MCMartin ChristenTechnology & Advisory
← Lab notes

Identity & PKI / Technical draft

Certificates are an operational lifecycle.

The question

What makes certificate-based trust dependable after initial setup? Issuance is only one stage. Renewal, revocation, trust distribution and recovery all affect the operating model.

A useful approach

Define ownership for the trust anchor, the requesting identity and the consuming service. Separate certificate issuance from distribution of trust. Make renewal behaviour observable and decide how a failed renewal becomes an actionable signal.

What to evaluate

Consider expiry, unavailable dependencies and changes to trust. A process is credible when its failure behaviour is understood. This is a general evaluation framework; it does not reveal certificate authorities, endpoints or private configurations.