Hello and welcome everybody to another Akeyless webinar. I'm excited to be, with you here today with, Harrison Sherwin, who is the product education specialist from Akeyless. And today, we're talking about how to prepare for the 47 day certificate era. We have an demo about automating your certificate life cycle management. And, Harrison, if you don't mind introducing yourself and I'll go after you. Absolutely. Like you said, first, thank you, Sam. I'm a product education specialist at Akeyless, which means I get to involve myself in just about anything that teaches our wonderful customers and users how Akeyless products work. So I'm really looking forward to our certificate demo today as pretty recent that they started finally enforcing those limits to bring down the maximum validity on certificates. Right, right, exactly. Well, thanks for that, Harrison. And myself, Sam Gabriel, I'm a platform engineer. I'm an educator and instructor in the platform engineering space. And let's go ahead and get started. So we're covering six areas today, so let me walk you through what we'll be diving into. First off, we're gonna explore why certificate life cycles keep getting shorter, the industry trends driving this change. Then we're gonna discuss the real problems that emerge when renewal windows compress and timelines get tight. Next, we talk about the stages of the entire certificate life cycle and what to look for in a platform that will do that for you. From initial discovery all the way through to revocation. And then we're gonna talk about, the practical use cases across different environments, things like Windows and Linux systems, Kubernetes clusters, web apps, and internal services. After that, we'll run through a live demo so you can see all of this in action on Akeyless. And we'll wrap up our time with questions, but feel free to post questions throughout our demo and presentation here so you don't forget them, and we'll address them as we go along or at the end, time permitting. Alright. So why does this matter now? The industry is fundamentally changing. Certificate validity periods are shrinking dramatically down to just 47 days, and this is scheduled to happen by March of 2029. And, so the implications for your team are basically, first, your manual renewal processes simply won't keep up with these short, life cycles. Automation has moved from nice to have to essential. There's almost no room now for human error or delayed action anymore and every manual touch point increases risk And, we used to joke about certificate renewals among system admins. You might have heard that that, you know, as a system admin, you'd hope that you won't be around at the company when the certificate is up to renewal or a series of certificates are up for renewal. So you create a certificate that expires, let's say, five years and move on with life, you can imagine if you're rotating a certificate every five years, you probably forget the process and hope not to worry about it moving forward. But this is not going be the case anymore, and it's not, just about efficiency. Shorter validity periods mean tighter margins for error. One missed renewal window could mean downtime that we can't afford, and this is why what comes next really matters a lot. If you're asking why the shift, there are a few factors I just threw on three here on the screen, you know, quantum preparedness, smaller blast radius, and forcing automation. But let's talk about the certificate life cycle. Certificates don't just exist in a vacuum. They have a complete life cycle that needs to be managed from start to finish, and you need a platform that can manage all five stages end to end so you don't have to juggle multiple tools yourself. And, the first stage is discovery. After that is store and organize. Then you wanna issue and provision these certs, and fourthly, renew and version them, and then fifthly, revoke and respond. And the key takeaway is this, that automated cycle replaces all manual certificate management work your teams used to do. Everything flows through one unified pipeline. In the next few slides, we're gonna talk about each one of these stages at a time. So let's go ahead and take a look at stage one discovery. And this is really the foundation of everything that follows. So before you automate anything, you need to understand what's already running in your environment. The key principle is this, discovery should be continuous, not a one time activity, at least in the beginning till you've built a process of always using automation for creating your certificates. Some of the capabilities that you would expect from a platform that gives you discoverability is, scanning IPs, maybe CIDRs, DNS names to find out what's what's out there, probe endpoints on both standard and custom ports to identify services, centralize all discovered certs in one place for visibility and management, and build your baseline from what's actually deployed. And really, you can't automate what you don't know about, so getting visibility first is absolutely critical. Stage two, this is where you wanna store and organize those certificates. And, firstly, you need a single secure location. You wanna consolidate all certificates into one centralized secure vault that eliminates the risk of your certificates getting scattered across different systems or locations. Next is sorting and browsing and tracking. So you need to implement organizational