Maintaining Your SSL Certificate Protection

When you purchase an SSL Certificate from Trustico® you are purchasing a license to secure your website or service for the validity period you have selected. Whether you choose a one-year, two-year, or multi-year subscription, your license entitles you to SSL Certificate coverage for that entire duration.

Reissue Your SSL Certificate Tracking & Management

Trustico® automatically issues SSL Certificates for the maximum allowable validity period permitted by industry regulations. Your SSL Certificate will be issued with the longest validity currently permitted, and you simply obtain replacement SSL Certificates as needed throughout your license period at no additional cost.

Maximum Validity Periods

The maximum validity period for publicly trusted SSL Certificates is set by the Certificate Authority / Browser Forum (CA/Browser Forum), the industry body that governs SSL Certificate issuance standards. This maximum validity period is subject to change as the industry evolves its security requirements.

Currently, the maximum validity period is 200 days. This means that during a multi-year license, you will need to obtain replacement SSL Certificates periodically to maintain continuous coverage.

When you reissue your SSL Certificate, the replacement is issued for the maximum allowable period or the remainder of your license, whichever is shorter. This ensures you always receive the longest possible validity for each SSL Certificate issued under your license.

Why Periodic Revalidation Exists

The requirement to periodically revalidate SSL Certificates exists to protect website visitors, businesses, and the integrity of the entire SSL Certificate ecosystem. Several important factors drive this industry-standard practice.

Confirming Continued Domain Ownership

Domain names can change ownership at any time. A business may transfer its domain, a domain registration may lapse, or ownership may move for various reasons. Periodic revalidation confirms that the entity requesting the SSL Certificate still legitimately controls the domain name.

Without regular verification, an SSL Certificate could continue to be used by someone who no longer has any right to represent that domain. This would undermine the trust that SSL Certificates are designed to provide.

Verifying the Right to Conduct Business

For Organization Validated (OV) and Extended Validation (EV) SSL Certificates, the Certificate Authority (CA) verifies that the organization exists and is legitimately conducting business. Companies can cease trading, be dissolved, or have their right to operate revoked.

Periodic revalidation ensures that SSL Certificates displaying organization information are only held by entities that continue to have a legitimate right to conduct business under that name.

Preventing Fraud and Misrepresentation

SSL Certificates establish trust between websites and their visitors. If a business changes hands, the new owners may operate under completely different standards or even engage in fraudulent activity.

Regular revalidation provides an opportunity to verify that the current operators of a website are who they claim to be. This helps prevent SSL Certificates from being used to lend credibility to fraudulent operations.

Maintaining Good Business Practices

The periodic revalidation requirement reflects broader principles of good business practice. Just as professional licenses, certifications, and regulatory approvals require periodic renewal, SSL Certificates require regular confirmation that the holder continues to meet issuance requirements.

This ongoing verification maintains the value and trustworthiness of SSL Certificates as indicators of legitimate, verified online operations.

Monitoring Your SSL Certificate

Customers are responsible for monitoring their SSL Certificate expiry dates and ensuring a timely reissue to maintain continuous coverage. There are several methods available to assist with this important administrative task.

Important : Partners and customers are responsible for monitoring the expiry dates of installed SSL Certificates. The ordering system displays all orders on an account with the purchased license validity dates, however each SSL Certificate has its own validity dates dependent on when it was issued within the license period.

The tracking system can be accessed on an order-by-order basis and displays both the license validity and the validity details of the last SSL Certificate issued. When managing multiple SSL Certificates, it is advisable to use bespoke monitoring tools or dedicated SSL Certificate monitoring software to detect installed SSL Certificates and be alerted when it is time to reissue.

Many web servers, hosting control panels, and infrastructure management tools include built-in SSL Certificate monitoring features that can alert you when expiry approaches. Dedicated SSL Certificate monitoring software is also available and can track multiple SSL Certificates across your infrastructure.

For simpler setups, calendar reminders provide an effective way to ensure you do not miss a reissue deadline. The Trustico® tracking system provides downloadable calendar files for both your SSL Certificate expiry date and your license expiry date, making it easy to add these important dates to your preferred calendar application.

Trustico® will send reminder notifications as your license expiry date approaches, however these are provided on a best-effort basis and should not be relied upon as your only safeguard.

