
SSL Certificates have a limited validity period. When they expire, your website displays a "Not Secure" warning that drives visitors away. Renewing your SSL on time is critical for maintaining trust and traffic. This guide covers renewal for both Let's Encrypt and paid SSL certificates, plus troubleshooting when things go wrong.
Check Your SSL Expiry Date
Before renewing, know when your SSL expires. There are several ways to check:
Via Browser
Click the padlock icon in the address bar → Certificate → look for "Valid to" or "Expires on" date.
Via OpenSSL Command Line
openssl s_client -connect yourdomain.com:443 2>/dev/null | \
openssl x509 -noout -dates
Via Online Tool
Use AsiaGB SSL Server Test at asiagb.com/ssl-checker.html — enter your domain and see the expiry date instantly.
Best Practice: Renew SSL at least 30 days before expiry to allow time to resolve any issues. For paid SSL, start the renewal process 45–60 days in advance.
Renewing Let's Encrypt
Let's Encrypt certificates last 90 days. On AsiaGB Hosting, renewal happens automatically via DirectAdmin — no action needed from you.
Auto-Renewal on Shared Hosting (DirectAdmin)
AsiaGB Hosting has Let's Encrypt auto-renewal configured. The system renews every 60–75 days (15–30 days before expiry). Check the status in DirectAdmin → SSL Certificates.
Manual Renewal Using Certbot (VPS / Dedicated)
# Dry run to check which certs are expiring
sudo certbot renew --dry-run
# Perform the actual renewal
sudo certbot renew
# Renew a specific domain only
sudo certbot renew --cert-name yourdomain.com
Set Up a Cron Job for Auto-Renewal
# Add to crontab -e (runs on the 1st of each month at 03:00)
0 3 1 * * /usr/bin/certbot renew --quiet && systemctl reload nginx
Renewing Paid SSL (RapidSSL, GeoTrust)
Paid SSL certificates last 1 year. The renewal process involves these steps:
Step 1: Place a Renewal Order
Log in at billing.in.th → My Services → select your SSL Certificate → click Renew. AsiaGB also sends reminder emails 60 days before expiry.
Step 2: Generate a New CSR
Generate a fresh CSR on your server (see How to Generate a CSR) and use this new CSR in the renewal form — do not reuse your old CSR.
Step 3: Complete Domain Validation
The CA will send a validation email to [email protected] or [email protected]. Click the verification link to approve the renewal (for DV SSL).
Step 4: Download and Install the New Certificate
Once you receive the new certificate, install it on your server to replace the old one, then reload your web server:
# Apache
sudo systemctl reload apache2
# Nginx
sudo nginx -t && sudo systemctl reload nginx
Fixing an Expired SSL Certificate
If your SSL has already expired and your site shows "Your connection is not private":
- Let's Encrypt expired — Run
certbot renew --force-renewal. On AsiaGB Hosting, contact support to force-renew from the DirectAdmin panel. - Paid SSL expired — You must purchase and install a completely new certificate. An expired paid SSL cannot be technically "renewed" — it must be reissued.
- Temporary fix — If waiting for a new paid certificate, install a free Let's Encrypt certificate in the meantime to restore HTTPS.
Post-Renewal Verification
After renewing and installing, verify everything is working:
- Open your site in an Incognito window to bypass browser cache
- Verify the new expiry date with the SSL Checker tool
- Verify the certificate chain is complete:
openssl verify -CAfile ca-bundle.crt certificate.crt - Test HTTPS on mobile devices as well
Setting Up SSL Expiry Alerts Before It's Too Late
Knowing when your SSL is about to expire gives you comfortable lead time for renewal. Missing the window means your site shows security warnings, which instantly damages visitor trust. Here are practical ways to stay ahead.
Email Alerts from the CA
Certificate Authorities such as DigiCert (which issues RapidSSL and GeoTrust certificates) send reminder emails to the registered address at 90, 60, and 30 days before expiry. Make sure the contact email on your billing account is current and regularly monitored.