structure so any team member can quickly locate these needed certificates. And of course that improves efficiency and reduces time spent searching. Next, expiration notifications, we need to have that. You need to set up automated alerts that notify you before certificates expire, prevents lapses in coverage and compliance issues. I don't know about you, Harrison, but what I what I've seen happen in organizations is they would put calendar invites for certificates that might expire. I've seen that happen multiple times, and sure, it got the job done back back in the day, but moving forward, I think we need a better solution than that. And finally, audit ready records. Maintain clean, well documented records with full tracking history, ensures you're prepared for compliance audits and reviews at any time. Next up is stage three. This focuses on getting your certs issued and deployed to where they're needed. So you need a flexible issuance option here where you're not locked into one approach. You need to be able to issue through a keyless PKI, for example, for internal control, use public CAs if that fits your workflow, or leverage Acme for automated standardized issuance. And what excites me also is provisioning to targets as well. So it's not just about, hey. Let's create a certificate, but what about, you know, sending that or provisioning that target with the new certificate? So we need to be able to deploy directly to targets and endpoints, push updates automatically to, workloads, servers, and applications, and needs to work seamlessly whether you're using, like I said, a keyless PKI or public CAs or Acme, and this keeps everything in sync and reduces manual certificate management. So the key benefit here is flexibility. So we're trying to, issue or choose an issuance method that works best for your environment and then automate the delivery to all, your systems. Stage four, renew and version, and this is where we need to manage the ongoing life cycle of your certificates. So firstly, you need to renew from a central location, with a keyless. You can do that from the console or the event center. So you have the flexibility here. So you can do that or and secondly, flexible key management. So when renewing, you can generate a completely new CSR and key pair for enhanced security, but you can also keep things simple by reusing your existing key. That that's an option. Thirdly, full version history. Every version of your certificate is tracked and maintained. If something goes wrong, you can roll roll back to a previous version at any time. And then CRL CRL maintenance, we don't wanna forget about that. Your certificate revocation, you can revoke certificates when needed and keep your certificate revocation list current and accurate, which takes us to the last stage, revoke and respond. So when you need to revoke certificates due to compromise or security risk or policy violet violation, that's when you would go ahead and revoke your certificates, of course, and respond. You need to be able to act immediately upon detection, update the status in your central system so everyone knows the certificate is no longer valid, and maintain detailed audit trails so you can renew or review what happened and when that happened, of course. So the risk of leaving a compromised certificate active is quite serious, and central revocation is critical to mitigating that risk quickly. With Akeyless specifically, you can revoke a certificate. When you revoke a certificate, that status updates everywhere simultaneously. No delays, no gaps, where some systems still trust that old certificate, and this unified approach is what makes revocation effective when you're scaling. So briefly some common use cases here. As you can see on the screen, Akeyless certificate lifecycle management or CLM handles different scenarios for modern infrastructure environments. So we can see Windows and Linux machines, Kubernetes, web apps, APIs, internal services, hybrid and multi cloud. So these use cases show how Akeyless can simplify your CLM across your entire infrastructure footprint. Akeyless solves certificate and key management challenges with two key differentiators and zero knowledge architecture. This is the foundation. Your private keys stay protected throughout the entire certificate life cycle. Neither Akeyless nor anyone else ever sees or handles your private keys, and that is important. And this is a fundamental security principle that Akeyless has built into CLM and PKI as a service, their entire portfolio actually, secrets management and so on. Core capabilities, so what you actually do with a keyless, zero knowledge CLM and PKI as a service for your internal certs, and support for both public and private CA workflows, so it's flexible for different use cases. And automated renewal and rotation. Like we said, no more manual certificate management headaches. Excellent. So, we're up for a demo and we'll get to see a complete certificate lifecycle workflow in Akeyless and how that all works. So I will stop sharing here. And, Harrison, if you'd like to share your screen. Thank you, Sam. Great. Let's go ahead and set this up. Move some things out of my way here. All right. So let's talk a little bit about what I'm gonna be doing here. We're gonna be walking through exactly what Sam just described you, that complete story of the certificate lifecycle management against a real Linux service. Some of the background