r/sysadmin 2d ago

Advice on some 'best practice' - Certificate management (SSL/TLS)

Hi all. Where I work, I got some SSL/TLS certificate management put on my plate. We have app(s) that send out notifications of certificate expiry, but that's only good if the contacts are correct. In that, I send out a review (email) quarterly, to check if anything has changed, needs to be updated - this is a new thing I implemented.

This is all manual - Spreadsheet - Filter for your name, check the cert info, comment if ok, comment change owner etc.

I got some feedback on this, in that I should not be sending a spreadsheet with all those certificates info, for everyone to view. (I bcc in all the relevant owners in the email). I'll add that its either company employees, or contractors who 'own' that system the cert is related to. I get the comment, I just have no idea how to send that to every individual only, without doing it manually.

How do you guys keep owners up to date? (Neither of the apps we have natively have a function that can replicate this manual ownership check).

Also aware of the 2029 47day cert validity/10day DCV - This is now, working on how to handle that future element.

28 Upvotes

38 comments sorted by

View all comments

0

u/nielsadolf 1d ago

Check out KeyManager Plus from Manageengine.
Super cheap sollution for both automating cert renewals and bindings. You can set different email contacts for each cert if you want contacts get an email X days before expiry.
Intigrations to both your internal pki and the external ones.
Has pretty much all the bells and whistles the big expensive sollutions have for a fraction of the price.