{"id":7247,"date":"2019-06-04T13:00:51","date_gmt":"2019-06-04T17:00:51","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=7247"},"modified":"2025-04-15T11:36:09","modified_gmt":"2025-04-15T15:36:09","slug":"what-happens-when-your-ssl-certificate-expires","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/","title":{"rendered":"This is what happens when your SSL certificate expires"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-what-happens-when-your-ssl-certificate-expires-this\">What happens when your SSL certificate expires? This.<\/h2>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>Editor&#8217;s Note:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/47-day-ssl-certificate-validity-by-2029\/\">Industry to Shift to 47-Day SSL\/TLS Certificate Validity by 2029<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most common questions we get asked is some variation on \u201cwhat happens when your SSL certificate expires?\u201d or \u201cwhat happens if you don\u2019t renew your SSL certificates on time?\u201d<span id=\"newline\"><\/span><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"269\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/jeeves-269x300.jpg\" alt=\"what happens when your SSL certificate expires\" class=\"wp-image-7248\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/jeeves-269x300.jpg 269w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/jeeves.jpg 290w\" sizes=\"auto, (max-width: 269px) 100vw, 269px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The answer is death. <strong>Swift ignominious death<\/strong>. Ever wonder what happened to Jeeves? Now you know. On the death certificate his cause of death just reads: \u201ccertificate expiry.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That was a dark day for the internet\u2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ok, so maybe that\u2019s a little bit hyperbolic (and patently untrue &#8211; everyone knows it was Google&#8217;s wetwork). But certificate expiration can have some serious consequences. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, today we\u2019re going to talk about what happens when your SSL certificate expires, we\u2019ll toss out some infamous examples of certificate expiration and we\u2019ll even go into how to avoid accidentally letting your SSL certificates expire in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-happens-when-your-ssl-certificate-expires\">What Happens When Your SSL Certificate Expires?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start by answering the question we posed at the outset and then we\u2019ll delve into some of the minutiae. SSL certificates facilitate the encryption of data in transit. By installing an SSL certificate on your website\u2019s server, it allows you to host it over HTTPS and create secure, encrypted connections between your site and its visitors. This safeguards communication. SSL also authenticates the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SSL certificates are not valid forever though. They expire. There is an industry forum, the Certificate Authority\/Browser Forum, that serves as a de facto regulatory body for the SSL\/TLS industry. The CAB Forum legislates the <a rel=\"nofollow noopener noreferrer\" href=\"https:\/\/cabforum.org\/wp-content\/uploads\/CA-Browser-Forum-BR-1.6.0.pdf\" target=\"_blank\">baseline requirements<\/a> that Certificate Authorities must follow to issue trusted SSL certificates. Those requirements dictate that SSL certificates may have a lifespan of <a href=\"https:\/\/www.thesslstore.com\/blog\/cab-forum-ballot-193\/\">no longer than 27 months<\/a> (two years + you can carry over up to three months when you renew with time remaining on your previous certificate).<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\">That means that every website needs to renew or replace its SSL certificate at least once every two years. So, what happens when your SSL certificate expires? It makes your sight nigh unreachable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a user\u2019s browser arrives at your website it checks for the validity of the SSL certificate within milliseconds (<a href=\"https:\/\/www.thesslstore.com\/blog\/explaining-ssl-handshake\/\">it\u2019s part of the SSL handshake<\/a>). If the certificate is expired, it issues a warning like this:<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"682\" data-id=\"10904\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Chrome-SSL-Expired-Warning.png\" alt=\"\" class=\"wp-image-10904\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Chrome-SSL-Expired-Warning.png 885w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Chrome-SSL-Expired-Warning-300x231.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Chrome-SSL-Expired-Warning-768x592.png 768w\" sizes=\"auto, (max-width: 885px) 100vw, 885px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"680\" data-id=\"10905\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/IE-SSL-Expired-Warning.png\" alt=\"\" class=\"wp-image-10905\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/IE-SSL-Expired-Warning.png 885w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/IE-SSL-Expired-Warning-300x231.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/IE-SSL-Expired-Warning-768x590.png 768w\" sizes=\"auto, (max-width: 885px) 100vw, 885px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"682\" data-id=\"10907\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Firefox-SSL-Expired-Warning.png\" alt=\"\" class=\"wp-image-10907\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Firefox-SSL-Expired-Warning.png 885w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Firefox-SSL-Expired-Warning-300x231.