The certificate ACME doesn't renew is the one that kills your VPN
Do the arithmetic: 15 March 2026, the day the 200-day ceiling for public TLS certificates came into force, plus 200 days. That lands on 1 October. Today. The first certificates issued under the new rule start expiring this week, and this stops being a 2029 problem. The CA/Browser Forum schedule (ballot SC-081v3, 25 issuers in favour and none against) drops to 100 days on 15 March 2027 and to 47 in 2029, with domain validation down to 10 days: about 37 validations a year per name. The 47 is neither arbitrary nor round: it is 31 + 15 + 1, sized so a monthly renewal fits with room for one retry. But the web server has renewed itself for years; the problem is the firewall portal, the VPN gateway and the RADIUS box doing EAP-TLS. And here is the uncomfortable conclusion: ACME validates from the outside, and those devices are not published on the Internet precisely because you segmented properly. The better your network, the worse your position. What path is left, what new risk comes from giving a script write access to your DNS, why half the list should not be in the public chain at all, and the four columns that decide by themselves what to do with each row.