Discovery must come before automation
You cannot automate certificates you cannot see. Build an inventory that ties each certificate to a service, an owner, a renewal method and a dependency. A scanner alone is not enough; include keystores, appliances and certificates issued outside the central CA.
Renewal is not deployment
A renewed certificate can still sit unused while the expired certificate remains bound to the application. Monitor issuance, delivery, binding and live presentation as separate states.
- Alert on failed renewal before the validity window becomes urgent
- Verify the certificate actually served by the endpoint
- Test revocation and chain building from the client networks that depend on it
This field note is general technical guidance. The safe remediation sequence depends on the hierarchy, clients and controls in the actual estate.