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Firefox-SSL-Expired-Warning-768x592.png 768w\" sizes=\"auto, (max-width: 885px) 100vw, 885px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"885\" height=\"682\" data-id=\"10908\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Opera-SSL-Expired-Warning.png\" alt=\"\" class=\"wp-image-10908\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Opera-SSL-Expired-Warning.png 885w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Opera-SSL-Expired-Warning-300x231.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Opera-SSL-Expired-Warning-768x592.png 768w\" sizes=\"auto, (max-width: 885px) 100vw, 885px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"773\" data-id=\"10909\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Safari-SSL-Expired-Warning-1-1024x773.png\" alt=\"\" class=\"wp-image-10909\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Safari-SSL-Expired-Warning-1-1024x773.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Safari-SSL-Expired-Warning-1-300x226.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Safari-SSL-Expired-Warning-1-768x580.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Safari-SSL-Expired-Warning-1.png 2030w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"886\" height=\"681\" data-id=\"10910\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Edge-SSL-Expired-Warning-1.png\" alt=\"\" class=\"wp-image-10910\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Edge-SSL-Expired-Warning-1.png 886w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Edge-SSL-Expired-Warning-1-300x231.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Edge-SSL-Expired-Warning-1-768x590.png 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You don\u2019t need me to tell you that this message is essentially a death warrant for your site\u2019s traffic, sales&#8211; whatever metric or KPI you value. While most browsers do offer an option to click through the warning, almost nobody does it. The average internet user <a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/report-70-us-employees-lack-strong-knowledge-privacy-security-best-practices\/\" target=\"_blank\">may not know a ton about cybersecurity<\/a>, but they know two things: computers are expensive and malware messes up computers. So, if their browser tells them a website isn\u2019t safe, or in this case that their connection isn\u2019t secure, they are probably going to listen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wouldn\u2019t you?<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-text-align-center\" id=\"h-certificate-expiration-by-the-numbers\">Certificate Expiration by the Numbers<\/h3>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"288\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-1024x288.png\" alt=\"Certificate expiration can be fatal, costing organizations millions of dollars every year\" class=\"wp-image-10106\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-1024x288.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-300x84.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry-768x216.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2014\/02\/Certificate-Expiry.png 1564w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-do-ssl-certificates-expire\">Why Do SSL Certificates Expire?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/ssl-certificates-expire\/\" target=\"_blank\">This is a topic we\u2019ve discussed quite a bit in the past<\/a>, but here\u2019s a quick rundown. As we mentioned earlier, SSL certificates help facilitate two things: encryption and authentication. The latter is the bigger culprit for certificate expiry. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All SSL certificates authenticate something, even domain validation certificates authenticate a server. As with any form of authentication, you occasionally need to re-validate the information you\u2019re using in order to make sure it\u2019s accurate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s especially true on the internet. Things change all the time. Websites change hands. Companies are bought and sold. And SSL\/TLS is based on a trust model that can be undermined by that. So it\u2019s important for Certificate Authorities that are issuing trusted certificates to ensure that the information they\u2019re using to authenticate servers and organizations is as up-to-date and accurate as possible.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Certificate-Expiration-Icon-1-300x300.png\" alt=\"\" class=\"wp-image-10915\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Certificate-Expiration-Icon-1-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Certificate-Expiration-Icon-1.png 402w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s look at a practical example. Circuit City was an electronics and appliance retailer that went out of business about a decade ago. Now, imagine for a moment that SSL certificates didn\u2019t expire. Circuit City\u2019s assets have all been sold off or jettisoned, what if someone grabs the certificate and the domain it was issued for. Now they\u2019re free to do whatever they want with that domain (until the certificate is revoked, but that\u2019s a completely separate mess) and everyone\u2019s browser would see this site as the legitimate article. Someone that didn\u2019t realize the company was now defunct could easily be duped. After all, the certificate is legitimate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That can\u2019t happen. If anything, expect certificate lifespans to get shorter. And believe it or not &#8211; we often hear critics claim certificate expiry is a racket for the Certificate Authorities &#8211; CAs aren&#8217;t the one driving shorter validity. The browsers are.