惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News | PayPal Newsroom
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
大猫的无限游戏
大猫的无限游戏
GbyAI
GbyAI
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LangChain Blog
S
SegmentFault 最新的问题
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Project Zero
Project Zero
P
Privacy & Cybersecurity Law Blog
V
Vulnerabilities – Threatpost
博客园 - 三生石上(FineUI控件)
Recorded Future
Recorded Future
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
宝玉的分享
宝玉的分享
aimingoo的专栏
aimingoo的专栏
T
Tor Project blog
T
The Exploit Database - CXSecurity.com
Schneier on Security
Schneier on Security
H
Help Net Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
M
MIT News - Artificial intelligence
W
WeLiveSecurity
P
Proofpoint News Feed
A
About on SuperTechFans
S
Securelist
I
InfoQ
G
Google Developers Blog
博客园 - 司徒正美
博客园 - 叶小钗
Latest news
Latest news
F
Fortinet All Blogs
G
GRAHAM CLULEY
腾讯CDC
Jina AI
Jina AI
S
Schneier on Security
I
Intezer
V
Visual Studio Blog
美团技术团队
V2EX - 技术
V2EX - 技术
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
罗磊的独立博客
Y
Y Combinator Blog

NETSCOUT

Why Customer Lifetime Value Begins on the Network | NETSCOUT Service Providers Rethink Fraud Detection in the 5G Era | NETSCOUT Resilience Is the Foundation of Modern Security Strategy | NETSCOUT How Machines Are Taking Over Network Traffic | NETSCOUT Why AI Moves Faster Than the Controls Built to Manage It | NETSCOUT NETSCOUT Named a SPARK Matrix™ Leader in Network Observability for the Third Consecutive Year | NETSCOUT Why CDNs Alone Are Not Sufficient for Modern DDoS Protection | NETSCOUT All That Glitters Isn’t Gold: Why AI Needs Better Data | NETSCOUT From Horseback to Real-Time Observability | NETSCOUT Why Digital Twins Are Now Mission-Critical for Scaling 5G with Confidence | NETSCOUT NETSCOUT Earns Six Leader Badges in the G2 Summer 2026 Grid Reports | NETSCOUT When Too Much Data Becomes Too Big an AI Problem | NETSCOUT Game-Changing AI in the RAN Plays by Its Own Rules | NETSCOUT 75,000 DDoS-for-Hire Actors Targeted by Law Enforcement | NETSCOUT What Is NETSCOUT Smart Data and Why Is It So Important? | NETSCOUT Understanding Network Traffic for Threat Hunting | NETSCOUT Black Box Versus Glass Box DDoS Protection Intellyx Names NETSCOUT to Prestigious 2026 Digital Innovator Award List How to Operationalize Threat Hunting with NETSCOUT, SIEM, XDR, EDR, and SOAR Solving Network Blind Spots Created by Massive Data Silos The Self-Healing Network: Why Your AI Strategy Needs a Neutral Lens Does It Feel Like a Stormy Season in Your Cloud? Four AI Trends Transforming Network Operations The 1 A.M. Cloud Migration Meltdown Communication Service Provider Supports Banking Application Success Across International Borders Defending Against DDoS Attacks at Scale AI-Driven Workflow Automation Is the New North Star for Communication Service Providers Key Takeaways from the EMA Network Management Megatrends 2026 The Digital Foundation of Public Trust Is More Than Skin Deep Unlocking the Full Value of 5G with Network Slicing NETSCOUT to Have a Strong Presence at Cisco Live Why Airlines and Airports Must Embrace Observability Ahead of the Summer Travel Surge Beyond “Best Effort”: Why Carrier Grade 5G Slicing Matters More Than Ever | NETSCOUT From Packets to Insight: How Curated Network Data Powers AI | NETSCOUT Data Centers Are Feeling the Heat, and That’s OK | NETSCOUT If You Can’t See the Slice, You Can’t Sell the SLA | NETSCOUT Insights from the GigaOm Radar for Network Observability v6 Report | NETSCOUT How Shadow AI Creates Zombie Infrastructure NETSCOUT Earns Eight Leader Badges in the G2 Spring 2026 Grid Reports Your Modern Manufacturing Network Deserves a Modern Observability Strategy How Botnet-Driven DDoS Attacks Evolved in 2H 2025 The Hidden Cost of Poor Network Observability Insurance Systems Look Simple, but the Infrastructure Isn’t How AI is Transforming the RAN With the Right Data When Cloud SaaS DDoS Mitigation Offerings Aren’t Enough Frictionless Banking Experiences Start with Observability Colocation Growth Demands Scalable End-to-End Observability Bringing Shadow AI Into the Light AIOps Outcomes Depend on Data Quality, Not Algorithms Why AI, Zero Trust, and Modern Security Require Deep Visibility How Service Behavior Changes in Remote Locations The 10-Hour Problem: How Visibility Gaps Are Burning Out the SOC From Insight to Impact: Observability Fuels AI-Driven Innovation How Orphaned Applications Are Quietly Fueling Your Shadow IT Problem Why Today’s Security Tools Can’t See the Network Anymore How NETSCOUT Addresses Modern Network Observability Challenges Helping IT Organizations Prevent Disruptions Before They Impact Business How Hidden Blind Spots Quietly Became Cybersecurity’s Biggest Vulnerability The Blame Game! Is it the Network or Gaps in Observability? Six Winter 2026 G2 Leader Badges Prove This DDoS Protection Stands Out The Value of Combining Modern Observability Solutions for Actionable Insights AI Failure Is the Norm Because Most Initiatives Are Flying Blind NETSCOUT Distinguished by Frost & Sullivan with the 2025 Company of the Year Recognition 5 Emerging AI Data Trends Enterprise IT Teams Cannot Ignore What is Network Slicing NETSCOUT’s Omnis Cyber Intelligence Earns Security Today’s 2025 CyberSecured Award Turning a Flood of 5G Data into Rocket Fuel for AIOps NETSCOUT Recognized by Comparably as a Top Workplace for Q4 2025 How to deliver consistent ultra-low latency, high-throughput, and total reliability across complex networks Smart Data: The Super Fuel Driving Next-Gen Observability NETSCOUT Recognized for Leadership in Network Detection and Response Integrating Deep Packet Inspection in 5G Networks Removing Barriers to Digital Transformation Gain Real-time Visibility to Future Proof Your Network for Autonomous Operations Why Is Cloud Performance Still Foggy? Smarter DDoS Security at Scale How DPI Is Transforming Observability and Operational Resilience 10 Key Challenges to Optimizing Radio Access Networks in the 5G Era Why Arbor Edge Defense and CDN-Based DDoS Protection Are Better Together NETSCOUT’s Holiday Playlist for IT Teams and Leaders More Data Does Not Always Equate to Better Business Visibility Seeing Clearly with Deep Packet Inspection at Scale How to Ensure High Availability for FWA Services System Integrators and the Future of Enterprise IT The Transformative Power of ‘Thinking’ AI and the Implications for Business How Fast Can Your Organization Identify and Resolve IT Outages? Observability for the “Always On” Power Industry
The Shrinking Lifespan of SSL/TLS Certificates | NETSCOUT
Eileen.Haggerty · 2026-04-23 · via NETSCOUT

