Identity & PKI / Technical draft
Certificates are an operational lifecycle.
The question
What makes certificate-based trust dependable after initial setup? Issuance is only one stage. Renewal, revocation, trust distribution and recovery all affect the operating model.
A useful approach
Define ownership for the trust anchor, the requesting identity and the consuming service. Separate certificate issuance from distribution of trust. Make renewal behaviour observable and decide how a failed renewal becomes an actionable signal.
What to evaluate
Consider expiry, unavailable dependencies and changes to trust. A process is credible when its failure behaviour is understood. This is a general evaluation framework; it does not reveal certificate authorities, endpoints or private configurations.