SSL certificate renewal and expiration

更新时间:
复制 MD 格式

Renew SSL certificates in SSL Certificate Management V2.0 (subscription mode) or V1.0 (Discontinued) to extend protection before expiration. If a certificate has already expired, follow the expiration handling procedures to restore service.

Before you begin

Difference between renewal and re-issuance

  • Renewal: Extends the certificate subscription validity period. The subscription validity period is greater than or equal to the certificate issuance validity period.

  • Re-issuance: Applies to the certification authority (CA) for an extension of the certificate issuance validity period. The CA issues a new certificate, and you must replace the certificate deployed on your server with the newly issued one. Because the CA imposes a maximum single-issuance validity period (subject to CA policy), when the subscription validity period exceeds the single-issuance validity cap, you must apply for re-issuance before the certificate issuance validity expires.

Confirm your certificate version and type

SSL certificates have been upgraded to V2.0. New users use V2.0. Existing users can identify the certificate version based on the console page where the certificate appears:

  • SSL Certificate Management V2.0: Go to the SSL Certificate Management V2.0 page. View V2.0 certificates on the Commercial Certificates tab.

  • SSL Certificate Management (V1.0 Discontinued): Go to the SSL Certificate Management (V1.0 Discontinued) page. View V1.0 certificates on the Commercial Certificates tab. V1.0 is discontinued for new purchases, but existing certificates can still be renewed. If your account has no V1.0 certificates, the link redirects to the Digital Certificate Management Service homepage and the V1.0 menu is not displayed.

  • Uploaded certificates: Managed on the Uploaded tab of the V2.0 page. For the renewal procedure, see Renew an uploaded certificate.

If the subscription has expired and the renewal entry is no longer visible, see Certificate expiration handling.

Certificate issuance validity period

The issuance validity period of a new certificate equals the CA's maximum single-issuance validity (starting from the issuance date), but does not exceed the subscription expiration date.

Renewal process

The certificate renewal process is as follows:

  • Submit renewal information and complete payment: Fill in the required renewal information and complete the payment.

  • Apply for a new certificate: Submit a new certificate application to the CA, verify domain ownership, and cooperate with the CA to complete the review.

  • Deploy and verify the new certificate: Deploy the newly issued certificate to your server or cloud service to replace the old certificate.

Renew a commercial certificate

SSL certificate management V2.0

Prerequisites

Renewal of a V2.0 subscription certificate instance requires all of the following conditions to be met:

  • The certificate instance status is Issued or About to Expire.

  • The GlobalSign brand does not currently support renewal.

  • The certificate is on the Commercial Certificates tab.

  • Certificates purchased before 2026-05-06 do not currently support renewal.

Procedure

  1. Log on to the SSL Certificate Management V2.0 console.

  2. On the Commercial Certificates tab, find the target certificate instance.

  3. In the Actions column, click Renew.

  4. The renewal page appears. Follow the on-screen instructions to complete the renewal.

    After you complete the renewal, proceed to Post-renewal operations to submit a certificate application to the CA and deploy the new certificate.

SSL certificate management (V1.0 discontinued)

Prerequisites

All of the following conditions must be met for the renewal entry to appear:

  • The certificate status is Issued or About to Expire.

  • The certificate expires within 15 days.

Procedure

  1. Go to the SSL Certificate Management (V1.0 Discontinued) page.

  2. On the Commercial Certificates tab, find the target certificate. In the Actions column, click Renewal purchase.

  3. In the Certificate renewal panel, configure the following parameters.

    • CSR Generation:

      A CSR (Certificate Signing Request) is the file submitted to the CA for a certificate application. It contains the domain name, public key, and subject information bound to the certificate, signed by the private key. Select Automatic (recommended).

      • Automatic: Generates and securely hosts a new key pair (same key algorithm as the old certificate) and creates a new CSR.

        Note

        This method follows key rotation security best practices.

      • Manual: Paste a CSR file generated in your own environment into the CSR File field. Certificates issued with this option cannot be deployed to Alibaba Cloud services through the console. For how to create a CSR and private key file, see Create a CSR file.

        Important
        • Make sure the encryption algorithm of the manually entered CSR matches the Encryption Algorithm of the old certificate. A mismatch prevents submission.

          Use the View CSR tool to verify the CSR's encryption algorithm. For more information, see Certificate Tools.

        • Store your private key file securely. Alibaba Cloud does not store it. If the private key is lost, you must purchase a new SSL certificate.

        • If you request a certificate with a Chinese cryptographic algorithm and manually enter the CSR, the private key is not stored on Alibaba Cloud. The encrypted certificate requires the private key for decryption. Contact the party that generated the private key for decryption assistance.

