Renewals

Renewing an SSL Certificate means purchasing a new license period to extend your coverage beyond your current license expiry date. This is a separate process from reissuing your SSL Certificate, which provides a replacement SSL Certificate within your existing license period at no additional cost.

Renew Your SSL Certificate Reissue Your SSL Certificate

If your SSL Certificate has expired but your license period is still active, you do not need to renew. Instead, you should reissue your SSL Certificate through the tracking system to obtain a replacement with updated validity. Learn About Maintaining Your SSL Certificate Protection 🔗

Renewal vs Reissuance

Understanding the difference between renewal and reissuance helps ensure you take the correct action and avoid unnecessary purchases.

Renewal involves purchasing a new SSL Certificate license when your existing license period has expired or is approaching expiry. This is a chargeable transaction that extends your coverage for a new validity period of your choice.

Reissuance involves obtaining a replacement SSL Certificate within your existing license period. This is available at no additional cost and provides a new SSL Certificate with the maximum allowable validity up to your remaining license period. Explore Our Tracking System 🔗

The Renewal Process

Renewing an SSL Certificate follows the same procedure as obtaining a new SSL Certificate. When you renew, you will need to replace your existing SSL Certificate, Private Key, and Intermediate Certificates within your hosting control panel or server.

When renewing, you benefit from being able to test and install your new SSL Certificate parallel to your existing SSL Certificate. This allows you to verify the installation before your current SSL Certificate expires.

Important : Do not leave your renewal until the last day. Order queuing or processing delays may prevent timely issuance. Renew and replace your SSL Certificate at least 14 days before your existing license expires.

License Validity Periods

SSL Certificate licenses can be purchased for validity periods of up to five years. When an SSL Certificate is issued, it will contain a validity date for a period as per industry requirements, which is currently a maximum of 200 days.

During a multi-year license, you will need to reissue your SSL Certificate periodically to maintain continuous coverage. Each reissuance provides a new SSL Certificate with the maximum allowable validity up to your remaining license period. Learn About SSL Certificate Validity Periods 🔗

Important : Partners and customers are responsible for monitoring the expiry dates of installed SSL Certificates. The ordering system displays all orders on an account with the purchased license validity dates, however each SSL Certificate has its own validity dates dependant on when it was issued within the license period.

The tracking system can be accessed on an order-by-order basis and displays both the license validity and the validity details of the last SSL Certificate issued. When managing multiple SSL Certificates, it is advisable to use bespoke monitoring tools or dedicated SSL Certificate monitoring software to detect installed SSL Certificates and be alerted when it is time to reissue or renew.

Subscriptions

If you have an automatic protection plan with Trustico® your SSL Certificate license will renew automatically each month or year. You do not need to worry about purchasing a renewal with an automatic protection plan.

Reissue Your SSL Certificate

For customers who prefer fully automated management including automatic reissuance, Trustico® offers Certificate as a Service (CaaS) which handles the entire SSL Certificate lifecycle without manual intervention. Learn About Certificate as a Service (CaaS) 🔗

Best Practices

Following these best practices when renewing your SSL Certificate will help ensure a smooth transition and maintain strong security.

Tip : Generate a new Certificate Signing Request (CSR) and Private Key when renewing your SSL Certificate. Fresh cryptographic keys reduce the risk associated with potential key compromise over time.

Avoid using an existing Certificate Signing Request (CSR) as this will ensure your Private Key matches the SSL Certificate that is issued. If you have generated your new Certificate Signing Request (CSR), you can proceed to the renewal options.

Certificate Signing Request

A Certificate Signing Request (CSR) is required to order an SSL Certificate. The Certificate Signing Request (CSR) is generated from within your hosting control panel, web server software, or server operating system.

Trustico® provides resources to assist with creating your Certificate Signing Request (CSR) for various platforms and server configurations.

Certificate Signing Request (CSR)

If you prefer not to generate your own Certificate Signing Request (CSR), the Trustico® AutoCSR service can automatically generate one for you during the order process. Learn About Certificate Signing Requests (CSR) 🔗

Install SSL Certificate

After your renewal SSL Certificate has been issued, you will need to install it on your server along with the corresponding Intermediate Certificates. Installation procedures vary depending on your hosting control panel or server software.

Trustico® provides comprehensive installation guides for various platforms and server configurations.

Installation Instructions

If you would prefer assistance with your renewal, the Trustico® support team can provide additional information on how to complete your order and install your renewal SSL Certificate. View Our Support Resources 🔗

Microsoft Windows Server Warning

There is a known issue with renewing SSL Certificates using Microsoft Internet Information Services (IIS) that you should be aware of before proceeding.

