<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Idea: Add Native Automated Certificate Management (e.g., ACME) to ArcGIS Enterprise in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/idea-add-native-automated-certificate-management-e/m-p/1686845#M43833</link>
    <description>&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Hi Everyone,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;With the upcoming industry-wide changes to public TLS certificate lifetimes, I wanted to propose an enhancement for ArcGIS Enterprise and see how the rest of the community is planning to handle this.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;The Upcoming Challenge:&lt;/STRONG&gt;&amp;nbsp;T&lt;SPAN class=""&gt;he maximum lifetime for public TLS certificates is rapidly accelerating toward much shorter durations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;According to recent announcements:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;STRONG&gt;March 15, 2026:&lt;/STRONG&gt;&lt;SPAN class=""&gt; Maximum lifetime reduces to 200 days&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;March 15, 2027:&lt;/STRONG&gt;&lt;SPAN class=""&gt; Maximum lifetime reduces to 100 days&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;March 15, 2029:&lt;/STRONG&gt;&lt;SPAN class=""&gt; Maximum lifetime reduces to just 47 days&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Reference Link&lt;/STRONG&gt; -&amp;nbsp;&lt;/SPAN&gt;&lt;A title="https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days" href="https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days" target="_blank" rel="noopener noreferrer"&gt;TLS Certificate Lifetimes Will Officially Reduce to 47 Days | DigiCert&lt;/A&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;The Impact on ArcGIS Enterprise:&lt;/STRONG&gt; &lt;SPAN class=""&gt;Currently, updating certificates in ArcGIS Enterprise (such as the IIS Web Adaptor and the Portal/Server Admin Web Servers) requires significant manual intervention.&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;If you are using an existing CA-signed certificate, the current workflow requires administrators to log into the Administrator Directory, manually import the .p12 or .pfx file, update the web server SSL certificate property, and restart the ArcGIS Server site. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Crucially&lt;/SPAN&gt;&lt;SPAN class=""&gt;, if you have a multiple-machine deployment, these manual steps must be repeated for &lt;/SPAN&gt;&lt;I&gt;each&lt;/I&gt;&lt;SPAN class=""&gt; GIS server in the deployment.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;By 2029, we will be forced to perform these manual certificate updates and service restarts every 47 days. While&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;public Application Load Balancers (ALBs) and Gateways can leverage protocols like ACME for automatic updates, ArcGIS Enterprise currently lacks an equivalent built-in automation for its internal web server components. This&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;frequency will introduce severe manual overhead and significantly increase the risk of operational downtime if a certificate update is missed.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;The Proposed Enhancement:&lt;/STRONG&gt; &lt;SPAN class=""&gt;We are requesting that Esri introduce automated certificate lifecycle management (such as native ACME protocol support) directly into ArcGIS Enterprise.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;This built-in automation would allow ArcGIS Server and Portal to automatically fetch, bind, and apply renewed certificates seamlessly, entirely removing the need for manual administrative overhead and manual service restarts.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Community Question:&lt;/STRONG&gt; &lt;SPAN class=""&gt;Is anyone else looking at this 47-day timeline and worrying about the manual overhead? Are you currently building your own custom automation to handle this&lt;/SPAN&gt;&lt;SPAN class=""&gt;?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;If you agree that Esri should provide a native, out-of-the-box solution to automatically manage these certificates, &lt;/SPAN&gt;&lt;STRONG&gt;please give this post a Kudos / Upvote!&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Thanks!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Ayush&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 26 Feb 2026 10:54:03 GMT</pubDate>
    <dc:creator>AYUSHYADAV</dc:creator>
    <dc:date>2026-02-26T10:54:03Z</dc:date>
    <item>
      <title>Idea: Add Native Automated Certificate Management (e.g., ACME) to ArcGIS Enterprise</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/idea-add-native-automated-certificate-management-e/m-p/1686845#M43833</link>
