SSL/TLS Certificate Architecture & Lifecycle
•Why are certificate lifetimes dropping?
The CA/Browser Forum reduced standard certificate validity to 398 days, with industry proposals pushing toward 90-day lifespans. Short lifespans limit private key exposure but require continuous automated perimeter auditing to prevent unexpected outages.
•What are the 30d, 14d, and 7d thresholds?
SubdomainWatch enforces three distinct alert milestones: 30 days (standard automated renewal window), 14 days (urgent escalation when ACME pipelines stall), and 7 days (critical emergency alert before browser security interstitials block your visitors).
•What causes Hostname Mismatch errors?
Under RFC 6125, single-level wildcards (*.example.com) protect immediate subdomains, but do NOT cover deep subdomains (app.api.example.com) or the bare apex domain (example.com).
•How does automated monitoring work?
SubdomainWatch continuously enumerates all subdomains across your domain perimeter, probing port 443 with transactional outbox dispatching to Slack and Resend email channels whenever a milestone is breached.