Warning : Do not use the "Renew SSL Certificate" option within Internet Information Services (IIS). This built-in function has known limitations that may cause the renewal to fail. Instead, generate a new Certificate Signing Request (CSR) and install your renewal SSL Certificate as a new installation.

Most Popular Questions

Learn how to renew your SSL Certificate license when it expires and understand the difference between renewal and reissuance to ensure continuous protection.

What Differs Between Renewing and Reissuing an SSL Certificate?

Renewal involves purchasing a new SSL Certificate license when your existing license period has expired or is approaching expiry, which is a chargeable transaction. Reissuance is obtaining a replacement SSL Certificate within your existing license period at no additional cost.

When Should I Renew My SSL Certificate?

Trustico® recommends renewing and replacing your SSL Certificate at least 14 days before your existing license expires. Do not leave your renewal until the last day, as order queuing or processing delays may prevent timely issuance.

Do I Need a New CSR When Renewing My SSL Certificate?

Yes, Trustico® recommends generating a new Certificate Signing Request (CSR) and Private Key when renewing. Fresh cryptographic keys reduce the risk associated with potential key compromise over time. If you prefer not to generate your own, the Trustico® AutoCSR service can create one automatically during ordering.

How Long Can I Purchase an SSL Certificate License For?

SSL Certificate licenses can be purchased for validity periods of up to five years. However, each issued SSL Certificate contains a validity date of approximately 398 days maximum per industry requirements, so you will need to reissue periodically during multi-year licenses.

Will My Automatic Protection Plan Handle Everything for My SSL Certificate?

Automatic protection plans handle license renewal only. You are still responsible for reissuing your SSL Certificate when it approaches its maximum validity period. For fully automated management including automatic reissuance, Trustico® offers Certificate as a Service (CaaS).

Why Should I Not Use the Renew SSL Certificate Option Within IIS?

The built-in renewal function within Internet Information Services (IIS) has known limitations that may cause the renewal to fail. Instead, generate a new Certificate Signing Request (CSR) and install your renewal SSL Certificate as a new installation.

Website Security Checks : Essential Steps to Protect Your Business Online

Website Security Checks : Essential Steps to Pr...

Keep your website secure with the SSL Certificate checks that matter most, from expiry and chain coverage to validation levels, issuance controls, and automation.

Website Security Checks : Essential Steps to Pr...

Keep your website secure with the SSL Certificate checks that matter most, from expiry and chain coverage to validation levels, issuance controls, and automation.

Installing an S/MIME E-Mail Certificate in Mozilla Thunderbird

Installing an S/MIME E-Mail Certificate in Mozi...

Import a PKCS12 E-Mail Certificate into Mozilla Thunderbird, assign it for signing and encryption, and exchange secured messages with any recipient.

Installing an S/MIME E-Mail Certificate in Mozi...

Import a PKCS12 E-Mail Certificate into Mozilla Thunderbird, assign it for signing and encryption, and exchange secured messages with any recipient.

Repackaging a PKCS12 File for macOS Keychain Compatibility

Repackaging a PKCS12 File for macOS Keychain Co...

Fix PKCS12 imports that macOS Keychain Access rejects despite a correct password by re-exporting the file with legacy compatible encryption.

Repackaging a PKCS12 File for macOS Keychain Co...

Fix PKCS12 imports that macOS Keychain Access rejects despite a correct password by re-exporting the file with legacy compatible encryption.

Fixing the IIS Binding Error - A Specified Logon Session Does Not Exist

Fixing the IIS Binding Error - A Specified Logo...

Resolve the IIS binding error stating a specified logon session does not exist by repairing the Private Key association or reimporting correctly.

Fixing the IIS Binding Error - A Specified Logo...

Resolve the IIS binding error stating a specified logon session does not exist by repairing the Private Key association or reimporting correctly.

Converting a Java Keystore to PKCS12 Format

Converting a Java Keystore to PKCS12 Format

Convert a legacy Java KeyStore (JKS) to PKCS12 with one keytool command, verify the contents, and extract PEM files for non-Java platforms when needed.

Converting a Java Keystore to PKCS12 Format

Convert a legacy Java KeyStore (JKS) to PKCS12 with one keytool command, verify the contents, and extract PEM files for non-Java platforms when needed.

The 64 Character Limit on the Common Name Field

The 64 Character Limit on the Common Name Field

Understand the 64 character limit on the Common Name (CN) field, why long hostnames fail at CSR generation, and how Subject Alternative Names solve it.

The 64 Character Limit on the Common Name Field

Understand the 64 character limit on the Common Name (CN) field, why long hostnames fail at CSR generation, and how Subject Alternative Names solve it.

1 / 6