Add a Calendar Reminder
After every successful renewal, record the new expiry date in Google Calendar or Outlook and set a reminder 60 days in advance. This low-tech approach is reliable and costs nothing — you will never be caught off guard.
Use an SSL Monitoring Tool
Services like UptimeRobot offer free SSL expiry monitoring. Add your domain and it will email you automatically when the certificate is approaching expiry. You can also scan your certificate anytime at AsiaGB SSL Server Test.
Automated Alert Script for VPS
If you manage SSL on a VPS, this script sends an email when fewer than 30 days remain:
#!/bin/bash
# ssl-check.sh — alert when SSL has fewer than 30 days remaining
DOMAIN="yourdomain.com"
DAYS_BEFORE=30
EXPIRY=$(openssl s_client -connect "$DOMAIN:443" -servername "$DOMAIN" 2>/dev/null \
| openssl x509 -noout -enddate | cut -d= -f2)
EXPIRY_EPOCH=$(date -d "$EXPIRY" +%s)
NOW_EPOCH=$(date +%s)
DIFF_DAYS=$(( (EXPIRY_EPOCH - NOW_EPOCH) / 86400 ))
if [ "$DIFF_DAYS" -lt "$DAYS_BEFORE" ]; then
echo "SSL for $DOMAIN expires in $DIFF_DAYS days!" | mail -s "SSL Alert" [email protected]
fi
Comparing SSL Certificate Types at Renewal Time
Renewal is a good opportunity to evaluate whether your current certificate type still fits your business needs. As your website grows, upgrading to a higher validation level signals greater trust to your visitors.
| SSL Type | Validity | Price From | Best For |
|---|---|---|---|
| Let's Encrypt (DV) | 90 days | Free | Personal sites, portfolios |
| RapidSSL (DV Paid) | 1 year | 1,000 THB/yr | SME business websites |
| RapidSSL Wildcard | 1 year | 5,000 THB/yr | Multiple subdomains |
| GeoTrust True BusinessID (OV) | 1 year | 4,000 THB/yr | High-trust business sites |
| GeoTrust True BusinessID with EV | 1 year | 7,000 THB/yr | E-Commerce, financial |
If you are currently on Let's Encrypt and want to build more customer confidence, upgrading to a paid DV SSL such as RapidSSL (1,000 THB/year) at the next renewal is a worthwhile investment that requires no code changes on your site.
Troubleshooting Common SSL Renewal Problems
Even with careful planning, you may encounter issues during the renewal process. These are the most frequently reported problems and their solutions.
DV Validation Email Link Has Expired
DV validation links typically expire within 24–72 hours. If yours expired before you could click it, request a resend of the validation email through the CA portal or contact AsiaGB Support to initiate a resend from our end.
Browser Still Shows the Old Certificate After Installation
This is almost always a caching issue. Try a hard refresh (Ctrl+Shift+R / Cmd+Shift+R) or open your site in an Incognito/Private window. If you use Cloudflare, purge the cache from the Cloudflare dashboard — CDN edge nodes may cache the old certificate for several hours.
Mixed Content Warning After SSL Renewal
Mixed content occurs when a page loads some resources (images, scripts, stylesheets) over plain HTTP instead of HTTPS. Search your HTML source for links beginning with http:// and update them to https:// or the protocol-relative form //.
Certbot Fails: "Too Many Certificates Already Issued"
Let's Encrypt enforces a rate limit of 5 certificates per domain per week. If you hit this limit, wait 7 days and try again. Use the --staging flag for testing certificate issuance without consuming rate-limit quota:
# Test without rate-limit impact
sudo certbot renew --staging
Renew SSL Certificate with AsiaGB
Paid SSL from 1,000 THB/year with 60-day advance expiry reminders and Thai support team for installation assistance.
View SSL Certificates