Certificate automation levels
The CA/Browser Forum is an industry consortium of Certificate Authorities (CAs) and major browser vendors. It maintains the Baseline Requirements for publicly issued TLS certificates. Under these requirements, the maximum validity for public TLS certificates is being reduced on a defined schedule:
-
200 days beginning on 15 March 2026
-
100 days beginning on 15 March 2027
-
47 days beginning on 15 March 2029
Additionally, the Domain Control Validation (DCV) reuse period will also reduce on the same schedule. (See the CA/B Forum Baseline Requirements, and Ballot SC-081v3 for details.)
To prepare, organizations should automate issuance and installation. Aperture provides an Automation Level filter, report, and widget to show where certificates are manual, partial, or fully automated.
Automation levels
Each certificate is assigned an automation level. These levels describe how much of the certificate lifecycle is automated. Higher levels mean more of the lifecycle is automated. Levels are calculated daily and when certificate settings are saved.
| Automation level | What it means |
|---|---|
| Unknown | Certificate is unassigned, disabled, or automation is not yet calculated. |
| No Automation | Certificate lifecycle is managed manually. |
| Pull Provisioning | Issuance is automated via a known client (ACME, EST, WebSDK, SCEP, NDES) but installation is manual. |
| Auto Renewal | Certificate automatically renews, but isn't linked to any applications. |
| Basic Application | Certificate is linked to at least one "basic" application with auto-renewal enabled. |
| Disabled Application | Certificate is linked to at least one "disabled" application with auto-renewal enabled. |
| Associated Not Provisioning | Certificate is linked to valid apps, but not configured for provisioning. |
| Fully Automated | End-to-end automation: issuance, renewal, and installation. |
These names match the Automation Level filter and Automation Level column in reports.
Automation level details
Click the name of the automation level to see details about each level, including suggested actions for certificates at this level.
Definition: The system cannot determine automation. Certificates may be unassigned, disabled, or not yet calculated.
How to Recognize:
- Management Type is Unassigned or the certificate is Disabled.
- Auto-Renewal and CA Template are unset or unknown.
Suggested Actions:
- Review if the certificate is in use.
- Assign a Management Type or re-enable if applicable.
Definition: Certificates are monitored only or issued manually.
How to Recognize:
- Management Type is Monitoring.
- Auto-Renewal is disabled or no CA Template assigned.
- May be created by an unrecognized client.
Suggested Actions:
- Assign a CA Template and enable Auto-Renewal.
- Standardize client identity if issued via API.
Definition: Certificate issuance is automated through a known client, but installation is still manual.
How to Recognize:
- Management Type is Enrollment or Provisioning.
- Known client (ACME, EST, WebSDK, SCEP, NDES).
- No application associations.
Suggested Actions:
- Add application associations.
- Configure push/provisioning to automate installation.
Definition: Certificates automatically renew, but are not linked to any applications.
How to Recognize:
- Auto-renewal enabled.
- CA Template assigned.
- No applications associated.
Suggested Actions:
- Associate the certificate with target applications.
- Configure provisioning to deliver certificates automatically.
Definition: Certificates are linked to at least one “basic” application with Auto-Renewal enabled.
How to Recognize:
- Auto-Renewal enabled.
- CA Template assigned.
- At least one associated application is Basic.
Suggested Actions:
- Migrate basic apps to fully supported integrations.
- Enable provisioning to those applications.
Definition: Certificates are linked to at least one “disabled” application with Auto-Renewal enabled.
How to Recognize:
- Auto-Renewal enabled.
- CA Template assigned.
- At least one associated application is Disabled.
Suggested Actions:
- Re-enable or replace disabled applications.
- Remove stale associations.
Definition: Certificates are associated with valid applications, but not configured for provisioning.
How to Recognize:
- Management Type is Enrollment.
- Auto-Renewal enabled.
- CA Template assigned.
- All associated applications are valid (not Basic or Disabled).
Suggested Actions:
- Switch Management Type to Provisioning.
- Configure push/provisioning for end-to-end automation.
Definition: Certificates are fully automated from issuance through delivery.
How to Recognize:
- Management Type is Provisioning.
- Auto-Renewal enabled.
- CA Template assigned.
- All associated applications are valid (not Basic or Disabled).
Suggested Actions:
- No action needed.
- Monitor automation coverage and maintain application associations.
Automation Level filter and report
The Automation Level filter in the certificate inventory and in the reporting tool gives PKI administrators a detailed view of automation adoption across the entire certificate inventory.
To filter the certificate inventory
-
In Aperture, go to Inventory > Certificates.
-
In the Common Filters section, look for Automation Level.
-
Select one or more automation levels, then click Apply Filters.
Matching certificates are shown in the inventory list.
To create a report based on automation levels
-
In Aperture, go to Reports > Custom Reports.
-
Click Add Report.
-
Choose the Certificates data type.
-
In the Common Filters section, look for Automation Level.
-
Select one or more automation levels.
The filter applies as you edit it.
-
Click Next.
-
Continue creating your custom report following the instructions in Creating a new custom report.
Automation Level widget
The Automation Level Widget provides a quick visual summary of your automation state.
To access the widget
-
In Aperture, go to the All Certificates Dashboard.
-
Locate the Automation Level widget in the widget panel.
The widget shows the percentage of certificates at each automation level. Click a pie segment or metric to see those certificates in the inventory with the filter applied.
Use the widget to quickly identify where automation is strong and where further effort is needed.