, said RapidScale CISO Brent Neal.
“You can’t use a person to go run through all the hundreds or thousands of certificates you may have—it’s becoming unfeasible,” Neal said. “That’s where I see where we are right now in the certificate management world, a little bit of chaos on what we need to do, and that does lead to knock-on effects for security.”
Needs and deeds. IT pros are often caught between the demands of the executive suite and the reality of security and efficiency concerns. Building out a full inventory is a good first step to establishing a foundation to build upon.
To Gweltas Radenac, SEALSQ director of IoT security, that inventory is part of managing prioritization; critical certificates need to be implemented with explicit trust models, while less important certificates can be dealt with using open-source tooling.
“It’s a question of understanding and defining the risks attached to each certificate and then writing a procedure where it’s clear for everybody that, for some of them, the help of an external party would be beneficial to minimize the risks,” Radenac told IT Brew.
TLS live. With certificates like TLS becoming more important in a post-quantum future, as IT Brew reported last June, that’s an additional imperative for IT teams to maintain an up-to-date inventory. The 2025 shift by the Certification Authority Browser Forum (CA/Browser Forum) to reduce TLS certificate lifespans to a 47-day window by 2029 has been a major driver in shifting certificate management.
“That’s an event which will require a more elegant way to manipulate and to manage the population of certificates within each company,” Radenac said. “The second event is the fact that there are more and more certificates in a company, which are distributed across cloud, data center, application network, API, IoT device areas…so the ownership becomes relatively complex to manage.”
Combine that time crunch with the increasing complexity of the tech stack and you’re looking at certificate inventory where manual management isn’t feasible, said Todd Moore, global VP of data security products for Thales.
“Spreadsheets aren’t going to work anymore, that’s something that needs to be figured out from an automation perspective, no matter what the life cycle is,” Moore said. “At the speed and the scale that we’re working at, there’s got to be automation and orchestration put in place to manage these security interactions.”
About the author
Eoin Higgins
Eoin Higgins is a senior reporter with IT Brew. His work focuses on AI, IT jobs, and hardware.
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
