Certificate expiry still causes preventable outages. A lightweight checklist keeps renewals boring—in a good way.
- Inventory every hostname and SAN before renewal windows.
- Confirm ACME automation or vendor renewal alerts fire to a staffed channel.
- Stage renewal on staging that mirrors cipher suites and chain.
- Verify HTTP Strict Transport Security and redirects after deployment.
Store validation artifacts with the ticket so auditors can trace what shipped.