An SSL Certificate has two separate expiry dates, and the earlier of the two arrives long before your license ends. When that date approaches, you replace the SSL Certificate yourself through a reissue.
A reissue costs nothing, is included with every license, and normally takes a few minutes. This page walks through the entire procedure for someone who has never done it before.
The Reason an SSL Certificate Expires Before the License
Your license is your entitlement to hold a valid SSL Certificate for the period you paid for and where you subsequently continue to prove control of the secured domain names. The SSL Certificate itself is a separate file that industry regulations now force to be much shorter lived than most license periods.
A one year license therefore covers a period longer than any single SSL Certificate is permitted to last. The license does not shrink, and nothing has been taken away from you. You simply collect a fresh SSL Certificate part way through and prove your right to continue to hold that SSL Certificate. Learn About The Reason Behind Reissues 🔗
Recognizing That a Reissue Is Due
The two dates sit side by side in the tracking system. One panel shows your license dates, and the panel beside it shows the validity dates of the last SSL Certificate issued. The second of those is the one that causes browser warnings.
Watching the validity remaining figure rather than the license remaining figure is the habit worth forming. The validity dates are encoded within the SSL Certificate itself, so the primary method of following these dates is by monitoring the server or hosting control panel where it is installed.
The tracking system also provides calendar files for both dates, which you can add to your own calendar so the reminder arrives without you needing to check. Learn About The Tracking System 🔗
Note : Trustico® does not hold records of where your SSL Certificates are installed and cannot detect that a website is serving an expiring SSL Certificate. Watching the validity dates remains your own responsibility and is a normal business function when operating a secure website.
Reissuing a few weeks ahead of the validity end date is more comfortable than reissuing on the day, because it leaves room for validation to be completed without pressure.
What to Have Ready Before You Start
You need your Certificate Authority (CA) Reference. This is not the same as your Trustico® order number, and the order number will not grant access, because a single order is capable of securing many domain names across several separate SSL Certificates.
The reference appears in the e-mail sent when your order reached the Certificate Authority (CA). It is also held within the ordering and billing systems where the order was placed, and it is shown inside the tracking system once you are signed in. Learn About Telling the Two Numbers Apart 🔗
You also need to decide whether you will supply a new Certificate Signing Request (CSR) or reuse the one already held by the Certificate Authority (CA). If you intend to supply a new one, generate it on the server where the SSL Certificate will be installed before you begin. Learn About Generating a Certificate Signing Request 🔗
Finally, make sure you have access to whichever validation method you plan to use, whether that means a mailbox, your Domain Name System (DNS) records, or the web server for the domain name.
Accessing the Tracking System
Access is granted per license rather than through a general account, so there is no password to remember and nothing to set up in advance.
Note : The tracking system supports traditional SSL Certificates only. Certificate as a Service (CaaS) products are maintained entirely by your own Automated Certificate Management Environment (ACME) client, and Trustico® performs no part of that process.
If you hold a Certificate as a Service (CaaS) product, the procedure described on this page does not apply to you. Issuance, validation and replacement all happen automatically on your own server, without a reissue ever being requested by hand. Learn About Certificate as a Service 🔗
Details Requested on the First Screen
You are asked for your Certificate Authority (CA) Reference, the domain name covered by the SSL Certificate, and the brand of the product you ordered, which is chosen from a list. A human verification check also appears on the same screen.
All three details must match the order. If the reference is rejected, the most common cause is that the order number was entered instead of the Certificate Authority (CA) Reference.
The Additional Security Code
A second screen may then ask for a security code. Whether it appears depends on a number of security factors, so its absence does not mean anything is wrong.
When it does appear, the code can be delivered by text message, by a messaging application, by voice call, or to an e-mail address that is not held with a free e-mail provider. Choose whichever you can reach immediately, because the code is intended for use straight away.
Reading Your Dashboard
Once you are in, the dashboard shows the current state of the license and every action available to you. Three areas matter before you reissue anything.
The Two Sets of Dates
License Information shows the start date, end date, duration and remaining days of your entitlement. SSL Certificate Issuance beside it shows the same four figures for the last valid SSL Certificate issued.
Seeing a large number of license days remaining alongside a much smaller number of validity days remaining is normal, and it is precisely the situation a reissue exists to resolve.
The Validation Progress Indicator
Three stages are shown : the Certificate Signing Request (CSR), Domain Control Validation (DCV), and Certification Authority Authorization (CAA). All three must complete before an SSL Certificate can be issued.
The third stage checks the Domain Name System (DNS) records that state which Certificate Authorities are permitted to issue for your domain name. It usually passes without any action on your part. Learn About Certification Authority Authorization Records 🔗
Choosing the Reissue Action
The available actions are grouped together lower down the dashboard. The one you want replaces your SSL Certificate within the license you already hold, and it will issue for the longest validity currently permitted, or to the end of your license period where that is sooner.
Alongside it you will find the option to download an SSL Certificate that has already been issued, which is where you will return once the reissue completes.
Step 1 : Choosing Your Certificate Signing Request
The reissue offers two routes. You can supply a new Certificate Signing Request (CSR), or you can use the one already on record with the Certificate Authority (CA). Both are valid.
Reusing the record held by the Certificate Authority (CA) is the quicker route, particularly if you go on to choose the same validation method you used originally. Generating a new Certificate Signing Request (CSR) produces a new Private Key, which is better security practice, and is the route to take if the existing key has been exposed or lost.
Important : Where you supply a new Certificate Signing Request (CSR), the primary domain name inside it must match the primary domain name on the original order. A mismatch will prevent the reissue from proceeding.
One detail surprises almost everyone the first time. Any additional names written into a Certificate Signing Request (CSR) are ignored, both at reissue and when ordering.
