Home/Labs/ACME Renewal Timeline
All 280 Labs
INTERACTIVE LAB📅

TLS Certificate Lifecycle at Scale Lab (Interactive)

Slide through the 90-day Let's Encrypt clock and flip HTTP-01 versus DNS-01. Trace domain-validation challenges, renewal windows, expiry outages, and OCSP-stapling handshake cost across an automation-controlled certificate fleet.

ACME Certificate Lifecycle Clock

Age a Let's Encrypt certificate through the 60-day renewal trigger, choose a domain-validation challenge, and see who survives the expiry cliff.

0d valid60d renew90d expiry120d

Days before expiry

76

TLS handshake cost

1 ms

Wildcard issuable

yes (DNS-01)

Certificate VALID — 76 days of validity left on the 90-day lifecycle.

# cert-manager DNS-01 solver

POST /acme/new-order · domains: ["*.example.com"]

challenge location → _acme-challenge.example.com (TXT)

renewBefore: 720h (auto at day 60)

ocsp-staple: cached signed CA response served in handshake

90-day lifetimes are deliberate: short-lived keys shrink the value of a stolen private key and force automation, because any PKI process that relies on a human calendar reminder is a future outage on a ticket queue. DNS-01 also works for internal VPCs with no public port 80, at the price of scoped DNS API credentials. Every issuance is logged in append-only Certificate Transparency Merkle trees so domain owners can audit for rogue certs.

How It Works Under the Hood

Public TLS certificates expire on purpose: Let's Encrypt issues 90-day X.509 certificates to shrink the blast radius of compromised keys, which makes renewal automation a hard dependency, because outages at Microsoft Teams, Spotify, and Fortnite were simply un-renewed certs. ACME validates control via HTTP-01 (a token file on port 80, fast but instance-level) or DNS-01 (a TXT record, the only path to wildcards and the better fit for internal CAs). A cert-manager style controller renews at day sixty. The lab advances the clock day by day, contrasts validation modes, and prices revocation checking: OCSP stapling keeps the status query off your clients' critical path, saving a round trip per handshake.

Core Architectural Principles

  • Day-60 automated renewal resets the clock; with automation off the fleet ages into hard TLS expiry.
  • Wildcard certificates (star.domain.com) can only be validated through DNS-01 TXT challenges.
  • OCSP stapling removes a per-client revocation lookup, cutting roughly 30 ms from the handshake.
Interview Round Script

Anchor on lifecycle: 90-day certificates make ACME plus cert-manager automation part of the SRE contract, not a nice-to-have, and cite real expiry outages. Explain HTTP-01 versus DNS-01 (wildcards demand DNS), then add OCSP stapling and Certificate Transparency logs as the revocation and audit story at scale.

Key Trade-Offs

Short-lived certificates shrink key-compromise windows but make renewal automation a new, very loud single point of failure.

Related Curriculum Chapter

TLS Certificate Management at Scale: ACME & Let's Encrypt

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs