Before you buy a cert manager, count your domains
Every certificate outage we've ever been called about had the same root cause: a hostname nobody was watching. It was set up years ago, moved to a different DNS provider, or handled by a team that no longer exists.
Inventory in four steps
- Pull every DNS zone you own. Include the ones that redirect. Include the country-code variants.
- Enumerate hostnames. Every A, AAAA, and CNAME. If it resolves, it needs a cert.
- Scan each hostname. Grab the cert's issuer, expiry, chain length, SANs, and TLS config. Tools:
openssl s_clientor a wrapper. - Compare against your ACME provider. Every hostname you own should be renewable by exactly one automation. Anything else is a future 2 a.m. page.
Then, and only then, buy tooling
Once you know what you have, picking a cert manager is easy. What kills you is not the tool — it's the missing hostname. Our SSL & Certs engagement starts here every time.
Want us to run this for you?
Tell us your stack and we'll come back with a scoped engagement within one business day.