• Sign in
  • Sign up
Elektrine
EN
Log in Register
Modes
Overview Chat Timeline Communities Gallery Lists Friends Email Vault DNS VPN
Back to Timeline
  • Open on infosec.exchange

CertKit

@certkit@infosec.exchange
mastodon 4.6.0-alpha.6+glitch

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

0 Followers
0 Following
Joined October 27, 2025
Website:
https://www.certkit.io/

Posts

Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · 1d ago

CertKit 1.9: push agent updates from the dashboard, no more logging into every server. Plus Google Trust Store as a second ACME issuer alongside Let's Encrypt.

https://www.certkit.io/blog/agent-1.9

#CertificateManagement #SSL

View on infosec.exchange
Remote Agent Updates and Google Trust Store
CertKit SSL Certificate Management

Remote Agent Updates and Google Trust Store

Agent 1.9 adds remote push updates so you can upgrade your entire fleet from the dashboard, plus first-class support for Google Trust Store as an ACME certificate issuer alongside Let's Encrypt.

0
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · 5d ago

Security vendors use "trust" as a magic spell. One homepage: 17 uses. I still don't know what they sell. You find out after you fill out a form, take a call, sit through a demo, and receive a market-ecture PDF.

https://www.certkit.io/blog/performative-trust-maximalism

#PKI #infosec

View on infosec.exchange
Performative Trust Maximalism
CertKit SSL Certificate Management

Performative Trust Maximalism

Certificate management vendors use the word "trust" so often it stops meaning anything. They also won't tell you what the product does, or what it costs, without a sales call first. These are, I shoul

1
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Apr 08, 2026

CertKit is out of beta.

600 signups. Real production deployments. A Keystore for keeping private keys on-prem. RDP and RRAS support for Windows shops.

Now there's real pricing — and 40% off forever if you get in before May 31st.

https://www.certkit.io/blog/out-of-beta

#PKI #CertificateManagement

View on infosec.exchange
CertKit is out of beta
CertKit SSL Certificate Management

CertKit is out of beta

We launched the beta in July 2025. Over 600 users later, the beta is over. Here's what we built, what we learned, and a thank you to the early adopters who helped make it real.

0
0
0
0
Open post
In reply to
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Apr 06, 2026
@filippo They may not matter much in volume, but lots of orgs are still tied to the OV/EV certs from legacy CAs. We still need to pull from just about all the CT Logs to get a complete picture for our discovery tool. https://www.certkit.io/tools/ct-logs/
View full thread on infosec.exchange
0
2
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Apr 01, 2026

CertKit Agent 1.8: Windows Certificate Store, Java Keystore, and RDP auto-detection.

We also shipped a retro MS-DOS confirmation dialog on April Fools Day. It is fully keyboard-compatible.

https://www.certkit.io/blog/agent-1.8 #CertificateManagement #PKI

View on infosec.exchange
CertKit Agent 1.8: Windows RDP, Windows Certificate Store, and Java keystores
CertKit SSL Certificate Management

CertKit Agent 1.8: Windows RDP, Windows Certificate Store, and Java keystores

Agent 1.8 closes the last gaps in Windows and Java certificate deployment. Write directly into the Windows Certificate Store, auto-detect Remote Desktop and Remote Gateway, drop JKS files for legacy J

2
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 30, 2026

Let's Encrypt ran a mass revocation drill on 3 million production certificates in March. No user notifications. They shortened ARI windows to signal an emergency and watched who responded.

Most ACME clients never noticed.

https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation

#PKI #ACME

View on infosec.exchange
Let's Encrypt simulated revoking 3 million certificates. Most ACME clients didn't notice.
CertKit SSL Certificate Management

Let's Encrypt simulated revoking 3 million certificates. Most ACME clients didn't notice.

Let's Encrypt ran their first annual mass revocation drill, shortening ARI renewal windows across 3 million production certificates. Here's what happened.