In a blog in late January, we discussed new NETSCOUT nGenius capabilities designed to help organizations prevent service disruptions. With Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate lifespans now shrinking dramatically, and playing a critical role in digital trust, it’s worth examining why certificate management has become a far more urgent challenge.

Certificate Volume

SSL/TLS certificates, widely used to encrypt communications and authenticate servers, ensure that sensitive data traveling between applications, users, and services remains secure. As organizations scale their digital infrastructure across cloud platforms, application programming interfaces (APIs), microservices, and hybrid environments, the number of certificates they must manage has exploded.

Estimates of certificate volume vary widely, from 3,500 to 5,000 certificates in average enterprises to more than 250,000 in large Fortune 2000 enterprises. The disparity reflects not only organizational size but also the pace of digital transformation, infrastructure complexity, and the maturity of certificate management strategies.

Several common conditions continue to drive certificate volume, including:

  • Growth in websites, mobile applications, email servers, virtual private networks (VPNs), and microservices used by a company
  • Decentralized teams, departments, or business units operating independently
  • Mergers and acquisitions that introduce parallel or overlapping IT environments
  • Shadow IT activities that deploy untracked or rogue certificates
  • Legacy systems that retain abandoned or forgotten certificates
  • External vendor partners managing certificates for marketing campaigns, customer portals, career sites, or investor pages

Shrinking Certificate Lifespans

Major policy changes by browser vendors and certificate authorities are rapidly shrinking certificate lifespans. SSL/TLS certificates in 2020 were valid for multiple years, but their renewal has become a more frequent operational task. Explosion in certificate volumes is coming at the same time as increased security and regulatory requirements for protecting enterprise networks, such as Health Insurance Portability and Accountability Act (HIPAA), Digital Operational Resilience Act (DORA) in Europe, and Payment Card Industry Data Security Standard (PCI DSS).

