Description of Multi-Year Certificate Delivery Methods
I. Maximum Validity Period of SSL Certificates
According to the regulations of the CA/Browser Forum, as of September 1, 2020, the maximum validity period of all publicly trusted SSL certificates (including DV, OV, and EV types) shall not exceed 398 days (approximately 13 months). This rule applies regardless of certificate brand (such as DigiCert, Sectigo, etc.) or type (single-domain, multi-domain, wildcard).
Background and Exceptions
-
Historical Policy Changes:
- Before 2018, certificates with a maximum validity of 5 years were allowed, which was later gradually shortened to 2 years and then 1 year.
- Shortening the validity period is designed to reduce the risk of private key compromise and enforce regular updates to improve security.
-
Exceptions:
- Private PKI/Internal Certificates: Certificates issued by an enterprise's self-built CA are not subject to this restriction, but are limited to internal system use only.
- Test Certificates: Some certificates for testing purposes may offer longer validity periods (require manual trust and are not suitable for production environments).
II. Delivery Methods for Multi-Year Certificates
Although the validity period of a single certificate does not exceed 398 days, most Certificate Authorities (CAs) offer "multi-year plans" (e.g., 2-year, 3-year). The actual delivery process is as follows:
1. Purchasing a Multi-Year Plan
- Fee Payment: Pay the fee for the multi-year plan in a lump sum (some CAs offer discounts).
- Initial Issuance: Obtain the first certificate with a 398-day validity period immediately.
2. Subsequent Certificate Renewal Process
- Automatic Renewal (Recommended):
- Some CAs automatically reissue new certificates before expiration (Domain Control Validation is still required).
- You need to log in to the CA console to manually submit a renewal request and re-complete Domain Control Validation (DCV).
- Manual Renewal:
- You need to log in to the CA console to manually submit a renewal request and re-complete Domain Control Validation (DCV).
3. Key Points of the Renewal Process
- Domain Validation: Domain control must be re-validated for each renewal (via DNS, HTTP file, or email validation).
- Generating New Private Key and CSR: It is recommended to generate a new private key and CSR (Certificate Signing Request) for each renewal to avoid the risk of long-term private key exposure.
- Certificate Replacement: Deploy the new certificate to the server manually or via automated tools (CLM systems).
4. Actual Delivery Example
Take purchasing a 2-year certificate as an example:
- Initial Delivery: A certificate with a 398-day validity period (approximately 13 months).
- Second-Year Certificate Delivery: 30 days before the first certificate expires, we will remind you to complete the renewal, obtain the new certificate, and replace it with the second-year issued certificate.
- Multi-year plan: Essentially a "multi-year service subscription", which requires annual renewal and re-validation.
- Core objective: Improve network security by shortening validity periods and enforcing renewals.
It is recommended to plan the certificate update process in advance to avoid service interruption caused by expiration.
5. Notes
- Price Risk: Price adjustments may apply when renewing a multi-year plan (e.g., CA price increases during the second-year renewal).
- Technical Support: Ensure that the multi-year plan includes ongoing technical support services.
- Refund Policy: Some CAs do not provide refunds for unused years.
III. Long-Term Certificate Management Recommendations
1. Automation Tools
- Use sslTrus CLM to achieve automatic renewal and automatic certificate deployment.
2. Monitoring and Alerts
- Monitor certificate expiration dates through sslTrus CLM to avoid service interruption.
3. Centralized Management Platform
- Enterprise users are recommended to adopt an automated certificate operation and maintenance platform (sslTrus CLM) to centrally manage multiple certificates.