SSL Certificate renewal and expiration

Updated at:

When an SSL certificate expires, HTTPS services are interrupted. This topic describes how to confirm the expiration status, determine the resolution, and complete the renewal when a certificate is about to expire or has expired.

Confirm the expiration status and determine the resolution

Follow these three steps to find your certificate, check its expiration dates, and choose the right resolution.

Step 1: Locate the target certificate

SSL Certificate Management has two versions, V2.0 and V1.0, with different management entries. If you hold certificates in both versions, open the following pages separately to confirm where the target certificate is located:

Entry

Description

SSL Certificate Management V2.0

The V2.0 management page. All newly purchased certificates are managed here, including Commercial Certificates, Individual Test Certificate (Formerly Free Certificate), and Uploaded Certificates.

SSL Certificate Management (V1.0 new purchases discontinued)

The V1.0 management page. Only existing Commercial Certificatesand Individual Test Certificate (Formerly Free Certificate) instances are managed here. New purchases are discontinued. If your account has no V1.0 certificates, the link opens the console homepage.

Step 2: Confirm the expiration time

Note

The concepts in this section apply only to Commercial Certificates. For Individual Test Certificate (Formerly Free Certificate), the subscription validity period is the same as the certificate validity period, so there is no need to distinguish them; for Uploaded Certificates, the subscription validity period does not apply. For these two certificate types, skip directly to Step 3: Determine the resolution.

Constrained by the policy of the global certificate industry organization (CA/B Forum), the maximum validity period of a single commercial certificate has being shortened to about 6 months, while a subscription can last 1 year, 2 years, or longer. Therefore, commercial certificates have two types of validity periods:

  • The subscription validity period is the total service duration of the subscription you purchased.

  • The certificate validity period is the usable duration of a single certificate, currently about 6 months (subject to the actual display in the console). Certificates purchased before this policy change may show longer durations, such as 12 months.

    The relationship between the subscription validity period and the certificate validity period is as follows:

image
  • The subscription validity period is counted from the issuance date of the first certificate, not from the purchase date.

  • Within the subscription period, when a certificate expires, apply for the next certificate. When the subscription expires, renew it first to extend the subscription validity period before you can continue applying for certificates.

Example: If you purchase a 1-year subscription on 2026-01-10 and the first certificate is issued on 2026-01-15:

  • Subscription expiration date: 2027-01-15

  • The first certificate expires around 2026-07-15, when you must apply for a second certificate to replace it

  • The second certificate expires around 2027-01-15 (the subscription expiration date). To continue using the service, renew the subscription to extend it

  • After a 1-year renewal, the subscription expiration date is extended to 2028-01-15 (counted 1 year from the original subscription expiration date)

Use the following methods to check the subscription expiration date and the certificate expiration date:

V2.0

  • Subscription expiration date: On the Commercial Certificates tab, check the Subscription Period column of the target certificate.

  • Certificate expiration date: On the Commercial Certificates tab, check the Status column of the target certificate. This column shows the certificate validity period as a date range (start date to end date), and the end date is the expiration date of the current certificate.

V1.0

On the Commercial Certificates tab, check the Validity Period column.

  • Certificate expiration date: The date shown in the Validity Period column of the target certificate is the expiration date of the current certificate. The column shows specific dates after the certificate is issued (the status is Issued, Pending Expiration, Expired, or Revoked). Before the certificate is issued, the column shows the certificate duration (such as 6 months or 12 months).

  • Subscription expiration date: Certificates in the same subscription are linked vertically by yellow lines image.

    • No yellow line (only one certificate): The date in the Validity Period column of that certificate is the subscription expiration date.

    • Yellow lines present (multiple certificates): The date in the Validity Period column of the last certificate is the subscription expiration date. If the last certificate has not been issued, find the last certificate that shows a date (from bottom to top), then add the durations of all certificates below it (the 6 months or 12 months shown in the Validity Period column) to that date in sequence. The result is the subscription expiration date.

      Example: Certificate 2 is the last certificate that shows an expiration date (2026-07-15). Certificate 3 below it is pending issuance with a duration of 12 months, so the subscription expiration date is 2026-07-15 + 12 months = 2027-07-15.

      Certificate

      Validity Period

      Certificate 1

      2025-01-15 ~ 2025-07-15 (6 months)

      Certificate 2

      2025-07-15 ~ 2026-07-15 (12 months)

      Certificate 3

      12 months (pending issuance)

Step 3: Determine the resolution

Based on the certificate type and the expiration status, choose a resolution from the following table. For Individual Test Certificate (Formerly Free Certificate), the certificate expiration date equals the subscription expiration date, and renewal is not supported.

