CMOtech Ireland - Technology news for CMOs & marketing decision-makers
Ireland
ManageEngine automates final TLS certificate deployment

ManageEngine automates final TLS certificate deployment

Mon, 20th Jul 2026 (Yesterday)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

ManageEngine has added post-deployment automation for transport layer security certificates in Key Manager Plus, aiming to remove the final manual stage in certificate renewal.

Key Manager Plus can now push renewed certificates to target servers, run configured scripts, restart dependent services, and notify stakeholders after deployment. The feature is available for both on-premises and cloud deployments.

The update comes as organisations prepare for shorter validity periods for public TLS certificates. Under changes approved by the CA/Browser Forum, the traditional 398-day validity period is being reduced in stages, with a 200-day period already in place, followed by 100 days and then 47 days.

That shift is forcing IT and security teams to rethink certificate handling, particularly in large estates where renewals can multiply across domains, servers, and internal processes. Tasks previously carried out once a year could soon recur several times over, increasing the operational burden and the risk of misconfiguration or service disruption.

Last step

Certificate management tools have typically focused on discovery, inventory, expiry alerts, and in some cases automated renewal. The work after renewal has often remained manual, including installing the certificate on the relevant system, restarting services, and checking that the new certificate is live.

ManageEngine is aiming to address that gap by extending automation to the final deployment stage, closing the lifecycle loop for organisations seeking zero-touch certificate management.

Jonathan Choiniere, Infrastructure Manager at RevSpring, described the scale of the challenge for businesses managing growing certificate estates.

"We're going from under 200 certificates to over 2,000, across a lot of domains, different server setups, credentials and post-deployment actions for nearly all of it. We've had to dedicate significant engineering time to certificate management alone since the change to 200 days. With the 47-day certificate renewals coming up, automation is the only way we can keep up, and Key Manager Plus' CA-agnostic, certificate lifecycle management has helped us automate the whole thing," Choiniere said.

The remarks reflect a wider industry concern as certificate validity windows continue to contract. More frequent renewals can increase administration costs, especially in mixed environments that rely on separate workflows for deployment and service restarts.

Operational pressure

ManageEngine also used the launch to highlight the financial and operational risks of manual renewal processes. If certificates are not deployed correctly or associated services are not restarted in time, websites, applications, and internal systems can suffer outages.

The impact becomes more pronounced as certificate lifespans shrink and the same sequence of tasks must be repeated more often. In large organisations, even minor deployment errors can have material consequences when they affect customer-facing systems or critical business applications.

Vasudevan Seshadri, Director of Product Management at ManageEngine, said the main burden is no longer issuance itself but the work required to complete deployment safely across multiple systems.

"Certificate renewal is rarely the hard part. The work that piles up on teams is what comes after it, at scale: pushing certificates to the server, restarting the services, and confirming they actually went live. End-to-end automation is what turns a 47-day renewal cycle from a scramble into something that runs on its own. With Key Manager Plus, we are eliminating the last manual step in the lifecycle management loop," Seshadri said.

Impact calculator

Alongside the product update, ManageEngine has released a 47-day TLS impact calculator to help organisations estimate how the shorter certificate cycle could affect them. The tool is based on the size of a company's certificate estate, the labour involved in current renewal processes, and potential exposure to outages.

That reflects a growing focus among software suppliers on helping customers quantify operational risk as compliance and infrastructure requirements evolve. In the case of TLS certificates, the challenge is not only technical but also organisational, because teams must align security, infrastructure, and application operations around much shorter renewal intervals.

Key Manager Plus sits within ManageEngine's broader security and IT management portfolio and is used to manage certificate lifecycles and other machine identities. The latest update suggests vendors in this segment are moving beyond monitoring and renewal into automation of the operational tasks that often determine whether a certificate change is completed without disruption.

With certificate validity periods heading towards 47 days, pressure on organisations to remove manual intervention from renewal workflows is likely to intensify.