      • Original Key Inherited: Reuses the old certificate's key pair to generate a new CSR and issue a new certificate.

        Note

        This method does not follow key rotation best practices and may not meet compliance requirements in some industries.

    • Domain Verification Method:

      Defaults to the same validation method used for the old certificate.

    • Contact:

      Depending on the domain validation method, the CA may email a certificate validation message to this contact or reach out by phone (the Chinese mainland only). Make sure the contact information is accurate and up to date.

    • Renewal Period:

      The renewal period represents only the purchased service duration, not the actual validity period of a single issued certificate. Multiple certificates may be needed to cover the purchased service duration. The single-certificate issuance validity period is subject to the certificate brand's policies. For more information, see Notice on validity period changes of SSL certificates.

  4. Click Renewal immediately and follow the on-screen instructions to complete the payment.

    • Payment rule: The system offsets the cost with your remaining certificate quota (matching this request's specifications) and remaining Managed Service uses. You pay only the shortfall.

    • View remaining certificate quota and Managed Service uses: On the Commercial Certificates tab, click Create Certificate:

      • Remaining Managed Service uses: Find the Validity Period (Years) field. The number displayed after "Available Quota for Hosting Service:" is your current remaining quota.

      • Remaining certificate quota: After you select a Certificate Type, click the Certificate Specifications drop-down list. The "Number of available certificates" indicates the remaining quota for each specification.

  5. After renewal, one or more new certificates appear below the old one. The count depends on the single-certificate issuance validity period. For more information, see Notice on validity period changes of SSL certificates.

    • New certificates are linked to the old one, indicated by an new icon on the left.

    • The old certificate's validity remains unchanged.

    • The first new certificate has a status of Pending Application.

    • The remaining certificates have a status of Not Activated.

Note

The Managed Service automatically submits the certificate application if the following conditions are met. Otherwise, submit it manually.

  • For DV certificates, the Alibaba Cloud account that uses Alibaba Cloud DNS for the domain name must be the same account that purchased the certificate, or the domain name must have validation-free authorization configured.

  • The certificate application information and materials are valid, as verified by the CA.

Renew an individual test certificate

SSL certificate management V2.0

SSL Certificate Management V2.0 no longer supports Individual Test Certificate (Formerly Free Certificate) renewal. Purchase a new certificate if needed.

SSL certificate management (V1.0 discontinued)

Prerequisites

The renewal entry for Individual Test Certificates in SSL Certificate Management (V1.0 Discontinued) opens within 15 days before expiration. Certificates that expire in more than 15 days do not have a renewal entry.

Renewal is equivalent to purchasing a new certificate in SSL Certificate Management V2.0. The new certificate's validity starts from issuance and does not carry over the old certificate's remaining validity. You can proceed directly following Purchase an Individual Test Certificate.

Procedure

  1. Go to the SSL Certificate Management (V1.0 Discontinued) page.

  2. On the Individual Test Certificate (Formerly Free Certificate) tab, find the target certificate.

  3. In the Actions column, click More. On the certificate details page, go to the Renew tab, and click Buy Now to go to the purchase page.

  4. For the remaining steps, see Purchase an Individual Test Certificate.

Renew an uploaded certificate

Uploaded certificates are managed in SSL Certificate Management V2.0. Renewal is equivalent to purchasing a commercial certificate. The new certificate's validity starts from issuance and does not carry over the old certificate's remaining validity.

Prerequisites

  • The Update button appears in the Actions column only when the Status is Pending Expiration and the certificate is not a PCA certificate.

  • If the Status shows PCA (an SSL certificate created by the PCA service), you must issue a new PCA certificate and then sync it to SSL Certificate Management.

Procedure

  1. Go to the SSL Certificate Management V2.0 page.

  2. On the Uploaded tab, find the target certificate.

  3. In the Actions column, click Update to go to the purchase page.

  4. Follow the same process as purchasing a commercial certificate. For more information, see Purchase a commercial certificate.

Post-renewal operations

Submit a certificate application

After the renewal is complete, submit a request to the certification authority (CA) and complete domain ownership validation.

Deploy and verify the new certificate

  • Deploy the certificate

    Deploy the new certificate to your web server or cloud service to replace the old certificate. For more information, see Select a deployment solution for an SSL certificate.

  • Verify the certificate

    In a browser (Chrome for example), go to https://<your domain name>.

    Click the image icon, and then click Connection is secure > Certificate is valid.

    In the certificate details, check General > Expires On. If the date matches the expiration date of the new certificate, the deployment was successful.

