Managing Short SSL Certificate Validity

Shorter SSL Certificate validity periods are coming, and Trustico® is building the tools to make the transition effortless. Whether you manage one SSL Certificate or thousands, the solutions outlined on this page are designed to keep you ahead of every expiry date without adding complexity to your workflow.

This page will be updated as each tool becomes available. Bookmark it and check back for the latest developments.

Why Shorter Validity Periods Require Better Tools

The CA/Browser Forum has approved a phased reduction in SSL Certificate validity periods. Maximum validity will reduce to 200 days, then 100 days, and eventually 47 days by 2029. These changes mean SSL Certificates will need to be reissued more frequently throughout the life of your license.

When you purchase an SSL Certificate from Trustico® you are buying a license for a set period. During that license, you can reissue your SSL Certificate as many times as needed. The reissue process itself is not changing. The only difference is that you will need to do it more often.

Note : A license validity period and an SSL Certificate expiration date are two separate things. Your license defines the total period you have paid for. Your SSL Certificate expiration is the date when your currently issued SSL Certificate stops working and needs to be reissued against that license.

This is exactly why Trustico® is investing in new tools now. More frequent reissues demand better automation, clearer visibility, and proactive notifications so that nothing falls through the cracks.

The Trustico® Tracking System

The Trustico® tracking system at tracking.trustico.com is the foundation that all of these new tools are built upon. It already allows customers and partners to manage reissues, check SSL Certificate status, and view license validity dates. Learn About The Trustico® Tracking System 🔗

Everything you can do through the tracking portal today will continue to work exactly as it always has. The tools described below are expansions of this system, giving you more ways to access the same functionality.

Tools in Development

Trustico® is actively developing a suite of tools that extend the tracking system to meet the demands of shorter validity periods. Each tool addresses a specific need, from programmatic automation to proactive alerting.

Tracking Application Programming Interface (API)

The most significant addition is a dedicated Application Programming Interface (API) that will be available to both customers and partners. This Application Programming Interface (API) brings the functionality of the tracking portal into your own systems, enabling you to automate SSL Certificate management without logging in to a web interface.

The Application Programming Interface (API) will allow you to request an SSL Certificate reissue by submitting a Certificate Authority (CA) Reference and domain. You can reissue using your original Certificate Signing Request (CSR) so the SSL Certificate works with your existing Private Key, or submit a new Certificate Signing Request (CSR) if you need a fresh key pair.

During the reissue process, you will be able to select your preferred Domain Control Validation (DCV) method. This includes approver e-mail, Domain Name System (DNS) validation, or file-based authentication. Learn About File-Based Authentication 🔗

The Application Programming Interface (API) will also let you retrieve both SSL Certificate expiration dates and license validity periods on demand. This makes it possible to build your own monitoring dashboards and automate renewal workflows across all of your domains. Learn About Certificate Signing Requests (CSR) 🔗

Tip : The Application Programming Interface (API) is actively in development and coming soon. Full documentation and integration examples will be published on this page when the Application Programming Interface (API) becomes available.

Expiry Notification Services

Trustico® is building notification services that will alert you when your SSL Certificates and licenses are approaching expiry. Because these are two separate events, the notification system will cover both independently.

You will receive advance warning for SSL Certificate expirations, giving you time to reissue before your current SSL Certificate stops working. You will also receive separate notifications for license expiry, so you know when it is time to renew your license to maintain coverage.

As validity periods decrease, timely notifications become essential to maintaining uninterrupted SSL Certificate coverage.

Certificate as a Service (CaaS) — Available Now

For those who want a fully automated solution today, Trustico® and Sectigo Certificate as a Service (CaaS) products are already available to order. Certificate as a Service (CaaS) SSL Certificates automatically reissue and install themselves before expiry, removing the need for any manual intervention. Learn About Certificate as a Service (CaaS) 🔗

To use Certificate as a Service (CaaS), you will need to set up an Automatic Certificate Management Environment (ACME) client on your servers. You will then configure the External Account Binding (EAB) credentials that Trustico® provides for each SSL Certificate. Once configured, the SSL Certificates take care of themselves. Learn About Automatic Certificate Management Environment (ACME) Clients 🔗

