SSL/TLS certificates limited to 825 days

This applies to all SSL certificates issued by a publicly trusted CA. The duration means you can renew a certificate for 2 years and carry over the remaining time, up to 3 months, onto the new certificate.

It is the CA/Browser Forum that adopted this change, and even though it does not take effect until 1 March 2018, changes are already happening.

Reuse of validation, for example when reissuing, will also be affected. This means that 3-year certificates may need to be validated again before they can be reissued in their final year.

Historically, the maximum lifetime has been getting shorter: from unlimited to 60 months, to the current 39 months, and now to 825 days.

To prevent certificates from being cut short, some CAs are already changing how long you can purchase certificates for.

This means that as early as next week (around 20 April 2017), the first CAs will stop issuing 3-year certificates and only accept 2-year orders.

The remaining CAs will be forced to follow suit, and at some point between now and 1 March 2018, the 3-year option will disappear entirely.

It is about SSL/TLS security

The reason for wanting a shorter maximum lifetime for SSL/TLS certificates is that the following types of certificates will naturally expire sooner:

  • Certificates created with weak and possibly broken technologies, such as SHA-1.
  • Certificates validated against standards that have since been tightened, such as DNS/URL validation content.
  • Certificates issued with incorrect or misleading information.
  • Certificates issued through malicious intent, hackers, and so on.

In fact, three weeks before the vote on this proposal, there was a proposal to reduce certificate validity to 13 months. Fortunately, it was strongly voted down due to the expected far greater administrative burden.

The new standard of 825 days, or approximately 27 months, is therefore a compromise between faster replacement for security reasons and increased administration costs from more frequent replacements.

What does this mean for you?

It does not affect any currently issued certificates.

It does not affect day-to-day operations. It does, change how often an SSL certificate needs to be installed on a given system. And for those with many systems, it can add quite a few extra hours per year.

CA/Browser Forum is an association of the largest public certificate authorities and browser manufacturers, which together adopt shared rules for SSL/TLS.