Certificate expiration handling

A certificate can expire in two ways:

FAQ

Renewal basics

What is the difference between renewal and direct purchase?

  • Commercial Certificates: The subscription time calculation method differs.

    • Certificate renewal: The new expiration date is calculated from the current subscription expiration date. For example, if the original subscription expires on June 1, 2026, and you renew for 1 year on May 16, 2026, the new subscription expires on June 1, 2027.

    • Direct purchase: Creates a new subscription instance, completely independent from the original certificate subscription instance.

  • Individual Test Certificate (Free), Individual Test Certificate (Pro), Uploaded: No difference between renewal and direct purchase. The validity period starts from the first issuance date of the new certificate in both cases.

Why is the certificate validity period short after purchasing a 2-year or 3-year certificate?

The certificate validity period consists of the subscription validity period and the issuance validity period. The subscription validity period matches the purchased duration. The issuance validity period is specified by the CA when issuing the certificate and changes according to industry policy. Therefore, the purchased duration usually does not equal the issuance validity period. If the certificate issuance validity expires within the subscription period, apply for a new certificate in the Digital Certificate Management Service console.

How do I apply for re-issuance when the certificate issuance validity is about to expire?

The certificate application entry opens 15 days before the issuance validity expires. Apply from the Operations column in the certificate list.

Renewal process issues

Why can't I find the renewal entry in the certificate list?

  • SSL Certificate Management (V1.0 Discontinued): The renewal entry opens within 15 days before expiration. Certificates that expire in more than 15 days do not display the Renew button.

  • SSL Certificate Management V2.0: The Renew button is visible when the certificate status is Issued or About to Expire. If you still cannot see the Renew button, confirm the following:

    • You are on the Commercial Certificates tab (certificates on the Individual Test Certificate (Formerly Free Certificate) tab do not support renewal).

    • The GlobalSign brand does not currently support renewal.

    • Certificates purchased before 2026-05-06 do not currently support renewal.

Why do duplicate certificate records appear after renewal?

In SSL Certificate Management (V1.0 Discontinued), based on the service duration you selected during renewal, one or more new certificates appear below the old one (with an new icon on the left), indicating they are linked to the old certificate.

Post-renewal deployment issues

Why does the website still show a "certificate expiring soon" warning after renewal and payment?

After paying for the renewal, you must complete the application process to have a new certificate issued. Then deploy the new certificate to your web server or cloud service to replace the old one.

To apply for a new certificate, see Submit a request to the certification authority (CA).

To deploy the new certificate, see Select a deployment solution for an SSL certificate.

Why does the website still show an "insecure" or "certificate expired" warning after deploying the renewed certificate?

Troubleshoot with the following steps:

  • Verify the deployed certificate file: Make sure the newly issued certificate file, not the old one, is deployed on your server.

  • Restart the web service: After replacing the certificate file on Nginx, Apache, Tomcat, IIS, or similar web servers, you must restart or reload the service for the new certificate to take effect.

  • Clear your browser cache: Your browser may have cached the old certificate. Try force-refreshing the page (Ctrl+F5), clearing the browser cache, or visiting the site in incognito or private mode.

  • Check CDN or WAF and other intermediate services: If you use content delivery network (CDN), Web Application Firewall (WAF), Global Accelerator (GA), or Server Load Balancer (SLB), you must also update the certificate in the console for each of these services. Otherwise, users still receive the old, expired certificate served by these intermediate services.

  • Verify the certificate chain is complete: Certificate files downloaded from Alibaba Cloud typically include the complete certificate chain. If you assemble it manually, make sure you include the server certificate and all intermediate certificates.

Emergency procedure for expired certificates

The certificate has expired and service is affected. How do I recover quickly?

If an expired certificate disrupts service, follow this emergency procedure to restore service quickly. Replace the temporary certificate with your intended commercial certificate later.

  • Purchase Certificate: Purchase a domain validated (DV) certificate immediately as a temporary fix. DV certificates have a simple validation process and are issued quickly.

  • Certificate Application: Choose DNS validation to verify domain ownership quickly, often within 10 minutes.

While waiting for issuance, locate the old certificate on your server so you are ready for replacement.

  • Deploy the certificate: After the new certificate is issued, immediately deploy it to your web server (such as Nginx or Apache) or cloud service.

  • Replace with a commercial certificate: The DV certificate is temporary. After service is restored, apply for a certificate with your original specifications (such as organization validated or extended validation) and replace the DV certificate as soon as possible.

To prevent recurrence, enable SSL certificate message notifications and renew certificates before they expire. You can also enable the Managed Service. The Managed Service automatically submits a certificate application when the certificate issuance validity is about to expire.