magic as I set up a CloudFormation stack to build two instances within my AWS account as well as a new network for this. One of those instances is going to be an NGINX server for us to actually use a website with. The second one is going to be a local instance of the Akeyless gateway. I'm going to show you potentially connecting into that gateway as well as connecting into the overall what we call the SaaS console or web console as we log in. This NGINX host, let me show you here, is set up already with a certificate. Unfortunately, that certificate is about to expire. There's also a number of other issues related to this certificate. Oh, I'm sorry, I'm highlighting the wrong part for you there. Oh, there. Me show you the right part as we log in and run my openssl command which will show this a little bit better here. There we go. It's about to expire, it looks like in two days and the other problem we're running into is it's completely self signed. Ew, gross, we don't want that. If you log into this as just a regular website and we blow that up for you. Not secure at the top here, we don't like that. I'm also leaking information out, should probably fix that with Akeyless Security Discovery issues as well. So we want to go ahead and fix that problem. We're gonna go through the process of replacing this certificate after we discover it. We're going to then take that new certificate, provision it to the server, verify everything worked, renew it, maybe revoke it, maybe see a few more things depending on the amount of time I'm allowed to have here. So we've seen the certificate already directly in here. The next command I'm gonna run, I'm gonna start using my Akeyless account now, is Akeyless certificate discovery. So I'm pointing directly to the host that I'm running in AWS down here. Let me get that up there. I'm looking at port four forty three. I'm saying, hey, once you discover any certificates, go ahead and put that into my account in the demo CLM discovered folder. Now, some of the prerequisites I already have here. I already have an AWS account. I've got everything configured in there. I've already gotten a Keyless account set up. I've already got that logged in with my credentials, and I already logged in my gateway with my credentials as well. There's some excellent quick starts in the Akeyless documentation if you want to kind of get to this point that I'm already set up in the webinar. And you can see certificate discovery was successfully finished. I updated one of my certificates and the host that was associated with that. There's a little bit of movie magic. I didn't want the demo to break, so it's not a new certificate, but the command here was still live. And if I show you my account, we'll make that bigger for those of you in the back. I'm already in that demo CLM folder. I'm gonna log in to the discovered folder and we can see that discovered certificate. Several of the tags were already associated with me. I've got that public endpoint. I've got my my public IP address. I've got the certificate data itself already in here. A private key associated with that. I can view more of these details. Look at things like the common name, the OU. This is a very bare bones certificate. This is a demo. I'm not going to win any cybersecurity awards here. That's the Akeyless engineer's job, not me over here in education. We can view lots of these details, say the version, I can see it's version three, I can see the serial number, I can see the issuer. Tons of detail I've now got about this certificate already without doing anything else except discovering it in my account. But we don't want to end that discussion here. We want to keep going beyond this initial visibility, beyond where it is, where it was found, when it expires. We want to do more proactive proactive management as part of this process. This discovered item is just the starting point as we go through. So I'm going to back up out of there. We can see some of the other options I have available to me. I can download it. I can set up access permission. I can view audit logs related to this certificate. Let's go ahead and move this out of the way. And now what we're gonna do is show another version of this to make things a little bit better. So now I'm logging into that private version of the gateway. Why have I swapped between the kind of publicly available console versus my private endpoint console here? Purely so you get to see more of what we're doing here. So one of the prerequisites that I have not done directly in front of you is setting up a target. My target in this case is the server itself. I've got it in a folder demo CLM targets. And then what we're going to go ahead and do is we need this target so we can associate our managed certificate with it. So we're going to swap back over to our certificates and we're going to now go back to the public SaaS console, get you a few more things in here. So I've got this new folder managed and we're gonna walk through that process as if I was making this new managed certificate from scratch. I'm gonna click new, I'm gonna go into certificate and I'm gonna give it a new fancy name, managed cert by Harrison. Never asked me to name anything. If I was in charge of my child's name, they'd be named child number one. Fortunately, that is not her name because her mother won out. Alright, I've got my location. I can add descriptions. I can add tags so I can do more advanced