Skip to main content

Emerging Standards

Certificate Management

Addresses issuance, installation, renewal, rotation, monitoring, revocation, and ownership of digital certificates used by immunization interfaces.

StageGather PathWorking on Now Topic typeCapability Followers12

Stage and Path

Stage

Gather

Gather topics are collecting broader input from implementers and stakeholders.

Path

Working on Now

The next meaningful work is understood, owned, and moving forward without a material constraint.

Overview

Explores how immunization information systems, IIS vendors, state IT organizations, hosting providers, and exchange partners issue, install, renew, rotate, monitor, revoke, and track digital certificates used for secure interfaces. This includes TLS server certificates, client certificates, mutual TLS, S/MIME and IZ Gateway certificates, certificate authorities such as DigiCert and Let’s Encrypt, ACME-based automation, DNS validation, expiration monitoring, private-key protection, deployment responsibilities, costs, and prevention of certificate-related outages. The topic will support sharing jurisdiction practices and determining whether common guidance, checklists, responsibility models, or automation recommendations are needed.

Coming soon

Support for source material, diagrams, and supporting notes is coming in a future update.

Meetings

MeetingAgendaPresenter(s)
Jul 17, 2026
Following the recent OAuth discussion, we will examine certificate renewal and management for direct HL7 v2 exchange and IZ Gateway connections, including automation, ownership, and the need for shared community guidance.
Nathan Bunker
Chris Sorenson

See All Meetings

Interface Securitydepends onOpen

Included In

Topic ID: 124
capability planning Public Read-only view