Members of the Certificate Authority/Browser Forum have voted to shorten the lifespan of SLS/TLS certificates to just under seven weeks. The changes will roll out gradually over the next several years until March 2029, when certificate lifetimes will be limited to 47 days. While the organization has argued that shortening the duration of the certificates' viability will improve security, others point out that the entities issuing the certificates will benefit financially from the changes. While no members of the CA/Browser Forum voted against the move, five members abstained from voting.
On March 15, 2026, the maximum lifecycle will be 200 days, requiring six-month renewals, and on March 15, 2027, it shrinks to 100 days, requiring 90 day renewals. Finally on March 15, 2029, the interval shrinks to 47 days, with an expected monthly renewal. At this point the move is to automate all SSL/TLS certificate renewals. Find servers and appliances you're not currently automating certificate management for and work with your suppliers for solutions while you have a bit of time; March 2026 isn't that far out for making changes to business and other high stability services. Find out the certificate interval where you have automation; you may be surprised how rapidly you already are updating certificates.
In light of this, what are others doing to prepare for monthly update of SSL certificates on IBM MQ Queue managers in production?
------------------------------
Anthony Julian
Technical Specialist II
Mayo Clinic
Rochester MN
5072545963
------------------------------