Certificate type

Status

Resolution

Commercial Certificates

Subscription not expired

No renewal is needed. Apply for the next certificate instead. In V2.0, apply manually. For the procedure, see Apply for a certificate. In V1.0, the system automatically submits the application for the next certificate when the remaining validity period of the current certificate is less than 15 days. If the application fails, see certificate verification.

Subscription about to expire

Renew the subscription to extend it. For the procedure, see Renew an Uploaded Certificates. V2.0 certificates purchased before 2026-05-06 do not support renewal and must be repurchased. See Purchase a certificate.

Subscription expired

Renewal is not supported. Purchase a new one. For the procedure, see Purchase a certificate.

Uploaded Certificates

Certificate about to expire

Renew it on Alibaba Cloud. For the procedure, see Renew a Commercial Certificates. Alternatively, renew it through the original purchase channel and upload the new certificate to Alibaba Cloud after it is issued. For the procedure, see Upload a certificate.

Certificate expired

Renewal is not supported. Purchase a new one through the original channel, or purchase a Commercial Certificates on Alibaba Cloud. For the procedure, see Purchase a certificate.

Individual Test Certificate (Formerly Free Certificate)

Free Edition certificate expires

If you still have free quota in the current calendar year, claim a free certificate again. If the quota is used up, purchase the Pro Edition or purchase a Commercial Certificate. On the SSL Certificate Management V2.0 page, click the Individual Test Certificate (Formerly Free Certificate) tab to view purchased certificates and the Free Certificate Quota. If the Free Certificate Quota shows "2 / 20", the account has claimed 2 of the 20 free certificates available in the current calendar year, and 18 remain.

Pro Edition certificate expires

Purchase the Pro Edition again, or purchase a Commercial Certificate.

Note

The renewal action appears under different button names in the console: Renew for V2.0 commercial certificates, Renew Purchase for V1.0 commercial certificates, and Update Certificate for uploaded certificates.

Renew a Commercial Certificates

Renewal extends the subscription validity period of a commercial certificate. The procedures in this section apply when the subscription has not expired and the certificate is issued or about to expire (the remaining validity period is less than 15 days). If the subscription has expired, renewal is not supported. Purchase a new certificate instead. If the certificate has expired but the subscription is still valid, no renewal is needed. Apply for the next certificate instead.

V2.0

Prerequisites

The Status must be Issued or About to Expire (the remaining validity period is less than 15 days). The renewal button is not displayed for other statuses.

Procedure

  1. Go to the SSL Certificate Management V2.0 page.

  2. On the Commercial Certificates tab, find the target certificate subscription instance.

  3. In the Actions column of the target certificate subscription instance, click the image icon, and then click Renew in the dialog box.

  4. On the page that appears, select the renewal duration, select auto-renewal if needed, and complete the payment.

    After you enable auto-renewal, the system automatically deducts the fee and extends the subscription before expiration. No manual payment is required.

Verify that the renewal has taken effect: on the Commercial Certificates tab, check whether the Subscription Period of the certificate instance has been extended by the renewal duration. The current certificate still shows the About to Expire status, which is expected, because renewal does not extend the validity period of the current certificate.

What to do next

  • Managed Service enabled:

    When the remaining validity period of the current certificate is less than 15 days, the system automatically submits the application for a new certificate. Depending on the certificate type, you may need to complete validation:

    • DV (domain validated) certificates: If the domain name is managed in the current Alibaba Cloud account, or validation-free authorization is configured, the certificate can be issued fully automatic. Otherwise, you must complete domain ownership validation.

    • OV (organization validated)/EV (extended validation) certificates: You must complete qualification authentication with the CA (handle the domain validation email and phone verification). This usually takes 3 to 7 business days.

      After the new certificate is issued, the system automatically deploys it to associated Alibaba Cloud services, such as CDN, WAF, and SLB. Certificates deployed on self-managed web servers on ECS or on-premises servers must still be downloaded and installed manually. For an introduction to the Managed Service, see Managed Service overview.

  • Managed Service not enabled:

    Apply for and deploy a new certificate yourself. For the procedure, see Apply for and deploy the new certificate after renewal.

V1.0

Prerequisites

The certificate Status must be Pending Expiration (the remaining validity period is less than 15 days). The renewal button is not displayed for other statuses.

Procedure

  1. Go to the SSL Certificate Management (V1.0 new purchases discontinued) page.

  2. On the Commercial Certificates tab, find the target certificate. In the Actions column, click Renewal purchase.

  3. In the Certificate renewal panel, configure the following parameters:

    • CSR Generation: Select Automatic (Recommended), which follows key rotation security practices. You can also select Manual or Original Key Inherited. For more information, see CSR configuration.

