- Background: Why CA/Browser Forum Shortened SSL Lifetimes
- SSL Validity Reduction Timeline: 2026–2029
- Impact on Website Owners
- Auto-Renewal Is the Primary Solution
- DirectAdmin AutoSSL with Let's Encrypt
- How Paid SSL Certificates Will Adapt
- Checklist: Preparing for 47-Day SSL
- Frequently Asked Questions
- Summary
Background: Why CA/Browser Forum Shortened SSL Lifetimes
In 2025, the CA/Browser Forum — the governing body that sets global SSL/TLS standards, comprising browser vendors (Google, Apple, Mozilla, Microsoft) and major Certificate Authorities — voted to significantly reduce the Maximum Validity of SSL certificates.
The current maximum SSL certificate lifetime is 398 days (approximately 13 months). However, security experts argue this is too long: certificate data such as domain ownership and public keys can become stale or compromised without detection.
SSL Validity Reduction Timeline: 2026–2029
The CA/Browser Forum has planned a phased reduction of Max Validity to give all parties time to adapt:
| Effective Date | Max Validity | Max DCV Reuse | Action Required |
|---|---|---|---|
| March 15, 2026 | 200 days | 200 days | New SSL issued after this date: 200-day max |
| March 15, 2027 | 100 days | 100 days | Renewals needed 3–4 times per year |
| March 15, 2029 | 47 days | 10 days | Auto-Renewal effectively required (~8×/year) |
Impact on Website Owners
The shortened SSL validity period has several significant implications for website operators:
1. Far More Frequent Renewals
Instead of renewing once per year, by 2029 you'll need to renew approximately 7–8 times per year. Manual renewals become impractical at this frequency.
2. Manual Renewal Workflows Must Change
Websites that still renew SSL manually — downloading a CSR file and emailing it to a CA — will face an unsustainable burden. Automated systems are no longer optional.
3. DCV Reuse Drops to Just 10 Days
From 2029 onward, CAs must re-validate domain control every 10 days, fundamentally changing how SSL issuance works at scale.
4. Security Benefits
- Compromised private keys can only be exploited for 47 days, significantly limiting damage
- OV/EV certificate data (company name, etc.) is verified more frequently, improving accuracy
- Certificate Transparency (CT) log coverage improves across the ecosystem
Auto-Renewal Is the Primary Solution
When SSL certificates need renewal 8 times per year, manual processes simply won't scale. Auto-Renewal is the essential capability every website owner needs.
What Is the ACME Protocol?
ACME (Automatic Certificate Management Environment) is a standard protocol developed by Let's Encrypt that enables systems to:
- Request new SSL certificates automatically
- Validate domain ownership automatically (via DNS-01 or HTTP-01 challenges)
- Renew certificates before expiry without administrator intervention
As the CA/Browser Forum mandates 47-day validity, all CAs will be required to support ACME — for both free (Let's Encrypt) and paid (RapidSSL, GeoTrust) certificates.
DirectAdmin AutoSSL with Let's Encrypt
For websites hosted on DirectAdmin — the control panel used exclusively at AsiaGB — the built-in AutoSSL feature provides Let's Encrypt integration at no cost:
How to Enable AutoSSL on DirectAdmin
- Log in to your DirectAdmin Control Panel
- Navigate to SSL Certificates
- Select Let's Encrypt
- Click Save to activate AutoSSL
DirectAdmin will then automatically renew your SSL every 60 days (30 days before expiry), covering all domains and subdomains in your hosting account.
| SSL Type | Certificate Lifetime | Auto-Renewal | Best For |
|---|---|---|---|
| Let's Encrypt (AutoSSL) | 90 days → 47 days (2029) | ✅ Automatic | General websites, blogs |
| RapidSSL DV (฿1,000/yr) | 398 days → 47 days (2029) | ⚙️ ACME setup required | SME business websites |
| GeoTrust OV (฿4,000/yr) | 398 days → 47 days (2029) | ⚙️ ACME setup required | Organizations needing OV |
| RapidSSL Wildcard (฿5,000/yr) | 398 days → 47 days (2029) | ⚙️ ACME setup required | Multiple subdomains |
How Paid SSL Certificates Will Adapt
Paid SSL certificates such as RapidSSL, GeoTrust, and Sectigo retain key advantages even with shorter validity periods:
- OV/EV Validation — Verifies organizational identity, providing trust signals unavailable with Let's Encrypt
- Wildcard Coverage — One certificate covers *.domain.com and all subdomains
- Warranty Protection — Paid SSL includes financial warranty coverage against CA-side errors
- Priority Support — Direct access to CA support teams
When the 47-day rule takes effect in 2029, all CAs in the CA/Browser Forum will be required to support ACME API, making automated renewal for paid SSL a universal standard — eliminating the need for manual CSR downloads and email submissions.
Checklist: Preparing for 47-Day SSL
Follow this checklist to prepare systematically for the transition:
Do Now
- ✅ Audit all SSL certificates across your domains — note expiry dates and renewal methods
- ✅ Enable AutoSSL in DirectAdmin if not already active
- ✅ Verify SSL expiry notification emails are still functioning
- ✅ Test your auto-renewal system at least once
Do Before March 2026
- 📋 Build a complete SSL certificate inventory for your organization
- 📋 Confirm your SSL provider supports the ACME Protocol
- 📋 Plan budget for any ACME-compatible paid SSL solutions needed
Do Before March 2029
- 🔧 Configure ACME clients for all paid SSL certificates
- 🔧 Conduct end-to-end Auto-Renewal testing in production
- 🔧 Set up alerts for renewal failures exceeding one attempt
- 🔧 Verify firewall rules allow traffic on ports required by ACME clients
Frequently Asked Questions
🔐 SSL Certificates Ready for New Standards
AsiaGB offers a full range of SSL types — from RapidSSL DV at ฿1,000/year to Wildcard at ฿5,000/year
with DirectAdmin AutoSSL for free Let's Encrypt included
🔖 Summary: SSL at 47 Days — No Fear, Just Preparation
- The CA/Browser Forum is reducing SSL Max Validity to 47 days by 2029, in phases: 200 → 100 → 47
- The goal is stronger security: limiting the damage window from key compromise and certificate staleness
- Solution: Auto-Renewal — DirectAdmin AutoSSL (Let's Encrypt) for hosting, ACME Protocol for paid SSL
- Existing SSL certificates remain valid for their original term, but Auto-Renewal should be set up before 2026
- AsiaGB Hosting includes AutoSSL on DirectAdmin — ready to use with no additional configuration required