Coverage comes from your license rather than from the request. Only the primary domain name is read from the Certificate Signing Request (CSR), and every name on the license is then added, with one of them designated as the primary name on the SSL Certificate. There is no need to list anything beyond the primary domain name.
Step 2 : Selecting a Validation Method
Every domain name on the license is listed, each awaiting a method. You may configure one domain name and then apply that same method to all the others, which is the sensible choice in most cases, or click an individual domain name to configure it on its own.
A method must always be selected, even where you have validated the same domain name recently. If your previous completion for that method is still inside its reuse period, the check may then complete without anything further being asked of you. Learn About Validation Reuse Periods 🔗
Choosing the method you used originally is therefore the fastest path, because it is the method most likely to still be within its reuse period.
Approver E-Mail Validation
A confirmation e-mail is sent to one of five pre-approved addresses at your domain name, and the recipient follows the instructions it contains. The address is chosen from a list on screen.
The mailbox must already exist and be able to receive e-mail before validation can complete, so create it first if it does not. This method is expected to be phased out in future, so it is not the one to build a routine around.
Domain Name System Validation
Two Domain Name System (DNS) methods are offered, one using a CNAME record and one using a TXT record. Both require you to add a record to the zone for the domain name and leave it in place until the SSL Certificate has been issued.
These methods suit anyone who already administers their own Domain Name System (DNS) records, and they remain available for every product type.
File Based Validation
The two file methods place a file on your web server, reachable over either Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS). They suit anyone with straightforward access to the files and pages being served on the website.
Where either file method is used, regulations require the file to be reachable at every subdomain that is to be secured, and at the root as well where the root is also secured. A file placed in one location alone will not validate the remaining names.
This obligation applies only to the two file methods. Approver e-mail and the two Domain Name System (DNS) methods carry no equivalent requirement, which is why they are usually the easier choice where a license covers many names.
Important : File based validation cannot be used for a Wildcard SSL Certificate. Wildcard entries are limited to approver e-mail, CNAME record, or TXT record validation, and the file options are shown as unavailable.
Once every domain name has a method assigned, the submit button becomes available and reports how many of your domain names have been configured. Learn About The Validation Procedure in Detail 🔗
What Happens After You Submit
Issuance is fast. Once validation and the automated checks that accompany it have completed, the SSL Certificate is usually issued within minutes.
Those automated checks repeat your validation from several independent network locations around the world, and all of them must agree. This is why validation resources must stay in place until the SSL Certificate has actually been issued rather than being removed as soon as the first check passes. Learn About The Automated Corroboration Checks 🔗
Restrictions that limit access to your web server or Domain Name System (DNS) servers by country or by address range are the most frequent reason these checks disagree, so those paths need to be reachable globally while validation is under way.
A misconfigured Domain Name System Security Extensions (DNSSEC) deployment will also prevent issuance, because the records required for the Certification Authority Authorization (CAA) check cannot be resolved and the check is recorded as a failure.
Downloading Your New SSL Certificate
Return to the dashboard and use the refresh action at the top right of the page to update the license and SSL Certificate status.
Then choose the download option. The next screen confirms the issued status, the new validity period, the serial number, and the names covered.
Your SSL Certificate is shown ready to copy, with the Intermediate Certificates shown separately below it. Both are required, because browsers need the full chain in order to establish trust. Learn About Intermediate Certificates 🔗
Several download formats are offered so you can match your server. You can take the SSL Certificate on its own, the chain on its own for servers that expect separate files, the SSL Certificate together with its chain, the same with the root included, or the PKCS#7 format.
An archive containing every format is also available, and the same archive can be sent directly to an e-mail address of your choosing if the person installing it is not you. Learn About Installing Your SSL Certificate 🔗
Your Previous SSL Certificate Stays Active
Reissuing does not switch anything off. Every SSL Certificate issued under your license remains active until its own validity end date unless it is revoked, and the license history records each one.
This means you can reissue early and install at a moment that suits you, with the previous SSL Certificate continuing to serve your website until you replace it. There is no gap and no outage created by the reissue itself.
If Your SSL Certificate Has Already Expired
The procedure is exactly the same. An expired SSL Certificate does not affect your license, and nothing additional is required of you.
As soon as the reissue completes, the new SSL Certificate is available to download and install. The browser warnings stop once it is installed and the web server has been restarted.
When Something Does Not Work
A rejected reference on the first screen is almost always the order number being used in place of the Certificate Authority (CA) Reference. Checking which number you have resolves most access problems immediately.
A reference that has never worked may mean the order has not yet reached the Certificate Authority (CA), which happens while an order is still being processed. Waiting for the e-mail that carries the reference is the correct response.
Validation that starts but never completes usually points at your own infrastructure rather than at the Certificate Authority (CA). Records removed too early, filtering by country or address range, and web servers that reject requests without a recognized browser identifier are the common causes.
Where none of these apply, the Trustico® team can look at the license with you. Contact The Trustico® Support Team 🔗
Avoiding This Every Few Months
Reissuing by hand is manageable while validation can be reused for a long period. That period is scheduled to shorten considerably over the next few years, and at its shortest a manual reissue cycle becomes impractical for anyone managing more than a handful of names.
Certificate as a Service (CaaS) removes the work entirely. Your server requests and validates each new SSL Certificate automatically, so no reissue is ever performed by hand and no validation window needs watching.
That process runs solely on your own side. Your Automated Certificate Management Environment (ACME) client handles each request, and no part of the cycle is performed by Trustico® or tracked through the tracking system.
Whichever route you take, the entitlement is the same. Your license covers a valid SSL Certificate for its full period, and reissuing is simply how that coverage is collected. Learn About Managing Shorter Validity Periods 🔗