    • Domain Verification Method: By default, the method of the old certificate is used. You can change it if needed.

    • Contact: Make sure the contact information is accurate and valid.

    • Renewal Period: Before you configure this parameter, check the remaining certificate quota at the top of the SSL Certificate Management (V1.0) page. The quota is the number of certificates that can still be issued in the V1.0 resource plan. The renewal period depends on the quota:

      • Quota > 0: The renewal period is fixed at 1 year. One quota unit is consumed, and no extra payment is required. The new certificate stays in the V1.0 tab.

      • Quota = 0: You must pay separately for a new subscription duration. The available periods are determined by the certificate brand (usually 1 to 3 years). The new certificate is created on the V2.0 Commercial Certificates tab, and subsequent operations must be completed in V2.0.

  4. Click Renewal immediately and complete the payment.

  5. Verify that the renewal has taken effect: a new certificate appears in the Pending Application status. If you renewed by paying separately because no quota remained, the new certificate is created in V2.0.

What to do next

You must manually apply for and deploy the new certificate. Otherwise, HTTPS service interruption occurs. For the procedure, see Apply for and deploy the new certificate after renewal.

Renew an Uploaded Certificates

This procedure applies when the uploaded certificate is about to expire (the remaining validity period is less than 15 days).

Prerequisites

The certificate Status is Pending Expiration (the remaining validity period is less than 15 days).

Procedure

  1. Go to the SSL Certificate Management V2.0 page.

  2. On the Uploaded Certificates tab, find the target certificate. In the Actions column, click Update, the renewal entry for uploaded certificates.

  3. On the purchase page, select the certificate brand, type (DV/OV/EV), domain type, and quantity. Keep them consistent with the original uploaded certificate (Recommended). Complete the purchase. For the purchase parameters, see Purchase a certificate.

  4. Verify that the renewal has taken effect: the system generates a new commercial certificate subscription instance.

What to do next

You must manually apply for and deploy the new certificate. Otherwise, HTTPS services are interrupted after the original certificate expires. For the procedure, see Apply for and deploy the new certificate after renewal.

Apply for and deploy the new certificate after renewal

Renewal (including auto-renewal) only extends the subscription validity period. It does not automatically apply for or deploy a new certificate, and it does not extend the validity period of the current certificate. If the current certificate is about to expire or has expired, apply for and deploy a new certificate. Otherwise, HTTPS services are interrupted.

  1. Apply for a new certificate. For detailed steps, see Apply for a certificate.

  2. Complete certificate verification and wait for the CA to issue the new certificate.

  3. After the new certificate is issued, download it and deploy it to your business systems to replace the old certificate. For deployment methods, see Deploy certificates.

  4. After deployment, visit your website in a browser and confirm that the certificate warning is gone. If the website still shows a certificate expired or insecure warning, see Why does the website still show a certificate expired or insecure warning after the renewal?.

FAQ

The certificate has expired. What should I do?

Expired certificates cannot be renewed. For a Commercial Certificates whose subscription is still valid, apply for the next certificate instead. See Step 3: Determine the resolution. Otherwise, purchase a new one:

  • If an Uploaded Certificates has expired, purchase a new one from the original channel, or purchase a Commercial Certificates on Alibaba Cloud.

Why is the certificate valid for only 6 months when I purchased a 2-year certificate?

This is expected. The validity period of a single certificate is constrained by the global certificate industry policy (CA/B Forum), and the maximum validity period of a single issuance is gradually being shortened to about 6 months. When the purchased duration exceeds the maximum certificate validity period, multiple certificates are issued in sequence to cover the purchased duration.

Why can't I find the renewal button?

First determine whether your certificate is managed in V1.0 or V2.0. For instructions, see Step 1: Locate the target certificate.

  • V1.0 does not support early renewal. The renewal entry opens only when the remaining validity period of the certificate is less than 15 days. When exactly 15 days remain, the "less than 15 days" condition is not met, so the renewal button is not displayed. Check again the next day.

  • In V2.0, certificates purchased before 2026-05-06 do not support renewal and must be repurchased.

The certificate is about to expire. Does the system automatically apply for the next certificate?

  • V1.0 certificates: When the subscription has not expired and the next certificate is in the Not Activated status, the system automatically submits the application.

  • V2.0 certificates: The system applies automatically only when the Managed Service is enabled. Otherwise, submit the application yourself before expiration.

What does the "Hosted, not activated" certificate status mean? Do I need to take action?

This is a normal status. It means the system has reserved the next certificate but has not started the issuance process. When the remaining validity period of the current certificate is less than 15 days, the system automatically submits the application. Pay attention to the success or failure notifications. If the application fails, handle it based on the notification.