searching as we look across multiple certificates. I can click next here and I can now actually put in those certificate details. Easiest way to do this is to go to this upload button and select the actual file you'd like to open up. We can set up a private key, we can add expiration notifications. When do I wanna be notified this is about? Maybe I'd like some leeway, a month worth of information before this expires, so I'll set it up for forty days. I'm going to click finish. Now that is expected because I've already made this certificate for you. Because again, we need a little bit of movie magic in place here. I can again view those certificate details. I can get far more information as I go through. I can see the validity endpoints and what I've set up. This is actually gonna be valid only until July eighteenth. Yeah, gonna set that up for your 47 day cycle as you're going through or maybe you need a little bit more leeway right now. I think the maximum you're allowed right now is two hundred days. Maybe you wanna just skip all that, go straight to 47 days, whatever you would like as part of that process. Now that I've got the certificate in place already in my account, we need to do two additional components. First, what we need to do is we need to associate this certificate with our target. I'm going to go ahead and get that command set up for you here for us to look at. Bear with me, there's a lot of moving pieces. Alright, move up a little bit there. That command is a keyless associate target item. Now, this is kind of expected as we go through. Things are going to break, so we're going to see if I can do live troubleshooting real fast here. Some of the live troubleshooting is I'm gonna make sure that my gateway is actually set up. It does say that it's allowed true and there's many of these wonderful troubleshooting details within our documentation. I hawk my wares over here since I'm particularly in charge of this. The point of the associate target item command is we're gonna say, hey, this certificate is now associated with this target. Do I have to do this step? Not really. I could manually set up my managed certificate with the server if I wanted to, not required, not the best for me wanting to make my life easier. So by setting up that association, we're gonna get the ability to do automated renewals as we're going through. The command, if this was working, would be to run the Akeyless provision certificate command. That's then going to say, hey, that certificate is now associated with that particular target and I'd like Akeyless to just handle this for me. I'd like it to take that certificate, drop it on that target, make it almost too easy. You're going to second guess, hey, did this work? What happened? This made my life too easy. Do I need to pick up a second job? Hopefully that is my goal for you that you think about that. So we've issued the certificate. That outage risk really only comes from that deployment and renewal process. We attach that certificate to our target through the gateway and tell Akeyless exactly where each file belongs. That post provision command that I just ran was going to rebuild that full chain file, validate the NGINX config, normalize our file permissions and reload NGINX. Because NGINX is so completely well known and supported in our platform, we make it as easy as possible for you. But don't worry, there's many other supported platforms as well on here. Think Kubernetes, think Windows IIS, think so many other options that are available to you. So you're basically saying we can discover certificates for these systems and then once they're discovered they're inside of a keyless and then from there we can manage them under a keyless moving forward, and rotate them and all that good stuff. Absolutely, I am saying that. Nice. I really like the discovery feature here. This is really cool. It is very cool. And I'm gonna let you all on some of the movie magic in the background so you get a little bit of extra troubleshooting here. The solution to this problem is I need to go into my CLI profile and I need to set up my gateway URL to point to the gateway. Why didn't that work in advance? Because I built up this environment like two hours ago in here and I was troubleshooting and some of those endpoints changed. The other problem I'm going to run into here is if I were to completely rebuild my CLI profile in front of you guys, you're going to see my authentication information and my CISO is going to have a real problem with you all seeing the details in my account. So what I wanna show you then next is some of the other options we've got available in here. I'm gonna go back to that managed certificate. You can see that provisioning option where I can set it up with the target, I can point it to the gateway, I can set up that certificate remote path, get all this FHIR file information available in here that I was going to run with that associate command. So let's grab some of these pieces. Our chain path, our post provision commands. And you can pretty much do everything you were showing in the CLI through the UI probably, right? Would imagine. Exactly. And that's one of the reasons why I'm doing this is because my gateway already knows, rather my web console already knows about my gateways. That shouldn't require me to do anything involved here except I did not plan for this endpoint to occur. I kept my demo somewhat bare bones in here, but you get