Renew your SSL certificate before the expiration date on your certificate

An SSL certificate has an expiration date — usually one or three years from when you first bought it. When that date approaches, your certificate stops working and browsers will show a security warning to anyone visiting your site. Renewing means getting a new certificate from your provider before the old one expires, which takes a few days to a few weeks depending on the certificate type.

The renewal process differs slightly based on who issued your certificate and what kind of certificate you have, but the basic steps are the same: request a new certificate from your provider, prove you control the domain, and install the new certificate on your server before the old one expires.

Key Takeaways

  • Start the renewal process at least 30 days before your certificate expires, since validation and installation can take one to three weeks.
  • Most providers send reminder emails when your certificate is about to expire, but checking your certificate details directly is more reliable than waiting for the email.
  • Domain validation certificates renew faster than organization validation certificates because they require less documentation.
  • You can renew with your current provider or switch to a different one, but switching takes longer because you start from scratch.
  • After you receive the new certificate, you must install it on your server and remove or replace the old one to avoid conflicts.

Check your certificate expiration date and set a reminder

Find out exactly when your certificate expires by checking your hosting account or your certificate provider's dashboard. Log into the account where you purchased the certificate — this might be your web host, a dedicated certificate provider like DigiCert or Sectigo, or a service like Let's Encrypt if you use free certificates.

Most providers show the expiration date in a certificate details page or in an email receipt from when you bought it. You can also check the expiration date directly in your browser: visit your website, click the lock icon in the address bar, and look for the certificate details. The "Valid until" or "Expires on" field shows the exact date.

Set a calendar reminder for 30 days before that date. This gives you enough time to request the certificate, complete validation, and install it without your site going down. If you miss the deadline and your certificate expires, visitors will see a security warning and some browsers will block access entirely.

Request a new certificate from your provider

Log into your certificate provider's account and look for a "Renew" button or link next to your current certificate. This is faster and cheaper than buying a new certificate from scratch because most providers offer renewal discounts and can reuse some of your existing information.

If you cannot find a renewal option, you may need to purchase a new certificate instead. This is more expensive but works the same way — you will still need to validate the domain and install the certificate. Some providers automatically renew certificates if you have auto-renewal turned on, so check your account settings to see if this is already happening.

When you request the renewal, you will need to choose the same certificate type as your current one: Domain Validation (DV), Organization Validation (OV), or Extended Validation (EV). DV certificates renew the fastest because they only require you to prove you control the domain. OV and EV certificates require additional documentation about your business, which takes longer.

Complete domain validation

After you request the renewal, your provider will send you a validation email or ask you to complete validation in their dashboard. For a Domain Validation certificate, you will need to prove you control the domain by choosing one of these methods: clicking a link in an email, adding a DNS record to your domain, uploading a file to your website, or answering a security question.

The email method is fastest — your provider sends a link to an email address associated with your domain (usually admin@yourdomain.com or the email on file with your domain registrar). Click the link within the time limit, usually 30 days, and validation is complete. If you do not receive the email, check your spam folder or ask your provider to resend it.

The DNS method requires you to log into your domain registrar's control panel and add a temporary DNS record with a code your provider gives you. This takes a few minutes but is more reliable if your domain email is not working. Once you add the record, your provider's system checks for it automatically, usually within a few minutes to a few hours.

Download and install the new certificate

After validation is complete, your provider will send you the new certificate file, usually as a .crt or .pem file, along with any intermediate certificates you need. Some providers also send a private key file (.key) if you are generating a new key pair — keep this file secure and never share it.

Install the new certificate on your server before your old certificate expires. The exact steps depend on your hosting platform. If you use cPanel, look for "AutoSSL" or "Install SSL Certificate" in the security section. If you use Plesk, go to Certificates and upload the new certificate file. If you manage your own server, you will need to copy the certificate files to the correct directory and update your web server configuration (usually in Apache's ssl.conf or Nginx's server block).

After installation, restart your web server to load the new certificate. Test that it is working by visiting your website and checking the lock icon in the browser — it should show the new certificate with the updated expiration date. If the old certificate is still showing, clear your browser cache or try a different browser.

Remove the old certificate to avoid conflicts

Once the new certificate is installed and working, remove or disable the old certificate from your server. Leaving both installed can cause conflicts or confusion about which certificate is active. In cPanel, go to the SSL/TLS Status section and remove the old certificate. In Plesk, delete it from the Certificates list. On a self-managed server, remove the old certificate file from your web server configuration.

If your old certificate is still in use on other services — like an email server, FTP server, or API endpoint — you will need to install the new certificate on those services too. Check each service's settings to see which certificate it is using and update them before the old certificate expires.

Renewing with a different provider

You can switch to a different certificate provider during renewal instead of renewing with your current one. This takes longer because you start the entire process from scratch — you request a new certificate, complete validation, and install it — but you might save money or get better support.

Before you switch, check whether your current provider has a transfer or reissue option. Some providers allow you to move a certificate to a different account or domain without buying a new one. If that is not available, you will need to purchase a new certificate from the new provider and follow the full validation and installation process.

The main drawback to switching is timing. If you wait until your certificate is about to expire, you might not have enough time to validate and install a certificate from a new provider. Plan the switch at least 60 days before your current certificate expires.

Frequently Asked Questions

What happens if my SSL certificate expires?

Your website will still load, but browsers will show a security warning and some visitors will not be able to access it. Search engines may also lower your site's ranking. The fix is to renew or install a new certificate immediately, but it is better to renew before expiration to avoid any downtime.

Can I renew my certificate early?

Yes. Most providers allow you to renew up to 90 days before expiration. Early renewal is useful if you want to lock in a discount or if you are planning to switch providers. The new certificate will start immediately, and your old certificate will stop working.

Do I need a new private key when I renew?

No. You can reuse your existing private key during renewal, which is faster and simpler. Your provider will ask whether you want to generate a new key or use an existing one — choose existing unless you have a specific reason to change it.

How long does SSL renewal take?

Domain Validation certificates usually renew within a few hours to a few days after you complete validation. Organization Validation and Extended Validation certificates take one to three weeks because your provider must verify your business details. Installation on your server takes a few minutes once you have the certificate file.

Will renewing my certificate change my website's URL or settings?

No. Renewing keeps your domain, website content, and all settings exactly the same. The only thing that changes is the certificate file itself, which is invisible to your visitors except for the updated expiration date in the browser's security details.