How do I configure or disable certificate expiration reminders?

  • Configure reminders: The default reminder policy cannot be modified. To change settings such as the reminder frequency or reminder recipients, purchase custom message reminder quota on the Message Notifications page first.

  • Disable reminders: Turn off the reminder switch of the target certificate on the Message Notifications page.

What should I do when an Individual Test Certificate (Formerly Free Certificate) expires?

Individual test certificates have a Free Edition and a Pro Edition. Neither supports renewal. When one expires, purchase a new certificate and deploy it to replace the old one. The validity period of the new certificate is counted from its issuance date and does not include the remaining duration of the old certificate.

  • Free Edition: A single certificate is valid for about 3 months, and up to 20 certificates can be claimed per calendar year (subject to the remaining quota displayed in the console). When the quota is used up, purchase the Pro Edition or a Commercial Certificates instead.

  • Pro Edition (CNY 34 per certificate): A single certificate is valid for 6 months, there is no quota limit, and the Managed Service is not supported. For more information, see Purchase an individual test certificate.

Nothing changed in the console after I paid for the renewal, and I cannot find the new certificate. Why?

Renewal extends the subscription validity period (the service duration). It does not directly extend the validity period of the issued certificate. After the renewal, you must apply for and have a new certificate issued within the new subscription period to replace the current certificate. Therefore, after the payment, the old certificate still shows the About to Expire status, which is expected. Confirm and handle it as follows:

  • Check whether the account is correct: Make sure you are logged on with the account that purchased the certificate.

  • Confirm that the renewal has taken effect: Step 1: Locate the target certificate and check whether the Subscription Period of the certificate instance has been extended by the renewal duration. If you renewed a V1.0 certificate by paying separately because no quota remained, the new certificate is created under Commercial Certificates in V2.0, and subsequent operations must be completed on the V2.0 Commercial Certificates tab.

Why does the website still show a certificate expired or insecure warning after the renewal?

Renewal only extends the subscription duration. It does not replace the certificate on your server automatically. You must apply for and deploy the certificate again. For detailed steps, see Apply for a certificate and Deploy certificates. If the warning persists after redeployment, troubleshoot as follows:

  • Confirm that the correct certificate file is deployed: Make sure the newly issued certificate file, not the old one, is deployed on your server.

  • Confirm that the web service is restarted: On web servers such as NGINX, Apache, Tomcat, and IIS, you must restart or reload the service after replacing the certificate file for the new certificate to take effect.

  • Clear the browser cache: The browser may have cached the status of the old certificate. Force-refresh the page (Ctrl+F5), clear the browser cache, or visit the site in incognito or private mode.

  • Check intermediate services such as CDN and WAF: If your website uses services such as content delivery network (CDN), Web Application Firewall (WAF), Global Accelerator (GA), or load balancing (SLB), you must also update the certificate to the new one in the consoles of those services. Otherwise, visitors still receive the old certificate served by those intermediate services.

  • Confirm that the certificate chain is complete: Certificate files downloaded from Alibaba Cloud usually include the complete certificate chain. If you assemble it yourself, make sure it includes the server certificate and all intermediate certificates.

Why does the certificate list show multiple records, including two identical ones, after a V1.0 renewal?

This is expected. After a V1.0 certificate is renewed, the system generates a new certificate in the Pending Application status and adds a linked record under the original certificate. The linked record only shows the relationship between the old and new certificates. It is not a new certificate, and you are not billed twice.

What is the difference between renewal and direct purchase?

The difference is how the subscription validity period of the new certificate is calculated:

  • Commercial Certificates:

    • Certificate renewal: The new expiration date is counted from the original subscription expiration date. Example: If the original subscription expires on June 1, 2026, and you renew for 1 year on May 18, 2026, the new expiration date is June 1, 2027.

    • Direct purchase: The calculation is completely independent of the original certificate subscription instance. The subscription validity period is counted from the date on which the new certificate is first issued. If you purchase directly while the original subscription is still valid, the two validity periods overlap, and the overlapping part is not refunded or extended.

  • Uploaded Certificates: There is no difference between renewal and direct purchase. In both cases, the subscription validity period is counted from the date on which the new certificate is first issued.

  • Individual Test Certificate (Formerly Free Certificate): Renewal is not supported. You can only purchase a new one. The validity period of the new certificate is counted from its issuance date (3 months) and does not include the remaining duration of the old certificate.

I have multiple certificates. How do I know which ones need renewal?

Check the certificate list on the Commercial Certificate tab in both SSL Certificate Management V2.0 and V1.0, and pay attention to certificates whose status is expiring soon or expired.