2
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 25, 2026

Some organizations have a hard requirement: private keys cannot leave the network perimeter. Third-party cert management has always meant violating that policy.

The CertKit Local Keystore is the fix. Keys stay on your infrastructure. Full automation still works.

www.certkit.io/blog/certkit-keystore

#PKI #CertificateManagement

View on infosec.exchange
infosec.exchange

Infosec Exchange

1
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 23, 2026

A 2024 PKI survey found organizations averaged 3 certificate outages over 24 months. In almost every case, the certificate renewed fine.

Distribution is where it fell apart.

https://www.certkit.io/blog/certificate-distribution-is-the-last-mile #PKI #infosec

View on infosec.exchange
Certificate distribution is the last mile nobody solved
CertKit SSL Certificate Management

Certificate distribution is the last mile nobody solved

Certbot solved certificate issuance. It's great at that. The hard part is everything that happens after: getting the certificate file to every server that needs it, in the right format, with the right

2
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 16, 2026

Mass revocation gives you 24 hours and thousands of certs to replace. ARI (RFC 9773) automates it, but only if your ACME client is always running.

Certbot uses a cron job. acme.sh has no ARI support.

https://www.certkit.io/blog/ari-solves-mass-certificate-revocation

#PKI #TLS

View on infosec.exchange
ACME Renewal Information (ARI) solves mass certificate revocation
CertKit SSL Certificate Management

ACME Renewal Information (ARI) solves mass certificate revocation

When a CA has to revoke hundreds of thousands of certificates on a short deadline, email notifications aren't enough. ARI is the protocol that lets the CA tell your client directly: renew now. Here's

0
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 11, 2026

CertKit now supports ACME ARI and 6-day certificates.

ARI means the CA tells us when to renew. We check it multiple times a day. Your next mass revocation event? Just another boring Tuesday.

Nothing to configure.

https://www.certkit.io/blog/acme-ari-and-6-day-certificates #PKI #infosec

View on infosec.exchange
ACME ARI support and 6-day certificates
CertKit SSL Certificate Management

ACME ARI support and 6-day certificates

CertKit now polls Let's Encrypt multiple times a day to check when each certificate should renew. That means mass revocations happen automatically, without you doing anything. We also added support fo

0
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 09, 2026

Your cert renewed. The old one is still serving.

LinkedIn renewed 10 days before expiry. It never deployed.

Most automation catches "forgot to renew." Nobody verifies the new cert is what the server is actually sending.

https://www.certkit.io/blog/how-to-verify-certificate-renewal #PKI #TLS

View on infosec.exchange
How to verify certificate renewal actually worked
CertKit SSL Certificate Management

How to verify certificate renewal actually worked

Certbot ran. The logs show success. Exit code 0. LinkedIn found out the hard way that renewed and deployed are not the same thing. The verify step is the part of certificate automation nobody builds u

1
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 04, 2026

Certificate management has always been a one-person job. CertKit now supports team access: role-based permissions, SAML SSO, MFA, and a weekly digest to keep the whole org in the loop.

https://www.certkit.io/blog/user-management #PKI #infosec

View on infosec.exchange
User management, MFA, SSO, and weekly summaries are live
CertKit SSL Certificate Management

User management, MFA, SSO, and weekly summaries are live

CertKit now supports team accounts with role-based access, multi-factor authentication, SAML single sign-on, and a weekly email digest. Here's what shipped and why it matters.

2
0
1
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Mar 02, 2026

March 15 is last call on 398-day certificates. After that, 200-day max, 100 in 2027, 47 in 2029.

Renew now and you buy yourself time to automate on your terms. Wait, and the CA/B Forum sets your schedule for you.

https://www.certkit.io/blog/last-call-on-398-day-certificates #PKI #WebPKI

View on infosec.exchange
Last call on 398-day certificates
CertKit SSL Certificate Management

Last call on 398-day certificates

The bar closes March 15. After that, no CA can serve you a 398-day certificate. If you're still managing commercial SSL certs manually, you have two weeks to grab one last round of full-year runway be

0
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Feb 25, 2026

CertKit Agent 1.6: RRAS support, deploy windows, and agent locking.