the same idea of I can do this from the console, I can do this from the CLI, I can do this from most languages available. We've got, I believe, about a dozen different SDKs. Don't check me on that number, but most of the popular programming languages are supported in here if you want to build this out yourself beyond just the CLI, beyond just the console. Heck, you could set up something like Postman and call the SDK APIs or rather call the API endpoints directly yourself. We've got version control available for these managed certificates. So as I renew it over time, as I've got these multiple versions that occur, I've got different actions I can perform on them. So we can go through Go ahead, Sam. I thought I heard you there. Oh, no. Sorry. My bad. I'm just hearing your breathing. You're so excited about this. Certificate renewal here, I would identify my PKI issuer. I would put in my auto CSR content or I can use an existing key if I want and that would allow me to perform renewal. I can then revoke these different versions of the certificate. So it's asking me for the name of that and I would revoke that. We've got some issues going on in here, but you've now seen how I would set everything up if we didn't have the curse of live demos where everything works right before you go on live and then things break. So let's walk through a bit of kind of the intent behind this. I discovered the certificate. It was running. I had manually created it. All I said is, Hey, go find the certificates I have at these hosts. Put those certificates within here. I then went through the process of saying, Nah, I don't want to do that. I wanna look at that information so I can make a managed version of that certificate. I create my target server that I wanna associate with that managed certificate and then I will provision that certificate all through a keyless directly to that server, that target. Then I get those more advanced management techniques available to me. I get renewals, I get revocations, I get viewing metadata, I get seeing all the certificates across my environment, managing them, avoiding that calendar invite problem Sam was describing earlier. We'll go ahead and call it there. Sam, did you have any thoughts as we kind of walked through what I'm trying to illustrate here? No, so like I said, the discovery is a big deal. I've had customers ask me quite a lot like what is like how do we find what already exists? Like where? And at the time I didn't really have an answer to that. Manually go run Nmap or do something, right? Go discover it yourself, and once we have it, then put it into your tool that you're going to manage certificates moving forward. But this is making life much easier. I really, really like discovery. And the second part is, sure. You discovered the certs. The certs are in, and, and we're managing the certs. But then if I wanna renew a cert, do I have to manually take that cert and put it on the target system? And what I like is, no. You can provision it and push it to your targets. Obviously, you need to put the targets in place so that Key West knows about them. But, but, yeah, this makes automation, you know, makes the automation of the certificates much easier. Really nice to see that. Alright. We've got some questions in chat. So let me go ahead and look at some of those that we can address. So if you've got any questions, you've got any thoughts in there, go ahead and throw questions in chat. We'll try to address some of these things. We'll try to talk some of them as we go through. So the first question here is, on a plain Windows Server, will it discover certs they are not installed and used by say IIS but some custom app and certs have password protected private keys? I'm gonna say maybe. It very much is going to depend on how you've set up a lot of that custom information. IIS, like I said, absolutely supported in there. We're say that for custom apps, depending on how you've set this up, it's gonna be likely that there is a way to do it. But I don't want to say it's just gonna be plug and play for you depending on your level of customization that you have performed within there. Sam, did you want to add anything to that? No, I think it's adding there at the bottom. Mean certs are not visible in cert alumni at MSC c, but used by, say, SQL Transparent Data Encryption (TDE) only. Ah, you've given me the information. Alright. Let me double-check here. I think since you've bypassed the operating system entirely there, we're not going to be able to support but I would encourage you if you're interested in Akeyless to talk to our team. They are far more intelligent and far more practiced at a lot of this stuff than I am and I highly suspect they've got an idea will minimize the friction of you changing everything involved to get that answer you're looking for. Sam, what do you think? Absolutely. One of the things I like about Akeyless is the speed in which they come up with things. And one of the advantages of having Akeyless being a SaaS is that they can iterate fast. And if there's a use case that makes sense and they you know, you bring that use case to them, they will do the best to incorporate that into the solution. So, yes, I agree with Harrison. Highly recommend you talk to the team. You are most welcome, Ilkin. What other questions, comments, concerns do you all have? We are here for you. There is a raised hand from Avajeet. Avajeet, I would encourage you