TLS Certificates and Renewal: The Decisions That Matter
The certificates that enable HTTPS, how they are issued and renewed, and the automation that prevents expiry outages.
The key figures
- Let's Encrypt
- issues free, short-lived certificates, historically valid for 90 days
- ACME
- the protocol for automated issuance, defined in RFC 8555
- Certificate lifetimes
- the industry is moving to shorter maximum validity periods
- Monitoring
- expiry monitoring catches failed renewals
Why this is worth getting right
Expired certificates take sites offline with browser warnings, and automated renewal prevents a common and embarrassing failure.
Do this, not that
Do
- Automate certificate issuance and renewal
- Monitor expiry dates
- Cover all hostnames, including www
- Test renewal after server changes
- Use HSTS once HTTPS is stable
Don’t
- Manual renewal reminders
- Certificates missing subdomains
- Unmonitored renewals failing silently
- Mixed content after switching to HTTPS
When to bring in help
Our advice Bring in help when certificates have expired or renewal processes are manual.
Where this comes from
- Let's Encrypt — How it works
- RFC Editor — RFC 8555 Automatic Certificate Management Environment (ACME)
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.