On-premises certificate lifecycle management is the automated discovery, issuance, deployment, renewal and revocation of digital certificates — run entirely inside your own network, with no external service holding your keys or your inventory.

For most organisations that is a preference. For defence, government, financial services, healthcare and critical infrastructure it is a requirement, and it rules out the majority of the CLM market in a single stroke.

PKI Insights is built for exactly that constraint. It deploys on your infrastructure and never transmits a private key outside your environment — while automating certificate renewal across Windows and Linux, web servers, load balancers, databases, Microsoft infrastructure and anything else you run.

On-premises describes where the platform runs. It does not restrict which certificate authority you use. PKI Insights issues from public CAs including DigiCert and Sectigo over ACME, and from private CAs including Microsoft ADCS, EJBCA, HashiCorp Vault and Khatim PKI Server — often both, across the same estate, from the same console.

pki-insights-clm-dashboard

Why on-premises certificate lifecycle management matters now

Public TLS certificate lifetimes are on a fixed reduction schedule:

  • 200 days from March 2026
  • 100 days from March 2027
  • 47 days from March 2029

Each step multiplies renewal volume against an estate that keeps growing.

That pressure pushes every organisation towards automation. But the dominant CLM platforms are SaaS, and SaaS creates a set of problems that regulated buyers cannot accept:

  • Key custody. Private keys, or the ability to generate them, sit with a third party.
  • Outbound connectivity. A platform that phones home cannot run in a segmented or air-gapped network.
  • Data residency. Certificate inventory is a map of your infrastructure. Under GDPR, NIS2, DORA and national sovereignty rules, that map may not be permitted to leave the jurisdiction.
  • Availability coupling. If your CLM provider has an outage during a renewal window, your certificates expire on their schedule, not yours.

On-premises certificate lifecycle management removes all four. The platform runs where your infrastructure runs, under your change control, inside your security boundary.

Air-gapped certificate lifecycle management

Air-gapped networks are the hardest test any CLM platform faces, and most fail it immediately. If the product requires outbound connectivity to a vendor cloud for licensing, telemetry, updates or issuance, it cannot operate on a network with no route to the internet.

PKI Insights runs fully offline. In an air-gapped certificate lifecycle management deployment:

  • Discovery, enrolment, deployment, monitoring and renewal all execute inside the enclave
  • Certificates are issued by a CA reachable from inside the enclave — Microsoft ADCS, EJBCA, HashiCorp Vault or Khatim PKI Server, over ACME or direct integration
  • Private keys are generated and remain inside your environment; nothing is transmitted outward
  • No vendor telemetry, no licence call-home, no external dependency in the renewal path

The constraint in an air-gapped network is reachability, not protocol. ACME is not an internet-only protocol — an internal ACME-enabled CA works identically inside an enclave. What changes is that a public CA is unreachable by definition, so issuance comes from your private PKI. On a connected on-premises deployment there is no such limit: public and private CAs can be used side by side, with public TLS certificates issued from DigiCert or Sectigo and internal certificates from ADCS, all managed from one inventory.

This is what makes PKI Insights deployable in classified networks, defence environments, OT and industrial control networks, and any enclave operating under a formal no-egress policy.

What is certificate lifecycle management?

Certificate lifecycle management (CLM) is the automated governance of digital certificates from request through to expiry or revocation. A CLM platform maintains an authoritative inventory of every certificate in the environment, knows where each is installed, tracks how long each has left, and renews and redeploys it before it expires — without a human opening a ticket.

The distinction that matters is between tracking and managing. A spreadsheet or a monitoring alert tells you a certificate is about to expire. A CLM platform renews it, installs it on the endpoint, reloads the service and confirms the new certificate is being served. The first still needs an engineer at 2am. The second does not.

The six stages of the certificate lifecycle

  • Discovery. Find every certificate already in the environment, including the ones no inventory records. Shadow certificates on forgotten appliances cause outages precisely because nobody is watching their expiry dates.
  • Enrolment. Generate the key pair and CSR, and request the certificate from the appropriate CA with the correct template, key usage and subject.
  • Deployment. Install the key and certificate on the target endpoint in the format that endpoint requires — Windows certificate store, PEM file pair, Java keystore, or a vendor-specific API.
  • Monitoring. Track validity, chain integrity, key strength and algorithm continuously, not on a scheduled audit.
  • Renewal. Repeat enrolment and deployment ahead of expiry, reload the dependent service, and verify the endpoint is serving the new certificate.
  • Revocation. Withdraw trust immediately when a key is compromised or a system is decommissioned, and confirm the revocation is published.