to use the Zoom Q and A function so we don't end up unmuting everybody and hearing everybody and their dog and their crying baby. Fortunately, my baby's at daycare and the dogs are locked upstairs. Otherwise, you would hear all of them. I got a question for you. Is there a way to prove compliance to auditors? Like, can we show records of our certificates or rotations or like, where's the audit logs for this? Like do we have audit logs that we can show? We absolutely have audit logs for nearly everything you see in a keyless. There is an audit log section. Let me see if I can pull mine up. I'm not gonna have a ton of it in there, but I at least should be able to show you. There we go. You're not sharing yet, Harrison. I know I'm prepping that right now. There we go. Audit logs. I'm in the console. I'm under that administration sub menu, and I went into audit logs, and you're gonna see every Nice. Can we get a bit bigger, Harrison? I'm gonna need glasses pretty soon. There we go. Thank you. All right, so I can see every action performed. You saw me attempt to do that revoke certificate command. I can see all of that right in there and all the different parameters associated with that. Every single action we are performing is gonna be tracked in here by audit logs. And also remember when I was looking at that certificate item, I also saw that version history for the certificate from that view as well. So I can see just about everything I could possibly want to see for myself or for auditors. Very cool. Is there a view to see all the certs in one place? You might not have many certs now, but Items? CLM. So I've got the individual folders view available to me. Gotcha. And if I recall, let me pull up a different view while we're thinking about it. While addressing all this and I'm trying to do things live that I did not plan, please throw all your questions into chat, and we will do our best to get to things. Here's a question. Is there any notification? This is from Avijit. Is there any notification when a cert renewed automatically? Yes. Because that is going to still require all of these API calls and every API call is going to end up in the audit log. So that's the first place. And you can also set up all those custom notifications. So I walked you through setting up some of that in there so you actually saw a lot of that information already. Trying to pull up. I'm pretty sure we can also set up webhooks or something that can send us Absolutely. You can. Should be fine. I lost one of my URLs, I'm going back into my account to pull that up on the database. But great questions everybody and keep them coming. One question that I typically get is like, can Akeyless help with revocation? And the answer is absolutely. Know, we're Absolutely. We we walked through that. Is the part exactly. Can keep a CRL and everything. So yep. That's what I was looking for. What you're not seeing is I now have logged into a different view directly through the One Gateway on a screen that you don't see. And the reason you don't see it is I'm logging in and I don't want you all to see my stuff. Another question. Can Akeyless discover certs that were created outside of Akeyless? Yeah. So that NGINECK, that scenario that Harrison walked through, that was created outside of Akeyless. So, yeah, absolutely. All right. And I did get your answer, Sam. And that answer is I absolutely can look at the certificate list. I just had to remember how to do it. I'm going to go back as though I am not somebody who has already changed things. So if I log into my list of items by normal things, I'm only going to see my top level items and then I'm going to see folders. What I'm going to first change here is I'm going to switch to a list view. It's going to make all those folders go away. I'm going to be looking at it as a flat structure and then I can filter by certificate. Are two certificates: the ones I discovered and the managed one. Cool. We're starting to do our kind of wrap up here everyone. We don't wanna continue talking to each other in front of you all. We've got other avenues for that. If you've got any other questions, go ahead, throw that in there. Otherwise, thank you all for being here today. It has been our pleasure to walk you through Akeyless to help you all solve some problems as we're going through and show you how we can potentially make your life a little bit easier as you think about these changes that we now need to be making for certificates. That 47 day maximum validity requirement from browsers, it's coming. I believe it's about, I'm gonna say 22 months out if I remember my notes here, March fifteenth, 2029, but that maximum validity is just gonna keep ticking down. In fact, you've only got about ten months before maximum validity hits a 100 days or you're gonna start getting those awkward warnings every time somebody tries to go to your website about, hey, this is insecure. Dang it, I really wanted to get their cool product, their cool service, but now I don't trust them. You want to avoid all those problems. Sam, do you have anything to say to our illustrious audience before we end it here? No, I mean, this has been great. And thank you everybody for being here. And, again, hopefully, this has been helpful. Do check out Akeyless. You can get a free demo and take a look at it and speak with the team, if there's interest there. So thank you, everybody. Thank you, everyone. Talk to you later. Take care.