      <description>&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Hi Everyone,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;With the upcoming industry-wide changes to public TLS certificate lifetimes, I wanted to propose an enhancement for ArcGIS Enterprise and see how the rest of the community is planning to handle this.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;The Upcoming Challenge:&lt;/STRONG&gt;&amp;nbsp;T&lt;SPAN class=""&gt;he maximum lifetime for public TLS certificates is rapidly accelerating toward much shorter durations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;According to recent announcements:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;STRONG&gt;March 15, 2026:&lt;/STRONG&gt;&lt;SPAN class=""&gt; Maximum lifetime reduces to 200 days&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;March 15, 2027:&lt;/STRONG&gt;&lt;SPAN class=""&gt; Maximum lifetime reduces to 100 days&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;March 15, 2029:&lt;/STRONG&gt;&lt;SPAN class=""&gt; Maximum lifetime reduces to just 47 days&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Reference Link&lt;/STRONG&gt; -&amp;nbsp;&lt;/SPAN&gt;&lt;A title="https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days" href="https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days" target="_blank" rel="noopener noreferrer"&gt;TLS Certificate Lifetimes Will Officially Reduce to 47 Days | DigiCert&lt;/A&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;The Impact on ArcGIS Enterprise:&lt;/STRONG&gt; &lt;SPAN class=""&gt;Currently, updating certificates in ArcGIS Enterprise (such as the IIS Web Adaptor and the Portal/Server Admin Web Servers) requires significant manual intervention.&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;If you are using an existing CA-signed certificate, the current workflow requires administrators to log into the Administrator Directory, manually import the .p12 or .pfx file, update the web server SSL certificate property, and restart the ArcGIS Server site. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Crucially&lt;/SPAN&gt;&lt;SPAN class=""&gt;, if you have a multiple-machine deployment, these manual steps must be repeated for &lt;/SPAN&gt;&lt;I&gt;each&lt;/I&gt;&lt;SPAN class=""&gt; GIS server in the deployment.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;By 2029, we will be forced to perform these manual certificate updates and service restarts every 47 days. While&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;public Application Load Balancers (ALBs) and Gateways can leverage protocols like ACME for automatic updates, ArcGIS Enterprise currently lacks an equivalent built-in automation for its internal web server components. This&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;frequency will introduce severe manual overhead and significantly increase the risk of operational downtime if a certificate update is missed.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;The Proposed Enhancement:&lt;/STRONG&gt; &lt;SPAN class=""&gt;We are requesting that Esri introduce automated certificate lifecycle management (such as native ACME protocol support) directly into ArcGIS Enterprise.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;This built-in automation would allow ArcGIS Server and Portal to automatically fetch, bind, and apply renewed certificates seamlessly, entirely removing the need for manual administrative overhead and manual service restarts.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Community Question:&lt;/STRONG&gt; &lt;SPAN class=""&gt;Is anyone else looking at this 47-day timeline and worrying about the manual overhead? Are you currently building your own custom automation to handle this&lt;/SPAN&gt;&lt;SPAN class=""&gt;?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;If you agree that Esri should provide a native, out-of-the-box solution to automatically manage these certificates, &lt;/SPAN&gt;&lt;STRONG&gt;please give this post a Kudos / Upvote!&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Thanks!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Ayush&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Feb 2026 10:54:03 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/idea-add-native-automated-certificate-management-e/m-p/1686845#M43833</guid>
      <dc:creator>AYUSHYADAV</dc:creator>
      <dc:date>2026-02-26T10:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Idea: Add Native Automated Certificate Management (e.g., ACME) to ArcGIS Enterprise</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/idea-add-native-automated-certificate-management-e/m-p/1690272#M43913</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/110315"&gt;@AYUSHYADAV&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Ideas should be posted on the ArcGIS Enterprise Ideas channel&amp;nbsp;&lt;A href="https://community.esri.com/t5/arcgis-enterprise-ideas/idb-p/arcgis-enterprise-ideas" target="_blank"&gt;ArcGIS Enterprise Ideas - Esri Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Glen&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 17:03:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/idea-add-native-automated-certificate-management-e/m-p/1690272#M43913</guid>
      <dc:creator>GlenterpriseUK</dc:creator>
      <dc:date>2026-03-12T17:03:56Z</dc:date>
    </item>
  </channel>
</rss>