Organizations must adjust to drastically reduced certificate lifespans:

  • Previous to March 14, 2026: Certificates could be valid for up to 398 days
  • Today: Maximum validity is dropping to 200 days
  • March 15, 2027: Certificates will be limited to 100 days
  • March 15, 2029: Major browsers are expected to enforce a 47-day certificate lifespan

These changes are designed to strengthen internet security by ensuring certificates are rotated more frequently. However, as organizations have scaled their digital operations, the number and complexity of certificates have far outpaced manual management methods, leaving them exposed to outages, compliance failures, and escalating operational and cybersecurity risks. Companies managing hundreds of thousands of certificates will soon face renewal cycles measured in weeks, a pace that traditional observability and monitoring tools are not designed to handle.

Risks of Poor Certificate Management

The consequences of poor certificate visibility are already significant. Industry research shows that more than half of organizations have experienced unacceptable, certificate-related risks, including:

  • Service or application outages caused by certificate issues
  • Disruptive data breaches, which undermine customers’ trust, attributed to avoidable certificate management failures
  • Certificate-related service outages costing more than $100,000 per incident, although the true cost is higher when factoring productivity loss, brand damage, and compliance exposure

The combination of shorter lifespans, expanding certificate inventories, and limited visibility creates a perfect storm for both operational and security risks. Expired certificates can immediately disrupt business activity, including:

  • Customer-facing websites
  • Mobile applications
  • Internal enterprise services
  • API integrations
  • Cloud workloads and microservices

Equally concerning is how weak certificate management increases cybersecurity exposure. Mismanaged certificates can allow attackers to exploit expired keys, bypass trust controls, or conduct man-in-the-middle (MITM) attacks against encrypted communications. As digital services continues to scale, even a single overlooked certificate can cascade into widespread outages or serious security incidents.

Closing the Certificate Visibility Gap with NETSCOUT

To address these challenges, organizations need more than basic monitoring. They need deep, automated visibility into their infrastructure. This is where NETSCOUT provides a critical advantage. By continuously observing and analyzing network traffic, NETSCOUT can automatically discover and monitor certificates across the environment, delivering unique capabilities that extend well beyond the limitations of legacy monitoring tools.

Key NETSCOUT nGenius capabilities include:

  • Comprehensive certificate discovery across applications, services, and traffic flows, enabling organizations to build a complete inventory of active certificates
  • Automated expiration monitoring and alerts, providing proactive warnings so teams can remediate issues early and prevent certificate-related outages
  • Automated analysis of certificate health and usage, leveraging analytics to identify anomalies, misconfigurations, and potential certificate-related security risks

NETSCOUT’s enhanced Certificate Monitor in nGeniusONE delivers real-time insights to maintain valid SSL certificates and proactively identify those approaching expiration. This helps prevent costly downtime, avoid browser security warnings that erode user trust, ensure compliance, and reduce exposure to vulnerabilities such as misissued or weak certificates.

A key advantage of NETSCOUT’s certificate monitoring capability is reliance on packets. By analyzing network traffic, nGeniusONE uncovers certificates missed by traditional tools, including those running on nonstandard ports or hidden within unexpected services. It will even discover certificates introduced through shadow IT, where a business group deploys a web page or service outside established IT processes.

Preparing for the Future of Certificate Management

The upcoming shift to 100-day, and eventually 47-day, certificate lifespans represents a fundamental change in how organizations must manage digital trust. What once required occasional administrative oversight will soon demand continuous monitoring and automation.

Organizations that rely on manual processes or incomplete observability will struggle to keep up with the pace of certificate renewal cycles, resulting in increased outages, higher operational costs, and greater cybersecurity risk. As certificate lifespans continue to shrink, proactive monitoring is no longer optional. It is essential for protecting uptime, maintaining customer trust, and securing the encrypted infrastructure that powers today’s digital economy.

By providing automated certificate discovery, monitoring, and proactive alerting, NETSCOUT helps organizations eliminate this blind spot—ensuring that certificates remain valid, secure, and aligned with the increasingly rapid cadence of modern internet security standards. 

Learn more about NETSCOUT’s certificate monitoring capabilities and how one customer reduced time-consuming certificate expiration management, which helped avoid customer service impact.