Managing Your SSL Certificate Lifecycle
Christopher LeeShare
An SSL Certificate is not something you set once and forget. From choosing the right one to keeping it valid over time, there are five stages to the work, and getting each one right is what keeps a website secure and trusted.
This overview walks through those five stages at a high level. Each one links to a detailed page where the steps are covered in full, so treat it as the map rather than the manual.
Choosing Your SSL Certificate
The first stage is matching the SSL Certificate to what the website actually needs. That means deciding how many names it must cover, whether a single site, a wildcard for every subdomain, or several separate domains on one license, and choosing a validation level.
Domain Validation (DV) confirms control of the domain name and issues quickly, which suits most websites. Organization Validation (OV) and Extended Validation (EV) also verify the organization behind the site, which carries more weight for businesses handling payments or sensitive data. Learn About Domain Validation (DV) 🔗
Creating Your Certificate Signing Request (CSR)
Before an SSL Certificate can be issued, your server needs a Certificate Signing Request (CSR) and its matching private key. The request carries the details that will appear on the SSL Certificate, while the private key must never leave the server it was created on.
The safest approach is to generate the pair on the server where the SSL Certificate will live, keeping the private key under tight access control. At the same time, configure the server to offer only modern protocols, giving the SSL Certificate a secure foundation to sit on. Learn About Certificate Signing Request Basics 🔗
Ordering, Then Validating
With the request ready, you place the order and choose the validation method. Every SSL Certificate requires Domain Control Validation (DCV), which proves you control each domain name on the order, using approver e-mail, a file on your web server, or a Domain Name System (DNS) record.
An Organization Validation (OV) or Extended Validation (EV) order adds checks on the organization itself, handled by the Certificate Authority (CA). Once every check passes, the SSL Certificate is issued, often within minutes for a Domain Validation (DV) order. Learn About The Validation Procedure 🔗
Installing Your SSL Certificate
Once issued, the SSL Certificate has to be installed on your server alongside its private key and the Intermediate Certificates that complete the trust chain. Leaving out the Intermediate Certificates is a common cause of browser warnings, even when the SSL Certificate itself is valid.
Each kind of web server has its own installation steps and file formats, so the detail matters here. Backing up the current configuration before you begin means you can always return to a known good state. Learn About Installing an SSL Certificate 🔗
Monitoring, Then Reissuing
An SSL Certificate is valid for a fixed period, and that period has been getting shorter across the industry. Keeping track of when each one expires is the ongoing part of the work, because an expired SSL Certificate turns visitors away with a security warning.
Rather than rely on memory, the tracking system records every SSL Certificate and warns you before a license period ends. When the time comes, you reissue the SSL Certificate within its license, and the tracking system guides that too. Learn About The Tracking System 🔗
For websites that would rather not track dates at all, Certificate as a Service (CaaS) removes the step entirely. Using the industry standard Automatic Certificate Management Environment (ACME) protocol, your client reissues and installs each SSL Certificate automatically before it expires. Learn About Reissuing Step by Step 🔗
Bringing Every Stage Together
These five stages are the whole of SSL Certificate management : choose, request, validate, install, and keep valid. Handled with the right tools, particularly a tracking system or Certificate as a Service (CaaS), what can feel like a chore becomes close to automatic. Explore Certificate as a Service (CaaS) 🔗