Interactive Learning Platform

Finally Understand PKI & TLS

Stop struggling with abstract diagrams. FixMyCert provides interactive, step-by-step visualizations for certificates, handshakes, and trust chains.

Built by an engineer who's managed thousands of production certificates and lived through real TLS outages.

See It In Action

Interactive visualizations that make complex concepts click

Client
ClientHello
ServerHello
Certificate
KeyExchange
Server

Visual Handshakes

Watch TLS packets fly between client and server. Understand exactly when encryption kicks in.

Read the Guide
Root CA
Intermediate
Your Cert

Chain Validation

See how browsers traverse the trust chain from leaf to root, and why intermediate certs matter.

Read the Guide
Expired

Certificate past validity

Revoked
Chain Error

Failure Scenarios

Simulate expired certs, revocations, and MITM attacks to learn how to troubleshoot real incidents.

Read the Guide
Interactive Demos

Learn By Doing

Visual, step-by-step demonstrations of PKI concepts. Click through to understand how things actually work.

New Guides Added

Start Learning

In-depth guides for real-world PKI challenges. From installation to troubleshooting.

HAProxy SSL Certificate Configuration
NEWWeb Servers

HAProxy SSL Certificate Configuration

Learn how to configure SSL/TLS certificates in HAProxy. Covers SSL termination, passthrough, cipher suites, and achieving an SSL Labs A+ grade.

12 min
Extended Key Usage (EKU) Explained
NEWCertificates

Extended Key Usage (EKU) Explained

What EKU is, why it matters, and how to check yours. Covers common EKUs, OID system, and the ClientAuth sunset.

10 min
NIST Certificate Management
NEWEnterprise PKI

NIST Certificate Management

Map NIST key management and cryptography standards to certificate lifecycle management. Covers SP 800-57, 800-52, 800-131A with practical CLM implementation guidance.

25 min
DCV Methods Sunset Timeline
NEWEnterprise PKI

DCV Methods Sunset Timeline

Complete timeline of CA/Browser Forum ballots SC-080, SC-090, SC-091 eliminating 11 domain validation methods by 2028. Email, phone, and WHOIS-based validation are being sunset.

12 min
WoSign/StartCom 2016: Lies, Backdating, and Secret Acquisitions
NEWEnterprise PKI

WoSign/StartCom 2016: Lies, Backdating, and Secret Acquisitions

The story of WoSign's systematic deception - backdating certificates, hiding acquisitions, and the consequences of getting caught.

12 min
Automating DNS-01 with DNS APIs
NEWEnterprise PKI

Automating DNS-01 with DNS APIs

Complete guide to DNS-01 automation with DNS provider APIs. Learn CNAME delegation, security best practices, and provider-specific configurations for Cloudflare, Route53, Azure DNS, and more.

15 min
F5 Certificate Installation
NEWF5 BIG-IP

F5 Certificate Installation

Step-by-step guide to importing certificates, keys, and chains into F5 BIG-IP. GUI and tmsh methods.

12 min
F5 SSL Passthrough vs Offloading vs Bridging
NEWF5 BIG-IP

F5 SSL Passthrough vs Offloading vs Bridging

Understand when to use SSL passthrough, offloading, or bridging on F5 BIG-IP. Configuration examples, use cases, and security trade-offs.

12 min
Client Authentication EKU Sunset
NEWCertificates

Client Authentication EKU Sunset

Chrome and major CAs are removing Client Authentication EKU from public TLS certificates by June 2026. Learn who's affected, key deadlines, and migration options.

15 min
SSH Certificate Authority Setup
NEWSSH Certificates

SSH Certificate Authority Setup

Create your own SSH CA with native OpenSSH. Key generation, protection levels, distribution, signing workflow, and operational procedures.

12 min

What's New

Here's what we've been building for you

New GuideCompliance

New: DNS-PERSIST-01 Guide + Security Analysis Blog Post

Comprehensive guide to the new persistent ACME DNS validation method (SC-088v3) plus a companion blog post analyzing 5 security assumptions that change with persistent authorization

DNS-PERSIST-01 is the biggest change to ACME certificate validation since DNS-01 was introduced. The CA/Browser Forum approved it unanimously, Let's Encrypt announced support, and production rollout is expected Q2 2026. We published a full guide covering how it works, how it compares to DNS-01, scope controls, security tradeoffs, implementation timeline, and a decision framework to help you decide when to adopt. We also wrote a companion blog post that goes deeper on the security side — five specific assumptions that change when your certificate validation becomes persistent, and what your team should do about each one. Both resources include video walkthroughs.

DNS-PERSIST-01 Guide
Improvement

Share Checklists & Runbooks with Your Team

All checklists and runbooks now have LinkedIn, X, and copy-link sharing buttons so you can easily send them to colleagues

Every checklist and runbook on FixMyCert now has social sharing buttons built right into the sticky progress bar. Share a checklist with your team on LinkedIn, post it on X, or copy the link to drop into Slack or email. This was one of the most requested features — when you find a checklist that solves a real problem, you should be able to share it in two clicks.

All Checklists & Runbooks
ComplianceNew Guide

New: 47-Day Readiness Audit Checklist (82-Point Assessment)

A structured audit to assess whether your PKI infrastructure is ready for 47-day certificate validity — covering automation, DCV, monitoring, and team readiness

With the March 15, 2026 Phase 1 deadline approaching, we built a comprehensive 82-point readiness audit that walks you through every area that matters: certificate discovery, renewal ownership, DCV readiness, ACME pipelines, deployment automation, monitoring, and organizational preparedness. Unlike a generic compliance checklist, this one is specifically designed around the SC-081v3 timeline. It includes a built-in readiness scoring guide so you can quickly assess where you stand — Ready, On Track, At Risk, or Critical — and prioritize accordingly. We also completely rewrote the F5 BIG-IP SSL Certificate Checklist with 52 items covering tmsh commands alongside GUI steps, PFX conversion instructions, chain warnings, and a full FAQ section.

47-Day Readiness Audit

Stay Compliant

Certificate validity periods are shrinking. Track deadlines and requirements with our live compliance hub.

Built for IT Professionals

DevOps & SREs

Debug ingress issues and automate certificate rotation with confidence.

Security Engineers

Visualize threat models and explain PKI concepts to stakeholders.

Network Engineers

Deep dive into TLS 1.2 vs 1.3, ciphers, and handshake performance.

PKI education for DevOps, Security Engineers, and Network Engineers

Ready to Master PKI?

Start with our interactive Digital Signature demo and work your way up to Cloud PKI architectures.