Lifetime
Why a certificate lives only 200 days
Certificate authorities are shortening the lifetime in stages for everyone. That’s why we sell a subscription and reissue the certificate ourselves.
The lifetime shrinks in stages
Every date is a CA/Browser Forum decision, mandatory for every public certificate, not just ours.
- 398 daysuntil 15.03.2026
- 200 daysfrom 15.03.2026 — now
- 100 daysfrom 15.03.2027
- 47 daysfrom 15.03.2029
Why certificate authorities do this
The CA/Browser Forum — an alliance of browsers and certificate authorities that sets the rules for public certificates — is shortening the maximum lifetime in stages. A shorter lifetime means less time for an attacker to use a stolen key, and a stronger push to automate reissuance instead of manual, once-a-year work.
What this means for us
Everything that repeats within the subscription, we do ourselves: you don’t need to log in twice a year and reissue the certificate manually, like with most sellers.
- 01Domain on our NSWe add the domain validation record ourselves at every reissue.
- 02Domain on other NSYou add a CNAME to our validation zone once. Then it’s automatic too.
- 03Confirmation every timeEvery reissue requires a new domain confirmation: we complete it automatically, the same way as at first issue.
What about organisation verification in OV?
The certificate authority reuses organisation verification for up to 398 days, then asks again, but not from a blank page: the form is already filled in from the previous application plus your profile and state register data, you just confirm it. Reminders arrive 45, 30 and 14 days ahead.
Common questions
What do I do at every reissue?
Nothing, if the domain is on our NS. If it’s on other NS, you add a CNAME to our validation zone once, and it’s automatic too.
Why not just sell a 2-year certificate?
Because no certificate authority issues a public certificate longer than the current maximum anymore. That’s an industry rule, not our restriction. We implement a multi-year purchase as a subscription.
What if I switch to other NS?
It’s enough to add CNAME delegation to our validation zone once. Reissuance stays just as automatic after that.
Does the shorter lifetime apply to paid OV/EV too?
Yes, the lifetime limit is the same for DV, OV and EV. Separate from that is organisation verification for OV/EV, which the certificate authority repeats once a year.