3 ms·
I've seen this happen to multiple sites and was wondering if there was a reason why some CAs don't let you issue a new cert until the day of the expiry. It does
by Sxw1212 12y ago
I've seen this happen to multiple sites and was wondering if there was a reason why some CAs don't let you issue a new cert until the day of the expiry. It doesn't seem like that would open up much of an attack surface.
- jlgaddis 12y agoWhich CAs do that? I get alerts from our monitoring system 30d prior to expiration and have not had any problems generating new certs then (and they expire on the same day as the previous -- i.e., I don't "lose" three weeks if I renew three weeks early).
- justinsb 12y agoIf your CA doesn't let you renew your cert well in advance of expiry (which I find hard to believe), get a new cert on a different CA. You can have multiple certs valid for the same domain name, from different providers; the active cert is the one you serve.
- agwa 12y agoI've never heard of a CA doing that. By and large, the reason why this happens is human error - no one knows the cert is about to expire because it's not being monitored and/or the email from the CA (if they even send one) goes to a mailbox that's not being read. But there's no reason why a rote task like renewing a certificate should be left to humans. It should be automated, which is what my startup, https://sslmate.com/ https://sslmate.com/, is doing.
- homakov 12y agoyou should put cert checker on top, seems like a great feature