← All notes

2026-07-27 · EdgeFXN

Before you buy a cert manager, count your domains

Every certificate outage we've ever been called about had the same root cause: a hostname nobody was watching. It was set up years ago, moved to a different DNS provider, or handled by a team that no longer exists.

Inventory in four steps

  1. Pull every DNS zone you own. Include the ones that redirect. Include the country-code variants.
  2. Enumerate hostnames. Every A, AAAA, and CNAME. If it resolves, it needs a cert.
  3. Scan each hostname. Grab the cert's issuer, expiry, chain length, SANs, and TLS config. Tools: openssl s_client or a wrapper.
  4. Compare against your ACME provider. Every hostname you own should be renewable by exactly one automation. Anything else is a future 2 a.m. page.

Then, and only then, buy tooling

Once you know what you have, picking a cert manager is easy. What kills you is not the tool — it's the missing hostname. Our SSL & Certs engagement starts here every time.


Want us to run this for you?

Tell us your stack and we'll come back with a scoped engagement within one business day.

Book a session