Skip to content
CERTIFICATE AUTOMATION BRIDGE

47 days. The countdown has started.

In March 2029, public certificates move to a 47-day validity period. For your SBCs, that means eight renewals a year instead of one. With zero service interruption. Across your entire fleet.

Certificate Automation Bridge

What changes in March 2029

The CA/Browser Forum has ratified a progressive reduction of public certificate validity, capped at 47 days starting March 2029. Concretely, what used to be renewed once a year must now be renewed eight times a year. Across dozens, sometimes hundreds of devices.

For voice infrastructures — SBCs, SIP trunks, registration front-ends — the risk is direct: a forgotten certificate means a P1 telecom outage. The topic sits at the intersection of PKI and telecom teams, with tooling and lifecycles historically designed in parallel rather than together.

The front-line platforms are the ones every decision-maker has in mind: Microsoft Teams (via Direct Routing), Genesys Cloud, and more broadly unified communications and cloud contact center services. All of them rely on SBCs that present public certificates to carriers and cloud services. Every missed renewal takes a trunk down.

Today, enterprise PKI tools don't natively talk to SBCs. Homegrown scripts die with their author. Most large enterprises are not ready.

The CA/Browser Forum trajectory

1

Yesterday

398 days

2

March 15, 2026

200 days

3

March 15, 2027

100 days

4

March 15, 2029

47 days

The workflow

Certificate Automation Bridge is a module of SIPify Pulse. It does one thing, and does it well: industrialize the certificate lifecycle on voice infrastructures, without human intervention, without service interruption.

Automatic inventory

Discovery of certificates deployed across the entire SBC fleet — by device, interface, and usage.

Pre-renewal audit

Verification of algorithm compatibility, chain of trust, expiry dates and dependencies before any action.

End-to-end orchestration

CSR generation, CA submission, deployment on the device, automatic rollback in case of failure.

Functional post-checks

Call tests after switchover. We don't just validate that a file is in place — we validate that voice traffic actually flows.

Compliant audit log

Who, when, what. Output ready for CISO teams and internal control.

In-house script vs CAB

Why a product module rather than a homegrown script

In-house scriptCAB
Written by an expert who eventually leavesMaintained and versioned by SIPify, Tier-1 support by NXO
Mono-technology or mono-versionMulti-tech SBC, vendor-agnostic
No rollback, no post-checkAutomatic rollback + post-switchover call tests
To be rewritten on every SBC upgradeProduct updates delivered by the SIPify workshop
Compliance not demonstrableAudit log ready for CISO / internal control

CAB is not a roadmap item. It's a workflow we coded to answer a concrete need.

SIPify Pulse is the agile voice workshop. A team of VoIP experts, an AI-augmented code factory, and the capacity to turn a business need into a delivered automation in a few weeks — not two years.

Where large vendors push generic platforms with frozen roadmaps, we start from the client's workflow. AutoDialer, Traffic Guardian, SBC Config Utility, CAB: these aren't products, they are the first workflows that came out of the workshop. The next one could be yours.

Distributed by NXO

SIPify Pulse is distributed exclusively by NXO, a large-account integrator. Dedicated sales team, trained Tier-1 support, industrial deployment on sensitive infrastructures. The agility of a workshop, the solidity of a major group.

Frequently asked questions

How long would this workflow take at your company, with your current vendor?

Personalized demo on your SBC perimeter. 30 minutes. No pre-installation required.

You can also go through your usual NXO contact.