Every server environment is different, so while Trustico® supplies the credentials, the implementation on your infrastructure is your responsibility. Trustico® provides comprehensive documentation on obtaining and configuring your External Account Binding (EAB) credentials to guide you through the process. Learn About Obtaining Your Certificate as a Service (CaaS) Credentials 🔗

Important : Certificate as a Service (CaaS) is a premium service and currently supports a smaller range of fully featured products. Discover The Differences Between Traditional and Certificate as a Service (CaaS) SSL Certificates 🔗

Automated Installation Tools

Reissuing an SSL Certificate is only half of the process. The SSL Certificate also needs to be installed on your server before it can protect your domain. As reissue cycles become shorter, the installation step becomes just as important to automate as the reissue itself.

Trustico® is developing installation tools that will handle this for you. These tools are being designed to support automated SSL Certificate installation across widely used server control panels, so that once your SSL Certificate is reissued, it can be installed without manual steps on your part.

Supported platforms will be announced as each integration becomes available. If you use a server control panel and would like to be notified when automated installation support is available for your platform, Trustico® welcomes you to get in touch so we can understand what our customers and partners need most. Learn About Contacting Trustico® 🔗

Tip : If automated installation is important to your workflow, let Trustico® know which server control panel you use. Your feedback helps prioritize which platforms are supported first.

Which Solution Is Right for You

Trustico® is building solutions to fit every workflow. If you prefer to manage SSL Certificates manually, the tracking portal continues to provide everything you need. If you want to automate SSL Certificate management within your own systems, the upcoming Application Programming Interface (API) will give you programmatic access to the same functionality.

If you want a completely hands-off solution where SSL Certificates reissue and install automatically, Certificate as a Service (CaaS) is available to order today. As validity periods shorten, the value of automation only increases.

The entire SSL Certificate industry is adjusting to shorter validity periods, and many providers have left preparation to the last minute. Trustico® is committed to delivering the tools customers and partners need ahead of these deadlines. As changes progress across the industry and in real world environments it’ll dictate the methods most important to both direct customers and partners. We value your feedback to accommodate streamlined processes throughout this transition period.

Most Popular Questions

Learn about the tools Trustico® is building to help customers and partners manage shorter SSL Certificate validity periods, including the tracking Application Programming Interface (API), expiry notifications, automated installation tools, and Certificate as a Service (CaaS) options.

What is changing about SSL Certificate validity periods?

The CA/Browser Forum has approved a phased reduction in maximum SSL Certificate validity. Validity will reduce to 200 days, then 100 days, and eventually 47 days by 2029. This means SSL Certificates will need to be reissued more frequently throughout the life of your license.

What is the difference between a license validity period and an SSL Certificate expiration date?

Your license validity period is the total time you have paid for when purchasing an SSL Certificate. Your SSL Certificate expiration date is when the currently issued SSL Certificate stops working and needs to be reissued against that license. These are two separate dates that need to be monitored independently.

Does the reissue process change with shorter validity periods?

No, the reissue process itself remains exactly the same. The only difference is that you will need to reissue your SSL Certificate more frequently. Trustico® is building tools to automate and simplify this so that shorter validity periods do not add complexity to your workflow.

What is the Trustico® tracking Application Programming Interface (API)?

The tracking Application Programming Interface (API) is a tool in development that will allow customers and partners to manage SSL Certificate reissues and retrieve license information programmatically. You will be able to submit an order number and domain to request a reissue, choose your Domain Control Validation (DCV) method, and retrieve expiry dates without logging in to the tracking portal.

Can I reissue using my existing Private Key through the Application Programming Interface (API)?

Yes, the Application Programming Interface (API) will allow you to reissue using your original Certificate Signing Request (CSR) so the SSL Certificate works with your existing Private Key. You will also have the option to submit a new Certificate Signing Request (CSR) if you need a fresh key pair.

Will Trustico® notify me before my SSL Certificate or license expires?

Trustico® is building expiry notification services that will alert you when both your SSL Certificate and your license are approaching expiry. These are handled as two separate notifications, and the advance warning period will be configurable to suit your workflow.

