When certificate lifetimes and domain validation windows shorten at the same time, manual operations can no longer keep up.
The timeline is set by the CA/Browser Forum: 100-day certificate lifetimes from March 15, 2027, followed by 47-day certificates and 10-day DCV from March 15, 2029. This is not just another constraint. It represents a fundamental shift in the Web PKI: the shorter the validity period, the closer the certificate remains to the current reality of the domain. And the more automation stops being an option.
Most teams are preparing to renew certificates more frequently. But that’s not where things break first. The real breaking point lies elsewhere: between certificates and DNS, across multiple CAs and providers, and between security, PKI, network, and DNS teams that all need to keep pace with the same cadence.
In 30 minutes, Étienne Laviolette, COO at Evertrust, and Christophe Gérard, Chief Product & Marketing Officer at Nameshield, will tackle the topic from both sides: digital certificate lifecycle management and DNS.