PKI Insights covers all six on-premises. Many platforms cover three or four and leave the rest manual.

PKI Insights CLM supported platforms

Platform category Supported systems Certificate formats
Web and application servers IIS, NGINX, Apache Tomcat, Oracle WebLogic PFX, PEM, DER
Load balancers, proxies and WAF F5, HAProxy, Citrix NetScaler, FortiWeb PFX, PEM
Databases Microsoft SQL Server, MySQL, PostgreSQL PEM, PKCS#12
Microsoft infrastructure ADFS, Exchange Server, RDP PFX, PKCS#12
Virtual apps and messaging Citrix StoreFront, RabbitMQ PFX, PEM, PKCS#12
Certificate authorities DigiCert, Sectigo, Microsoft CA (ADCS), EJBCA, HashiCorp Vault, Khatim PKI Server, and any public or private CA supporting ACME Multiple formats
Operating systems Windows Server (all versions), Linux Platform-native
Anything else Custom/Agentic scripts via the pluggable CLM module Any format

How PKI Insights reaches endpoints it cannot connect to directly

Every enterprise has systems that no management platform can talk to. An appliance with only a console. A bespoke application that stores its certificate in a proprietary location. A host behind a jump box, in a separate security zone, or on a network segment that permits no inbound connection. These are usually the endpoints that cause outages, precisely because no tool covers them.

Where direct connectivity exists

PKI Insights connects to the target system itself, using its API or management interface, and completes the full cycle without intermediation. This covers most of the estate: IIS, NGINX, F5, Citrix NetScaler, FortiWeb, ADFS, Exchange, SQL Server and the rest of the supported platform list.

Where it does not

The platform still performs every security-sensitive and stateful step. Only the final handover is delegated:

Step Handled by
Certificate discovery and inventory PKI Insights
Key pair generation PKI Insights Agent
CSR creation and submission PKI Insights
CA communication and issuance PKI Insights
Format conversion (PFX, PEM, DER, PKCS#12) PKI Insights
Renewal scheduling and expiry tracking PKI Insights
Placing the key and certificate on the target PKI Insights Agent or custom script
Reloading or restarting the dependent service PKI Insights Agent or custom script

Why the split is drawn there

  • Key custody stays in one place. Key generation never moves into the script.
  • One inventory, no blind spots. A scripted endpoint appears in the same console, with the same expiry countdown and the same renewal history, as a natively integrated one.
  • No dependency on a vendor roadmap. Support for a new platform does not require waiting for a release. If a system can receive a file and reload a service, it can be automated now.

Why manual renewal stops working at 100 days

At 100-day maximum validity, a practical cadence is roughly 90 days — four renewals per endpoint per year. At one hour of engineer time per renewal, covering request, retrieval, installation, chain update, service reload and verification:

Certificates Renewals per year Engineer hours per year Equivalent headcount
20 80 80 ~2 working weeks
250 1,000 1,000 ~0.6 FTE
500 2,000 2,000 ~1.1 FTE
1,000 4,000 4,000 ~2.2 FTE
5,000 20,000 20,000 ~11 FTE

At 47 days in 2029, every figure doubles.

PKI Insights - CLM - Alerts
Renewal outcomes over seven days. Manual renewals fail; automated ones are tracked either way.

Read the full analysis: The 100-Day Deadline Lands March 2027

Any CA — public or private

Most CLM platforms are built around a preferred certificate authority, and the further you move from it the more the automation degrades. PKI Insights treats the CA as an interchangeable component.

  • Public CAs. DigiCert, Sectigo and any publicly-trusted CA supporting ACME. Use these for externally-facing TLS where browser trust is required.
  • Private CAs. Microsoft ADCS, EJBCA, HashiCorp Vault and Khatim PKI Server. Use these for internal service-to-service certificates, device identity, and anything inside the perimeter.
  • Both at once. A typical enterprise estate needs both — public certificates on the edge, private certificates behind it. PKI Insights manages them in a single inventory with a single renewal engine, rather than forcing two tools and two sets of expiry dates.

This matters more as lifetimes shorten. When a public certificate renews four times a year and an internal one renews on a separate cycle from a separate system, the gaps between the two inventories are where outages live.

ACME support for automated certificate issuance

PKI Insights uses ACME (RFC 8555) for automated certificate issuance and renewal against public CAs, and direct integration for private ones. ACME is the protocol that turns certificate requests from a ticketed human process into an API exchange, and it is what makes short-lived certificates survivable at scale.

