Yeah, some new SSL expiration even though it's not expired. Twice this has happened now. So, looked into it. Of course it just adds costs.
The newly approved measure, initially proposed by Apple and endorsed by Sectigo in January 2025, will gradually reduce certificate lifespans from the current 398 days to 47 days through a phased approach:
March 15, 2026: Maximum TLS certificate lifespan shrinks to 200 days. This accommodates a six-month renewal cadence. The Domain Control Validation (DCV) reuse period reduces to 200 days.
March 15, 2027: Maximum TLS certificate lifespan shrinks to 100 days. This accommodates a three-month renewal cadence. The DCV reuse period reduces to 100 days.
March 15, 2029: Maximum TLS certificate lifespan shrinks to 47 days. This accommodates a one-month renewal cadence. The DCV reuse period reduces to 10 days.
“At Sectigo we have long advocated for shorter certificate lifecycles as a crucial step in bolstering internet security, which is why we endorsed this ballot from its inception,” said Kevin Weiss, chief executive officer at Sectigo. “This collaborative initiative passed by the CA/Browser Forum not only showcases the industry’s unified commitment to enhance digital trust for all but also empowers customers to be at the leading edge of preparing for a quantum future.”
Enhanced security: Shorter certificate renewals protect private keys from being compromised by limiting the time they are exposed to potential threats, ultimately reducing the risk of man-in-the-middle attacks and data breaches.
Encouraging automation: Reducing certificate lifespans encourages automation and the adoption of practices that drive the ecosystem away from baroque, time-consuming, and error-prone issuance processes. The result enables faster adoption of emerging security capabilities, changes in cryptographic algorithms, and general best practices.
Preparing for quantum challenges: In an era of promoting quantum preparedness, shorter certificate lifespans foster crypto agility by accelerating the adoption of stronger algorithms and ensure compliance with evolving security standards.
“The industry’s unified support for reducing certificate lifespans to 47 days reflects a shared commitment to enhancing digital security and trust for all,” said Tim Callan, chief compliance officer at Sectigo and vice-chair of the CA/Browser Forum. “This pivotal and positive advancement for our industry underscores the importance of agility and proactive risk management in today’s threat landscape while preparing for the risks of the quantum era.”