Description of SSL Certificate Renewal Timeline
The validity period of SSL certificates has been shortening year by year. Currently, according to the regulations of the CA/Browser Forum, the maximum validity period of an SSL certificate shall not exceed 398 days. For purchased multi-year certificates, the certificates will be issued in batches, and the maximum validity period for each issuance shall not exceed 398 days. This article provides a detailed explanation of the SSL certificate renewal time window and the renewal logic for different brands.
Validity Period Connection and Renewal Rules
I. Core Renewal Rules
-
Renewal time window
- Existing customers on the Racent platform can initiate a renewal application and have a new certificate issued as early as 1 month in advance.
- It is recommended to complete the renewal process at least 14 working days in advance.
-
Validity period connection logic
Brand Type Renewal Feature Seamless connection type Seamless validity period connection between old and new certificates is available for sslTrus/Sectigo/Digicert Long-cycle issuance type Globalsign/sslTrus can issue certificates with 13 months of validity Standard renewal type For brands such as CFCA, the validity period is calculated from the new issuance date
II. Renewal Rules for Existing Racent Customers
| Brand | Product Series | Renewal Rule |
|---|---|---|
| sslTrus | sslTrus Basic sslTrus Pro | Renew within one month in advance, a 13-month certificate can be issued |
| Sectigo | Sectigo PositiveSSL | Renew within one month in advance, a 13-month certificate can be issued |
| Digicert | Basic SecureSite | Renew within one month in advance, the expiration date will be extended by 1 year from the current year's expiration date |
| GeoTrust | GeoTrust RapidSSL | Renew within one month in advance, the expiration date will be extended by 1 year from the current year's expiration date |
| Globalsign | Globalsign | Renew within one month in advance, a 13-month certificate can be issued |
| CFCA | China Root China Root Pro | Renew within one month in advance, the expiration date will be extended by 1 year from the current year's expiration date |
CFCA requires the provision of application materials + the original certificate .crt file or DN number.
The certificate renewal process is: Log in to the Racent backend -> Click order details -> Click the renewal button -> Click Submit
III. Important Notes
- The validity period of all certificates starts from the date of issuance. Therefore, certificate renewal cannot directly extend the validity period of the previous certificate; instead, a new certificate is issued.
- White-label certificates shall follow the rules of the original vendor.
-
Rules for domain replacement during certificate reissuance SSL certificate reissuance refers to the process of reissuing an existing certificate. It is generally requested when the customer's private key is lost or compromised, or when certificate information needs to be changed. Reissuing a certificate incurs no fees, and customers can reissue SSL certificates an unlimited number of times within the certificate validity period. However, domain replacement is usually not supported during reissuance (to learn about the rules for replacing domains through reissuance, see "Can I Replace Domains When Reissuing an SSL Certificate Within Its Validity Period?".
-
Certificate billing To learn about certificate billing rules and their correspondence with validity periods, see "SSL Certificate Billing Overview"