TLS Certificate Lifecycle at Scale Lab (Interactive)
Slide through the 90-day Let's Encrypt clock and flip HTTP-01 versus DNS-01. Trace domain-validation challenges, renewal windows, expiry outages, and OCSP-stapling handshake cost across an automation-controlled certificate fleet.
ACME Certificate Lifecycle Clock
Age a Let's Encrypt certificate through the 60-day renewal trigger, choose a domain-validation challenge, and see who survives the expiry cliff.
Days before expiry
76
TLS handshake cost
1 ms
Wildcard issuable
yes (DNS-01)
# cert-manager DNS-01 solver
POST /acme/new-order · domains: ["*.example.com"]
challenge location → _acme-challenge.example.com (TXT)
renewBefore: 720h (auto at day 60)
ocsp-staple: cached signed CA response served in handshake
90-day lifetimes are deliberate: short-lived keys shrink the value of a stolen private key and force automation, because any PKI process that relies on a human calendar reminder is a future outage on a ticket queue. DNS-01 also works for internal VPCs with no public port 80, at the price of scoped DNS API credentials. Every issuance is logged in append-only Certificate Transparency Merkle trees so domain owners can audit for rogue certs.
How It Works Under the Hood
Public TLS certificates expire on purpose: Let's Encrypt issues 90-day X.509 certificates to shrink the blast radius of compromised keys, which makes renewal automation a hard dependency, because outages at Microsoft Teams, Spotify, and Fortnite were simply un-renewed certs. ACME validates control via HTTP-01 (a token file on port 80, fast but instance-level) or DNS-01 (a TXT record, the only path to wildcards and the better fit for internal CAs). A cert-manager style controller renews at day sixty. The lab advances the clock day by day, contrasts validation modes, and prices revocation checking: OCSP stapling keeps the status query off your clients' critical path, saving a round trip per handshake.
Core Architectural Principles
- Day-60 automated renewal resets the clock; with automation off the fleet ages into hard TLS expiry.
- Wildcard certificates (star.domain.com) can only be validated through DNS-01 TXT challenges.
- OCSP stapling removes a per-client revocation lookup, cutting roughly 30 ms from the handshake.
Anchor on lifecycle: 90-day certificates make ACME plus cert-manager automation part of the SRE contract, not a nice-to-have, and cite real expiry outages. Explain HTTP-01 versus DNS-01 (wildcards demand DNS), then add OCSP stapling and Certificate Transparency logs as the revocation and audit story at scale.
Short-lived certificates shrink key-compromise windows but make renewal automation a new, very loud single point of failure.