Shorter lifetimes mean certificate automation has to act like real deployments: issue, deploy, verify. Deploy windows keep disruptions inside maintenance windows, and agent locking freezes commands so UI changes can’t be weaponized.

https://www.certkit.io/blog/agent-1.6

#CertificateAutomation #WebPKI

View on infosec.exchange
CertKit Agent update: RRAS support, deploy windows, and agent locking
CertKit SSL Certificate Management

CertKit Agent update: RRAS support, deploy windows, and agent locking

The CertKit Agent now supports Microsoft RRAS for VPN certificate management. We also added deploy windows so you can control when certificate updates happen, and agent locking to protect your infrast

0
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Feb 23, 2026

22,000+ incidents in the Verizon DBIR. Man-in-the-middle? Less than 4%, mostly phishing proxies. Not TLS interception.

Forward Secrecy killed "record now, decrypt later." So what actually compromises your connections?

https://www.certkit.io/blog/man-in-the-middle

#cybersecurity #TLS

View on infosec.exchange
How likely is a man-in-the-middle attack?
CertKit SSL Certificate Management

How likely is a man-in-the-middle attack?

A stolen TLS private key sounds catastrophic. But thanks to forward secrecy, it can't decrypt recorded traffic. The only thing left is server impersonation, and that requires network position that ran

1
0
1
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Feb 18, 2026

Curious how CertKit works? I made a page for that.

https://www.certkit.io/how-it-works

View on infosec.exchange
How CertKit Works - Automated SSL Certificate Management
CertKit SSL Certificate Management

How CertKit Works - Automated SSL Certificate Management

CertKit automates your entire certificate lifecycle. Issue certificates via ACME, deploy them with the CertKit Agent, and verify everything with real TLS checks. No open ports, no ACME on your servers

0
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Feb 16, 2026

We found a valid DigiCert certificate on a domain we just purchased, issued to someone we've never met. Getting it revoked took 6 emails. 72 hours after confirmed revocation, every browser still trusts it.

https://www.certkit.io/blog/bygonessl-happened-to-us

#InfoSec #CertificateManagement

View on infosec.exchange
BygoneSSL happened to us
CertKit SSL Certificate Management

BygoneSSL happened to us

We wrote about BygoneSSL and the 1.5 million domains with certificates owned by someone else. Then we bought certkit.dev and found one on our own domain. A DigiCert certificate, still valid for 98 day

1
0
0
0
Open post
certkit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
CertKit
CertKit
@certkit@infosec.exchange

Automated SSL certificate management for IT teams who have better things to do. No scripts, no cron jobs. Free 90-day trial to start renewing your certificates.

infosec.exchange
@certkit@infosec.exchange · Feb 12, 2026

Most “certificate automation” stops at issuance. That’s how you renew a cert and still serve the old one.

With the CertKit agent, we can now do all three. Renew certs, deploy files, restart services, verify the correct certs run in production.

https://www.certkit.io/blog/certkit-agent

#PKI #DevOps

View on infosec.exchange
Introducing the CertKit Agent
CertKit SSL Certificate Management

Introducing the CertKit Agent

CertKit can now deploy certificates directly to your servers. The CertKit Agent is a lightweight service for Linux, Windows, and Docker that detects your software, writes certificates where they need

1
0
0
0

Media

313k7r1n3

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • VPN Policy

Email Settings

IMAP: mail.elektrine.com:993

POP3: pop3.elektrine.com:995

SMTP: mail.elektrine.com:465

SSL/TLS required

Support

  • support@elektrine.com
  • Report Security Issue

Connect

Tor Hidden Service

khav7sdajxu6om3arvglevskg2vwuy7luyjcwfwg6xnkd7qtskr2vhad.onion
© 2026 Elektrine. All rights reserved. • Server: 18:18:15 UTC