Is Trustico® building automated SSL Certificate installation tools?

Yes, Trustico® is developing automated installation tools that will support widely used server control panels. Supported platforms will be announced as each integration becomes available. Contact Trustico® to let us know which server control panel you use so we can prioritise accordingly.

What is Certificate as a Service (CaaS)?

Certificate as a Service (CaaS) is a fully automated solution where SSL Certificates reissue and install themselves before expiry without any manual intervention. Trustico® and Sectigo Certificate as a Service (CaaS) products are available to order today and require an Automatic Certificate Management Environment (ACME) client and External Account Binding (EAB) credentials to be configured on your server.

Is Certificate as a Service (CaaS) available for all SSL Certificate products?

Certificate as a Service (CaaS) is a premium service and currently supports higher-priced products. There is no indication that low-cost Certificate as a Service (CaaS) solutions will become available industry-wide in the near future.

When will the new tools be available?

The tracking Application Programming Interface (API), expiry notification services, and automated installation tools are all actively in development. Trustico® will update this page as each tool becomes available, including full documentation and integration details.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

SSL Certificate Validity Periods Are Changing to 200 Days

SSL Certificate Validity Periods Are Changing t...

The reduction in SSL Certificate validity periods is driven by the need to regularly confirm that the Certificate holder is still entitled to use the SSL Certificate. No new Certificate...

SSL Certificate Validity Periods Are Changing t...

The reduction in SSL Certificate validity periods is driven by the need to regularly confirm that the Certificate holder is still entitled to use the SSL Certificate. No new Certificate...

SSL Certificate Works on WWW but Not Root Domain : Troubleshooting Guide

SSL Certificate Works on WWW but Not Root Domai...

Several server configuration problems can cause SSL Certificates to work on the www version but fail on the non-www version of a domain. Understanding these causes helps identify the specific...

SSL Certificate Works on WWW but Not Root Domai...

Several server configuration problems can cause SSL Certificates to work on the www version but fail on the non-www version of a domain. Understanding these causes helps identify the specific...

Understanding SSL Certificate File Formats and Extensions

Understanding SSL Certificate File Formats and ...

SSL Certificate files can be broadly categorized into three main types based on how the data is encoded and stored. Understanding these categories will help you identify which format you...

Understanding SSL Certificate File Formats and ...

SSL Certificate files can be broadly categorized into three main types based on how the data is encoded and stored. Understanding these categories will help you identify which format you...

Understanding the AutoCSR Service for SSL Certificate Orders

Understanding the AutoCSR Service for SSL Certi...

Learn how AutoCSR works, compare it to hosting company practices, find out when automated credential generation is appropriate versus generating your own CSR. Covers security considerations including the Trustico® non-retention...

Understanding the AutoCSR Service for SSL Certi...

Learn how AutoCSR works, compare it to hosting company practices, find out when automated credential generation is appropriate versus generating your own CSR. Covers security considerations including the Trustico® non-retention...

What Is Encrypted Server Name Indication (ESNI)? How Encrypted Client Hello (ECH) Protects Your Privacy

What Is Encrypted Server Name Indication (ESNI)...

The limitations of Encrypted Server Name Indication (ESNI) led to its evolution into Encrypted Client Hello (ECH) in 2020. Encrypted Client Hello (ECH) addresses the shortcomings of its predecessor while...

What Is Encrypted Server Name Indication (ESNI)...

The limitations of Encrypted Server Name Indication (ESNI) led to its evolution into Encrypted Client Hello (ECH) in 2020. Encrypted Client Hello (ECH) addresses the shortcomings of its predecessor while...

Transport Layer Security (TLS) and Cybersecurity

Transport Layer Security (TLS) and Cybersecurity

Every time a browser connects to a website using Hypertext Transfer Protocol Secure (HTTPS), Transport Layer Security (TLS) encrypts the connection to protect data from interception and tampering.

Transport Layer Security (TLS) and Cybersecurity

Every time a browser connects to a website using Hypertext Transfer Protocol Secure (HTTPS), Transport Layer Security (TLS) encrypts the connection to protect data from interception and tampering.

1 / 6