Certificate automation levels

The CA/Browser Forum is an industry consortium of Certificate Authorities (CAs) and major browser vendors. It maintains the Baseline Requirements for publicly issued TLS certificates. Under these requirements, the maximum validity for public TLS certificates is being reduced on a defined schedule:

  • 200 days beginning on 15 March 2026

  • 100 days beginning on 15 March 2027

  • 47 days beginning on 15 March 2029

Additionally, the Domain Control Validation (DCV) reuse period will also reduce on the same schedule. (See the CA/B Forum Baseline Requirements, and Ballot SC-081v3 for details.)

To prepare, organizations should automate issuance and installation. Aperture provides an Automation Level filter, report, and widget to show where certificates are manual, partial, or fully automated.

Automation levels

Each certificate is assigned an automation level. These levels describe how much of the certificate lifecycle is automated. Higher levels mean more of the lifecycle is automated. Levels are calculated daily and when certificate settings are saved.

Automation level What it means
Unknown Certificate is unassigned, disabled, or automation is not yet calculated.
No Automation Certificate lifecycle is managed manually.
Pull Provisioning Issuance is automated via a known client (ACME, EST, WebSDK, SCEP, NDES) but installation is manual.
Auto Renewal Certificate automatically renews, but isn't linked to any applications.
Basic Application Certificate is linked to at least one "basic" application with auto-renewal enabled.
Disabled Application Certificate is linked to at least one "disabled" application with auto-renewal enabled.
Associated Not Provisioning Certificate is linked to valid apps, but not configured for provisioning.
Fully Automated End-to-end automation: issuance, renewal, and installation.

These names match the Automation Level filter and Automation Level column in reports.

Automation level details

Click the name of the automation level to see details about each level, including suggested actions for certificates at this level.

Automation Level filter and report

The Automation Level filter in the certificate inventory and in the reporting tool gives PKI administrators a detailed view of automation adoption across the entire certificate inventory.

To filter the certificate inventory

  1. In Aperture, go to Inventory > Certificates.

  2. In the Common Filters section, look for Automation Level.

  3. Select one or more automation levels, then click Apply Filters.

Matching certificates are shown in the inventory list.

To create a report based on automation levels

  1. In Aperture, go to Reports > Custom Reports.

  2. Click Add Report.

  3. Choose the Certificates data type.

  4. In the Common Filters section, look for Automation Level.

  5. Select one or more automation levels.

    The filter applies as you edit it.

  6. Click Next.

  7. Continue creating your custom report following the instructions in Creating a new custom report.

Automation Level widget

The Automation Level Widget provides a quick visual summary of your automation state.

To access the widget

  1. In Aperture, go to the All Certificates Dashboard.

  2. Locate the Automation Level widget in the widget panel.

The widget shows the percentage of certificates at each automation level. Click a pie segment or metric to see those certificates in the inventory with the filter applied.

Use the widget to quickly identify where automation is strong and where further effort is needed.