ACME matters more than the certificate lifetime schedule alone suggests. The CA/Browser Forum ballot that reduces validity also reduces how long domain control validation data can be reused: 200 days today, 100 days from March 2027, and just 10 days from March 2029. Past that point you cannot issue from cached validation — domain control has to be re-proven on almost every renewal. That is a different engineering problem from installing a certificate, and only a programmatic protocol solves it.

Certificate auto-renewal without vendor lock-in

PKI Insights performs renewals directly on target systems using lightweight agents, supporting PFX, PEM, DER and PKCS#12. The platform is CA-agnostic and endpoint-agnostic, suitable for mixed estates spanning Windows, Linux, on-premises and cloud.

  • Eliminates manual renewal effort
  • Removes outage risk from missed expirations
  • Avoids dependency on proprietary runtime integrations
  • Keeps every private key inside your infrastructure

Why CLM alone is not enough

Automating renewal without understanding PKI posture propagates risk faster than it fixes it. Weak templates, misconfigured CAs, improper key usage and excessive enrolment privileges are not corrected by automation. They are renewed on schedule, four times a year, with less human review at each step.

Automation keeps certificates alive. Posture keeps trust intact.

PKI Insights combines:

  • Certificate Lifecycle Management — automated issuance, deployment and renewal
  • PKI Posture Management — continuous assessment of CA configuration, templates, crypto policy and trust paths, including the full family of ADCS ESC misconfigurations
  • PQC Readiness — post-quantum posture across certificates, endpoints and issuing infrastructure

Read more: What Should Enterprises Prioritize First: PKI CLM or PKI Posture?

Why security teams choose PKI Insights

  • Fully on-premises and air-gap capable — keys never leave your infrastructure
  • Unified CLM across heterogeneous platforms
  • Agent-based renewals with no vendor lock-in
  • Posture-aware automation aligned to secure CA and template configuration
  • Reduced operational toil and fewer emergency changes
  • Audit-ready visibility into renewal history and deployment state
  • PQC-aware roadmap for hybrid TLS and crypto transitions

FAQ

What is on-premises certificate lifecycle management?

It is CLM deployed entirely within your own infrastructure rather than consumed as a cloud service. The platform, the certificate inventory and the renewal process all sit inside your network boundary, under your change control. No private key or inventory data is transmitted to a vendor.

Can on-premises CLM issue certificates from a public CA?

Yes. On-premises describes where the management platform runs, not where certificates come from. PKI Insights issues from public CAs including DigiCert and Sectigo over ACME, and from private CAs including ADCS, EJBCA, HashiCorp Vault and Khatim PKI Server. Most enterprises use both — public certificates on external endpoints, private certificates internally — managed from a single inventory.

Can certificate lifecycle management work in an air-gapped network?

Yes, but only if the platform has no cloud dependency in its licensing, updates, telemetry or issuance path. Most SaaS CLM products cannot operate without outbound connectivity. PKI Insights runs fully offline, issuing from your internal CA with no external call in the renewal path.

Does ACME work in an air-gapped network?

Yes. ACME is a protocol, not a cloud service. An internal ACME-enabled CA inside the enclave works exactly as a public one does. What an air gap removes is reachability to public CAs, so issuance comes from your private PKI — the automation itself is unchanged.

How does CLM handle internal certificates from ADCS?

Internal certificates are not governed by CA/Browser Forum rules, but the same arithmetic applies as organisations voluntarily shorten internal lifetimes. PKI Insights manages certificates from Microsoft ADCS, EJBCA, HashiCorp Vault and Khatim PKI Server alongside publicly-trusted ones.

Does certificate lifecycle management require agents?

PKI Insights uses a lightweight agent in both cases — what changes is what the agent does once the certificate is issued.

  • For supported platforms, the agent uses a built-in integration: it generates the key, installs the certificate in the form that platform expects, and reloads the service natively. IIS, NGINX, F5, Citrix NetScaler, FortiWeb, ADFS, Exchange and SQL Server all work this way, with no configuration beyond connecting the endpoint.
  • For anything outside that list, the same agent runs an agentic script. The script handles only the final delivery — placing the key and certificate where that particular system expects them and restarting whatever depends on them. Everything before that point is unchanged: PKI Insights generates the key, submits the CSR, obtains the certificate from your chosen CA, converts the format and holds the renewal schedule.

The agent is the execution point in both modes. The script is not a second product or a separate automation to maintain; it is the last step of the same pipeline, for endpoints no built-in integration covers yet.

What is the difference between CLM and PKI?

PKI is the trust infrastructure — the certificate authorities, keys and policies that issue and validate certificates. CLM is the operational layer managing the certificates PKI produces across their lifetime. You can have PKI without CLM, which is how most organisations arrive at a manual renewal problem.