Notes on machine identity.
Short posts in plain words on certificates, keys and the machines that hold them, from the person building trstctl.
Every external fact links to its source. Every claim about trstctl links to the code or the design document it comes from, and is checked against the repository before it is published. Corrections are welcome as an issue on the trstctl repository.
47 days: what actually changes
The CA/Browser Forum has cut the lifetime of a public TLS certificate to 47 days by March 2029, and the proof that you own a name to ten days. The schedule, what breaks, and the four moves that make it a non-event.
PKI in plain words
Certificates, private keys, authorities, chains, domain-control validation, ACME, expiry, revocation and transparency logs, explained for someone who owns more certificates than they can name.
Why the signer is a separate process
Automation has to sign certificates all day. It should never hold the keys. How trstctl draws that line, what the line guarantees, and what it does not, with links to the code.
Machine credentials beyond TLS
The 47-day schedule is the visible tip of a bigger shift: every credential a machine holds is moving to short lifetimes. SSH, secrets, tokens, workload identity, code signing and now AI agents, and why one inventory beats seven.
Stop buying certificates. Start owning renewals.
A public TLS certificate has been free for ten years. What you are still paying for, whether you buy it or not, is the renewal. What free already covers, where a purchase still makes sense, and the five jobs that are yours either way.