أخبار الاستضافة · قراءة 5 دقيقة

TLS Certificates Are Now 200 Days. Here Is What Breaks Next.

TLS Certificates Are Now 200 Days. Here Is What Breaks Next.

On 15 March 2026 the first step of the CA/Browser Forum's publicly trusted certificate validity reduction took effect. The maximum validity period for newly issued publicly trusted TLS certificates is now 200 days, down from the previous 398-day limit. 1

This is only the first reduction. The schedule continues to 100 days on 15 March 2027 and then to 47 days on 15 March 2029. The same timetable also reduces the maximum reuse period for domain and IP address validation results, requiring applicants to prove control of domains and IP addresses more frequently. For OV and EV certificates, Subject Identity Information reuse is reduced from 825 days to 398 days during the March 2026 step. 1

The schedule came from CA/Browser Forum ballot SC-081, proposed by Apple and developed through the CA/Browser Forum process with participation from major ecosystem members including Apple, Google, Mozilla and Sectigo. 2

Revocation was never enough

Shorter certificate lifetimes are primarily a security measure rather than a paperwork change. The ballot text explains that existing certificate status mechanisms such as CRLs and OCSP have limitations at internet scale, including privacy, performance, timeliness and accuracy concerns. Shorter certificates do not replace revocation, but they reduce the amount of time a compromised or misissued certificate can remain useful on the public internet. 2

The operational impact is significant. Moving from a 398-day maximum validity period to 47 days means roughly 8.5 times as many possible renewal cycles over the same period. Even the intermediate 100-day stage in March 2027 is short enough to break any process that still depends on calendar reminders, manual tickets or someone logging in after an expiry warning.

Four things worth doing this quarter

Start with an inventory. Many organisations do not have an accurate list of every certificate they operate, and automation cannot renew certificates that nobody knows exist. Certificate Transparency logs provide a useful way to discover publicly visible certificates issued for your domains.

Then automate every service that uses TLS. The ACME ecosystem has made automated TLS certificate renewal standard, with tools such as Let's Encrypt, Certbot, acme.sh, lego and Caddy's built-in certificate management. Pick a method and standardise it.

Do not forget the systems that are not traditional websites. Mail servers, load balancers, internal APIs, monitoring platforms, VPN concentrators and IPMI interfaces can all depend on certificates and often receive less attention than web servers.

Finally, monitor certificate expiration from the outside. Alerting only on renewal jobs is not enough. A renewal task can succeed while deployment, DNS validation, firewall rules or service reloads fail. Check the certificate that users on the internet actually receive.

Managed platforms have a problem here

Automation is straightforward when you control the operating system. It becomes harder when the platform hides the renewal process.

Many managed hosting products issue certificates through a control panel or provider-managed system, with limited access to ACME hooks or certificate deployment workflows. That was manageable with a 398-day certificate window. At 100 and eventually 47 days, customers become increasingly dependent on the provider's automation working every time.

Root access removes a major dependency

We provide root access because control matters for exactly these kinds of operational requirements.

Our VPS products run on KVM virtualisation with full root access, and our VDS plans provide the same level of control at larger scale. You can install your preferred ACME client, choose your own renewal schedule, and create your own deployment hooks for nginx, HAProxy, Postfix or any other service that needs certificate updates.

Because you control the VM, certificate issuance and renewal do not depend on our internal control panel or provider-managed certificate automation. Your infrastructure, your automation, your certificates.

That also covers more advanced setups. You can manage DNS-01 challenges through your own DNS provider, run a central certificate automation system for multiple servers, or distribute certificates to internal services that are not directly exposed to the public internet.

If you operate services across multiple locations including Tirana, Skopje, Amsterdam or Dublin, the same automation approach works everywhere because each server remains a Linux system you control.

Plans start at €5/mo, we accept crypto, and there is no KYC requirement. Deploy one and configure your certificate automation today.

March 2027 is the real deadline

15 March 2027 is when many organisations will feel the impact. A 100-day certificate window is short enough that quarterly manual processes no longer fit safely inside the renewal cycle.

You have time to prepare. Certificate automation takes minutes to configure compared with the disruption caused by an expired certificate.

Frequently Asked Questions

Are SSL certificates now limited to 200 days?

For newly issued publicly trusted TLS certificates from public certificate authorities, yes. Private certificates and internal PKI systems are not governed by CA/Browser Forum rules.

Does this affect Let's Encrypt certificates?

The change applies to publicly trusted certificates generally. Services such as Let's Encrypt already use the ACME protocol, so users who already have automatic renewal configured are largely prepared for shorter validity periods.

Do private certificates need to follow the 200-day limit?

No. The CA/Browser Forum rules apply to publicly trusted certificates used by browsers and operating systems. Private PKI deployments can choose their own certificate lifetimes.

What happens when certificates become 47 days?

Certificate automation becomes effectively mandatory for most internet-facing services. Manual renewal processes become increasingly risky as the time between issuance and expiration becomes shorter.

Sources

  1. TLS Certificate Lifetimes Will Officially Reduce to 47 Days, DigiCert
  2. Ballot SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods, CA/Browser Forum Server Certificate Working Group

العودة إلى أخبار الاستضافة