Preparing for the Era of 47-day Digital Certificates with Keyfactor Command
Toyota Tsusho Systems Corporation (TTS) has officially announced the launch of a new solution called
Keyfactor Command, aimed at automating the management and renewal of digital certificates and Public Key Infrastructure (PKI). This launch comes in response to the exponential increase in the number of digital certificates used within corporations, spurred by the growth of Zero Trust security and cloud utilization. Furthermore, a significant change in the validity period of SSL/TLS certificates has heightened the need for corporations to adopt a sophisticated certificate management framework.
The Shift from 398 Days to 47 Days
In April 2025, the CA/Browser Forum will implement a phased reduction of SSL/TLS certificate validity periods. Currently validated for 200 days, this timeframe is set to shrink to just 47 days by 2029. This shift signifies that organizations will need to transition from updating their certificates roughly once a year to approximately every six weeks. Traditional methods of managing and renewing certificates utilizing spreadsheets or manual oversight are increasingly inadequate.
Rising Operational Burden of Certificate Management
For many businesses, the number of digital certificates in use can range from dozens to thousands. To illustrate, if a company holds 150 certificates that require an average of two hours for each renewal, that amounts to around 450 hours annually at the current 200-day validity. However, transitioning to the 47-day renewal policy would escalate that demand to approximately 2,400 hours per year—an increase of over five times the current operational burden. Companies possessing a larger volume of certificates will inevitably face greater challenges, further underscoring the impracticality of relying solely on human resources for management. To thrive in this evolving landscape, organizations must shift their focus from merely managing certificates to automating the renewal process.
The Consequences of Poor Certificate Management
Failure to adequately manage digital certificates can expose companies to various risks:
1.
System Downtime Due to Oversights: Expired certificates can lead to significant operational disruptions, bringing business continuity into question. An uptick in renewal frequency amplifies this risk.
2.
Security Incidents: Failure to manage certificates can leave vulnerabilities open to exploitation, increasing the risk of identity theft and data interception.
3.
Governance and Compliance Challenges: Different management methods across departments can complicate company-wide oversight and audit compliance.
To mitigate these issues, companies need solutions that provide visualization, centralized management, and automation of certificate processes.
What Is Keyfactor Command?
Keyfactor Command is a comprehensive certificate lifecycle management (CLM) platform that integrates the management of digital certificates and PKI. It enables organizations to oversee the entire spectrum of certificate issuance, renewal, and revocation through a single interface, thereby streamlining operations and enhancing governance.
Main Features of Keyfactor Command:
- - Unified Management Across Multiple Issuers: Whether it's public CAs like GlobalSign or private CAs such as AWS Private CA, organizations can unify their certificate management under one umbrella.
- - Automated Renewal Processes: Keyfactor supports various protocols such as ACME and SCEP, ensuring automatic distribution and updates across servers and devices.
- - Efficiency Improvements Through Workflows: Keyfactor automates workflows related to requests, approvals, issuances, and notifications, leading to substantial reductions in operational overhead.
- - Detection of Unmanaged Certificates: The platform’s SSL scanning functionality identifies unmanaged or vulnerable certificates, safeguarding investment in digital security.
Practical Applications of Keyfactor Command:
1.
Centralized Management for Multi-CA SSL/TLS Certificates: Addressing the risk of missed updates by consolidating certificates spread across departments.
2.
Automated Renewal Operations: Facilitating the transition to increased renewal frequencies ahead of the impending 47-day requirement without adding manual workload.
3.
Zero-Trust and Cloud Environment Adaptation: Providing seamless management across both on-premises and cloud resources.
Strategic Partnership with Keyfactor
In September 2024, TTS entered into a strategic partnership with Keyfactor and Toyota Tsusho Corporation. By blending TTS's experience with large-scale PKI operations in the automotive sector alongside Keyfactor's advanced PKI and cryptographic asset management capabilities, they aim to assist clients from initial planning through design, implementation, and operation in a singularly integrated approach.
Conclusion: Transitioning from Manual to Automated Management
The move to a 47-day SSL/TLS certificate validity period in 2029 will necessitate profound change in how organizations operate. Increasing update frequencies will render traditional, manual renewal methods unviable, demanding a shift towards a more automated framework. Keyfactor Command offers tools that promote visibility, automation, and control in certificate management, ultimately bolstering an organization’s digital trust foundation. TTS remains committed to facilitating secure digital infrastructure for its clients by delivering not only CLM solutions but various PKI solutions throughout the industry.
Contact Information:
For inquiries regarding Keyfactor Command, please contact:
Toyota Tsusho Systems Corporation
Department: Technical Solutions Mobility Security
Inquiry site:
Keyfactor Command
About Toyota Tsusho Systems Corporation
- - Company Name: Toyota Tsusho Systems Corporation
- - Location: Nagoya, Aichi
- - Founded in: 1994
- - CEO: Hiroshi Watanabe
- - Shareholding: 100% owned by Toyota Tsusho Corporation
- - Website: Toyota Tsusho Systems