Keeping Your Own Records

Your Certificate Authority (CA) Reference is what you need to keep. It works in the same way as a serial number supplied with any other product, and it becomes difficult to locate two years later if it was never recorded.

An SSL Certificate license can produce many SSL Certificates over its lifetime, since you may download and reissue as often as you wish. That was not always the case, because a license once produced a single SSL Certificate that simply ran to its expiry date.

Only you know where each SSL Certificate has been installed and how many installations exist. Recording those installations, and the date each one stops working, is what keeps a website from going unprotected unexpectedly.

The license expiry date matters just as much, because once the license expires no further reissue is possible and a new license is required. Learn About The Tracking System 🔗

The Reissue Process

Obtaining your replacement SSL Certificate is a largely automated process. When your current SSL Certificate approaches its maximum validity, you can complete a reissue through the tracking system.

The process involves completing Domain Control Validation (DCV) to confirm your continued control of the domain name. For most customers, this can be completed in minutes using automated validation methods such as e-mail, file-based authentication, or Domain Name System (DNS) records.

For Organization Validated (OV) and Extended Validation (EV) SSL Certificates, organization verification may also be required. However, previously verified organization details are often retained by the Certificate Authority (CA), streamlining subsequent validations.

Reissue at Any Time

You are not required to wait until your current SSL Certificate approaches expiry to obtain a replacement. You may reissue your SSL Certificate at any time during your license period for any reason.

Common reasons for reissuing include generating new cryptographic keys, changing your Certificate Signing Request (CSR) details, moving to a new server, or simply preferring to align your SSL Certificate expiry with other administrative schedules.

Each time you reissue, your replacement SSL Certificate is automatically issued with the maximum allowable validity period, up to the remaining balance of your license. This flexibility ensures you always have access to a current, fully valid SSL Certificate whenever you need it.

Trustico® provides comprehensive tracking tools that display your SSL Certificate status, license expiry date, and validation requirements.

Tracking & Management

You may complete Domain Control Validation (DCV) via e-mail, file-based authentication, or Domain Name System (DNS) record methods depending on your preference. Discover The Validation Procedure 🔗

Security Benefits

Each time you obtain a replacement SSL Certificate, you have the opportunity to generate a new Certificate Signing Request (CSR) and corresponding Private Key. Generating fresh cryptographic keys at regular intervals is a security best practice that reduces risk associated with potential key compromise.

Trustico® offers the AutoCSR service which automatically generates your Certificate Signing Request (CSR) and delivers your Private Key in a secure, encrypted archive. Learn About Certificate Signing Requests (CSR) 🔗

Your License Entitlement

Your SSL Certificate license from Trustico® provides complete coverage for your selected validity period. A two-year license means two years of SSL Certificate protection, and a three-year license means three years of protection.

The periodic reissue requirement does not reduce your entitlement in any way. You are simply installing updated SSL Certificates during your license period rather than having a single SSL Certificate file that remains unchanged.

This licensing model applies universally across the SSL Certificate industry. All Certificate Authorities (CAs) and SSL Certificate providers operate under the same CA/Browser Forum regulations governing maximum validity periods.

Multiple SSL Certificates

It is technically possible to hold multiple SSL Certificate licenses for the same Fully Qualified Domain Name (FQDN) or website. There is no restriction preventing you from purchasing additional SSL Certificates for a domain that already has active coverage.

Tip : Maintain a single SSL Certificate license per Fully Qualified Domain Name (FQDN) for simplified management. Managing multiple overlapping licenses for the same domain can create confusion regarding expiry dates and reissue schedules.

If you already have an active SSL Certificate license and require a new SSL Certificate, the recommended approach is to reissue your existing license rather than purchasing a new one. A reissue provides you with a fresh SSL Certificate at no additional cost, issued for the maximum allowable validity up to your remaining license period.

Purchasing Additional Licenses

Customers who choose to purchase additional SSL Certificate licenses for a Fully Qualified Domain Name (FQDN) that already has active coverage are welcome to do so. This is a normal transaction and some customers prefer to maintain multiple licenses for operational reasons.

Important : Each SSL Certificate license purchase is a separate chargeable transaction. Trustico® is unable to offer refunds for subsequent SSL Certificate purchases made for a domain that already has active coverage.

