Renew SSL Certificate: Let's Encrypt and Paid SSL Guide

SSL Certificates have a limited validity period. When they expire, your website displays a "Not Secure" warning that drives visitors away. Renewing your SSL on time is critical for maintaining trust and traffic. This guide covers renewal for both Let's Encrypt and paid SSL certificates, plus troubleshooting when things go wrong.

Check Your SSL Expiry Date

Before renewing, know when your SSL expires. There are several ways to check:

Via Browser

Click the padlock icon in the address bar → Certificate → look for "Valid to" or "Expires on" date.

Via OpenSSL Command Line

openssl s_client -connect yourdomain.com:443 2>/dev/null | \
  openssl x509 -noout -dates

Via Online Tool

Use AsiaGB SSL Server Test at asiagb.com/ssl-checker.html — enter your domain and see the expiry date instantly.

Best Practice: Renew SSL at least 30 days before expiry to allow time to resolve any issues. For paid SSL, start the renewal process 45–60 days in advance.

Renewing Let's Encrypt

Let's Encrypt certificates last 90 days. On AsiaGB Hosting, renewal happens automatically via DirectAdmin — no action needed from you.

Auto-Renewal on Shared Hosting (DirectAdmin)

AsiaGB Hosting has Let's Encrypt auto-renewal configured. The system renews every 60–75 days (15–30 days before expiry). Check the status in DirectAdmin → SSL Certificates.

Manual Renewal Using Certbot (VPS / Dedicated)

# Dry run to check which certs are expiring
sudo certbot renew --dry-run

# Perform the actual renewal
sudo certbot renew

# Renew a specific domain only
sudo certbot renew --cert-name yourdomain.com

Set Up a Cron Job for Auto-Renewal

# Add to crontab -e (runs on the 1st of each month at 03:00)
0 3 1 * * /usr/bin/certbot renew --quiet && systemctl reload nginx

Renewing Paid SSL (RapidSSL, GeoTrust)

Paid SSL certificates last 1 year. The renewal process involves these steps:

Step 1: Place a Renewal Order

Log in at billing.in.th → My Services → select your SSL Certificate → click Renew. AsiaGB also sends reminder emails 60 days before expiry.

Step 2: Generate a New CSR

Generate a fresh CSR on your server (see How to Generate a CSR) and use this new CSR in the renewal form — do not reuse your old CSR.

Step 3: Complete Domain Validation

The CA will send a validation email to [email protected] or [email protected]. Click the verification link to approve the renewal (for DV SSL).

Step 4: Download and Install the New Certificate

Once you receive the new certificate, install it on your server to replace the old one, then reload your web server:

# Apache
sudo systemctl reload apache2

# Nginx
sudo nginx -t && sudo systemctl reload nginx

Fixing an Expired SSL Certificate

If your SSL has already expired and your site shows "Your connection is not private":

Post-Renewal Verification

After renewing and installing, verify everything is working:

Setting Up SSL Expiry Alerts Before It's Too Late

Knowing when your SSL is about to expire gives you comfortable lead time for renewal. Missing the window means your site shows security warnings, which instantly damages visitor trust. Here are practical ways to stay ahead.

Email Alerts from the CA

Certificate Authorities such as DigiCert (which issues RapidSSL and GeoTrust certificates) send reminder emails to the registered address at 90, 60, and 30 days before expiry. Make sure the contact email on your billing account is current and regularly monitored.

Add a Calendar Reminder

After every successful renewal, record the new expiry date in Google Calendar or Outlook and set a reminder 60 days in advance. This low-tech approach is reliable and costs nothing — you will never be caught off guard.

Use an SSL Monitoring Tool

Services like UptimeRobot offer free SSL expiry monitoring. Add your domain and it will email you automatically when the certificate is approaching expiry. You can also scan your certificate anytime at AsiaGB SSL Server Test.

Automated Alert Script for VPS

If you manage SSL on a VPS, this script sends an email when fewer than 30 days remain:

#!/bin/bash
# ssl-check.sh — alert when SSL has fewer than 30 days remaining
DOMAIN="yourdomain.com"
DAYS_BEFORE=30
EXPIRY=$(openssl s_client -connect "$DOMAIN:443" -servername "$DOMAIN" 2>/dev/null \
  | openssl x509 -noout -enddate | cut -d= -f2)
EXPIRY_EPOCH=$(date -d "$EXPIRY" +%s)
NOW_EPOCH=$(date +%s)
DIFF_DAYS=$(( (EXPIRY_EPOCH - NOW_EPOCH) / 86400 ))
if [ "$DIFF_DAYS" -lt "$DAYS_BEFORE" ]; then
  echo "SSL for $DOMAIN expires in $DIFF_DAYS days!" | mail -s "SSL Alert" [email protected]
fi

Comparing SSL Certificate Types at Renewal Time

Renewal is a good opportunity to evaluate whether your current certificate type still fits your business needs. As your website grows, upgrading to a higher validation level signals greater trust to your visitors.

SSL Type Validity Price From Best For
Let's Encrypt (DV) 90 days Free Personal sites, portfolios
RapidSSL (DV Paid) 1 year 1,000 THB/yr SME business websites
RapidSSL Wildcard 1 year 5,000 THB/yr Multiple subdomains
GeoTrust True BusinessID (OV) 1 year 4,000 THB/yr High-trust business sites
GeoTrust True BusinessID with EV 1 year 7,000 THB/yr E-Commerce, financial

If you are currently on Let's Encrypt and want to build more customer confidence, upgrading to a paid DV SSL such as RapidSSL (1,000 THB/year) at the next renewal is a worthwhile investment that requires no code changes on your site.

Troubleshooting Common SSL Renewal Problems

Even with careful planning, you may encounter issues during the renewal process. These are the most frequently reported problems and their solutions.

DV Validation Email Link Has Expired

DV validation links typically expire within 24–72 hours. If yours expired before you could click it, request a resend of the validation email through the CA portal or contact AsiaGB Support to initiate a resend from our end.

Browser Still Shows the Old Certificate After Installation

This is almost always a caching issue. Try a hard refresh (Ctrl+Shift+R / Cmd+Shift+R) or open your site in an Incognito/Private window. If you use Cloudflare, purge the cache from the Cloudflare dashboard — CDN edge nodes may cache the old certificate for several hours.

Mixed Content Warning After SSL Renewal

Mixed content occurs when a page loads some resources (images, scripts, stylesheets) over plain HTTP instead of HTTPS. Search your HTML source for links beginning with http:// and update them to https:// or the protocol-relative form //.

Certbot Fails: "Too Many Certificates Already Issued"

Let's Encrypt enforces a rate limit of 5 certificates per domain per week. If you hit this limit, wait 7 days and try again. Use the --staging flag for testing certificate issuance without consuming rate-limit quota:

# Test without rate-limit impact
sudo certbot renew --staging

Renew SSL Certificate with AsiaGB

Paid SSL from 1,000 THB/year with 60-day advance expiry reminders and Thai support team for installation assistance.

View SSL Certificates