Skip to main content

Richard Hicks

Microsoft MVP consultant and founder of Richard M. Hicks Consulting, Inc. specializing in PKI, enterprise mobility, and secure remote access with 30+ years of experience.

Jun 23, 2026

IgalHOST
11:23
I'm going to be super excited.
11:25
Yep.
11:26
So, yeah, so with regards to certificate rotation, automation is going to be key, right? We are going to have to automate this.
11:35
No one's going to want to rotate certificates manually every 30 days.
11:39
Today, that's the case because we do it annually.
11:42
So administrators, they're trained to do that.
11:45
They have run books.

13 MINS LATER

AaronHOST
24:23
yeah that's actually maybe a good segue into more of the private pki side we spent a good amount of time on on public but earlier on you mentioned that this movement to 47 days and a lot of the kind of strict uh deadlines being put on for public certificates doesn't apply to the private side but i'm curious uh what when you go in and and help companies of any size with their private pki for issuing their internal certificates What are the validity periods and timelines you typically recommend? Is it one size fits all or kind of how do you break those down based on the use case?
15:26
Right.
15:26
Microsoft has given us a bunch of, um, uh, tools to do that.
15:31
If you go to, I think it's, um, aka.ms/um, securebootplaybook, I think is the client version, and securebootforserver is the server version of that.
15:45
There's a ton of information there.
15:47
I won't rehash that, that here, but ultimately, there's a ton of information for ways to kick off the process, monitor the process, and so forth.
15:55
And, and back to the story I was, I started at the top of the, of the hour here, I wrote a PowerShell script because I was frustrated with the fact that the default command, uh, Get-SecureBoot, um, U- Get-UEFISecureBoot, I think is the command, doesn't return anything that I can readily look at.
16:15
So I wrote a PowerShell script called Get-UEFI Certificate-

6 MINS LATER

22:48
Mm-hmm

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.