Before purchasing, check your existing orders in the tracking system to determine whether a reissue would meet your requirements. Explore Our Refund Policy 🔗

Reissue Your SSL Certificate Renewal Information

For customers who prefer fully automated management, Trustico® offers Certificate as a Service (CaaS) which handles the entire SSL Certificate lifecycle including automatic reissue without manual intervention. Learn About Certificate as a Service (CaaS) 🔗

Further Information

Trustico® has published a comprehensive guide covering SSL Certificate validity periods, the history of maximum validity changes, and detailed information about multi-year licensing options.

Complete Validity Guide

If you have questions about your SSL Certificate license, upcoming reissue requirements, or the replacement process, the Trustico® support team is available to assist. View Our Support Resources 🔗

Most Popular Questions

Frequently asked questions covering SSL Certificate license validity, reissue requirements during a license period, periodic revalidation, expiry monitoring, and automated management options.

Maximum Validity of a Newly Issued SSL Certificate

Trustico® issues every SSL Certificate for the longest validity period the industry permits, currently a maximum of 200 days. Your license entitles you to coverage for the full period purchased, and replacement SSL Certificates are obtained as needed at no additional cost.

Reissue Requirements During a Multi Year License

The CA/Browser Forum limits the validity of an issued SSL Certificate to less than any multi year license period. Your license remains active throughout, so you obtain a fresh SSL Certificate from it whenever the installed one approaches its expiry date.

Purpose of Periodic Revalidation

Revalidation confirms that the entity holding the SSL Certificate still controls the domain name and, for Organization Validated (OV) and Extended Validation (EV) products, still holds the right to conduct business. Domain names change ownership and companies cease trading, so periodic checks prevent an SSL Certificate remaining in use by someone no longer entitled to it.

Monitoring Your SSL Certificate Expiry Dates

The tracking system provides downloadable calendar files for both your SSL Certificate expiry date and your license expiry date. Many web servers and hosting control panels include monitoring features, and dedicated SSL Certificate monitoring software can track several installations at once. Monitoring installed SSL Certificates remains the responsibility of the certificate owner.

The SSL Certificate Reissue Process

A reissue is completed through the tracking system and requires Domain Control Validation (DCV) to confirm continued control of the domain name. Validation by e-mail, file-based authentication, or Domain Name System (DNS) record usually takes only minutes. Previously verified organization details are often retained by the Certificate Authority (CA), which shortens subsequent validations.

Reissuing Before the Expiry Date

You may reissue at any point during your license period for any reason, without waiting for the installed SSL Certificate to approach expiry. Common reasons include generating new cryptographic keys, changing Certificate Signing Request (CSR) details, or moving to a new server.

Consequences of a Missed Reissue

An expired SSL Certificate causes browsers to display security warnings to your visitors, even though the license itself remains active. Tracking expiry dates and reissuing in good time is the responsibility of the certificate owner or their server administrator.

Choosing Reissue Rather Than a New License Purchase

Where an active license already exists, a reissue provides a fresh SSL Certificate at no additional cost for the maximum allowable validity up to the remaining license period. Purchasing a second license for the same domain name is permitted but chargeable, and Trustico® is unable to offer refunds in that situation.

Security Benefits of a Regular Reissue

Each reissue is an opportunity to generate a new Certificate Signing Request (CSR) and a new Private Key. Rotating cryptographic keys at regular intervals reduces the risk associated with a key compromise that has gone unnoticed.

Multiple Licenses for the Same Domain Name

Holding more than one SSL Certificate license for the same Fully Qualified Domain Name (FQDN) is permitted and nothing prevents it. A single license per domain name is easier to manage, since overlapping licenses create confusion over expiry dates and reissue schedules.

Keeping a Record of Your Certificate Authority (CA) Reference

Your Certificate Authority (CA) Reference works in the same way as a serial number supplied with any other product, and it becomes difficult to locate later if it was never recorded. Only you know where each SSL Certificate has been installed and how many installations exist, so those records are yours to maintain.

Automated Management Through Certificate as a Service (CaaS)

Certificate as a Service (CaaS) handles the entire lifecycle, including automatic reissue, without manual intervention. It suits customers who would rather not track dates or perform a reissue by hand.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Formatting Domain Name System (DNS) Records and the Trailing Dot

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

1 / 6