<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>trstctl blog</title>
    <link>https://blog.trstctl.com/</link>
    <description>Short posts in plain words on certificates, keys and the machines that hold them, from the person building trstctl.</description>
    <language>en</language>
    <atom:link href="https://blog.trstctl.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>47 days: what actually changes</title>
      <link>https://blog.trstctl.com/47-days-what-actually-changes</link>
      <guid isPermaLink="true">https://blog.trstctl.com/47-days-what-actually-changes</guid>
      <pubDate>Mon, 21 Sep 2026 09:00:00 GMT</pubDate>
      <description>The CA/Browser Forum has cut the lifetime of a public TLS certificate to 47 days by March 2029, and the proof that you own a name to ten days. The schedule, what breaks, and the four moves that make it a non-event.</description>
    </item>
    <item>
      <title>PKI in plain words</title>
      <link>https://blog.trstctl.com/pki-in-plain-words</link>
      <guid isPermaLink="true">https://blog.trstctl.com/pki-in-plain-words</guid>
      <pubDate>Mon, 21 Sep 2026 09:00:00 GMT</pubDate>
      <description>Certificates, private keys, authorities, chains, domain-control validation, ACME, expiry, revocation and transparency logs, explained for someone who owns more certificates than they can name.</description>
    </item>
    <item>
      <title>Why the signer is a separate process</title>
      <link>https://blog.trstctl.com/why-the-signer-is-a-separate-process</link>
      <guid isPermaLink="true">https://blog.trstctl.com/why-the-signer-is-a-separate-process</guid>
      <pubDate>Mon, 21 Sep 2026 09:00:00 GMT</pubDate>
      <description>Automation has to sign certificates all day. It should never hold the keys. How trstctl draws that line, what the line guarantees, and what it does not, with links to the code.</description>
    </item>
    <item>
      <title>Machine credentials beyond TLS</title>
      <link>https://blog.trstctl.com/machine-credentials-beyond-tls</link>
      <guid isPermaLink="true">https://blog.trstctl.com/machine-credentials-beyond-tls</guid>
      <pubDate>Mon, 21 Sep 2026 09:00:00 GMT</pubDate>
      <description>The 47-day schedule is the visible tip of a bigger shift: every credential a machine holds is moving to short lifetimes. SSH, secrets, tokens, workload identity, code signing and now AI agents, and why one inventory beats seven.</description>
    </item>
    <item>
      <title>Stop buying certificates. Start owning renewals.</title>
      <link>https://blog.trstctl.com/stop-buying-certificates-start-owning-renewals</link>
      <guid isPermaLink="true">https://blog.trstctl.com/stop-buying-certificates-start-owning-renewals</guid>
      <pubDate>Mon, 21 Sep 2026 09:00:00 GMT</pubDate>
      <description>A public TLS certificate has been free for ten years. What you are still paying for, whether you buy it or not, is the renewal. What free already covers, where a purchase still makes sense, and the five jobs that are yours either way.</description>
    </item>
  </channel>
</rss>