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At one point, SSL certificates could be issued for as long as five years. Then it was knocked down to three. <a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/cab-forum-ballot-193\/\" target=\"_blank\">Then last year it was down to two<\/a>\u2014which was a compromise because the original Google proposal was for one year. In the future certificate validity may be as short as 3-6 months. Let\u2019s Encrypt issues 3 month certificates right now.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Related<\/strong>: <em>Secure Your Domain &amp; Sub-Domains with a <a href=\"https:\/\/www.thesslstore.com\/rapidssl\/rapidssl-wildcard.aspx\" target=\"_blank\" rel=\"noreferrer noopener\">RapidSSL Wildcard Certificate<\/a>.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication isn\u2019t the only culprit for certificate expiry though. Having shorter certificate validity periods also makes it easier for the industry to roll out changes more quickly. For instance, a few years ago the SSL\/TLS industry <a href=\"https:\/\/www.thesslstore.com\/blog\/final-countdown-end-sha-1\/\" target=\"_blank\" rel=\"noopener noreferrer\">deprecated the use of SHA-1<\/a> as a hashing algorithm. As anyone that has ever ordered an SSL certificate knows, you pick the hashing algorithm during generation. With three year validity, in some cases you may have to wait as long as 39 months after the deadline before the certificate expires and SHA-1 is deprecated by that website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Short validity periods fix this. If we were to phase out <a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/difference-sha-1-sha-2-sha-256-hash-algorithms\/\" target=\"_blank\">SHA-2 in favor of SHA-3<\/a> (don\u2019t worry, that\u2019s not coming anytime soon) you could set a cutoff date for issuing SHA-2 certificates and within 27 (or 15 if it\u2019s reduced to one year) months, SHA-2 would be completely deprecated.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"380\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Stamp-1024x380.png\" alt=\"expired ssl certificates\" class=\"wp-image-10911\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Stamp-1024x380.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Stamp-300x111.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Stamp-768x285.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Stamp.png 1490w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-high-profile-ssl-certificate-expirations\">High Profile SSL Certificate Expirations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you do accidentally forget to renew on time and let your SSL certificate expire, you can take some solace in knowing that you are not alone. Below, we\u2019re going to keep a running list of high-profile SSL expirations:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-linkedin-let-s-one-of-its-ssl-tls-certificates-expire-again\"><a href=\"https:\/\/www.thesslstore.com\/blog\/linkedin-suffers-ssl-tls-certificate-expiration-again\/\"><strong>LinkedIn let&#8217;s one of its SSL\/TLS certificates expire&#8230; again!<\/strong><\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For the second time in two years LinkedIn suffered outages in the US and UK following the expiration of one of its SSL certificates. This time the expiration affected a link shortener, lnkd.in, which rendered the site unreachable to anyone that clicked one of the shortened links (they&#8217;re typically found on social media). Link shorteners basically act like proxies, the shortened link connects with the link shortening server, gets inspected, and then gets passed along to the intended destination. And here&#8217;s the thing, this didn&#8217;t just affect LinkedIn, anyone sharing content through the site has their link shortened. Here&#8217;s an example of one of our posts with its URL shortened.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"546\" height=\"292\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/shortened-url.png\" alt=\"\" class=\"wp-image-10914\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/shortened-url.png 546w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/shortened-url-300x160.png 300w\" sizes=\"auto, (max-width: 546px) 100vw, 546px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This is a perfect example of how an expired certificate doesn&#8217;t just harm your organization, it can also harm your customers and partners, too.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-us-government-shutdown-causes-dozens-of-ssl-certificate-expirations\"><a href=\"https:\/\/www.thesslstore.com\/blog\/more-websites-breaking-as-certificates-expire-during-government-shutdown\/\"><strong>US Government shutdown causes dozens of SSL certificate expirations<\/strong><\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To round out 2018 and kick-start 2019, the two political parties that govern the United States decided to play a game of shutdown chicken that ended up causing the expiration of over 130 government SSL certificates, rendering dozens of sites completely unreachable. As part of a Department of Homeland Security directive from 2015, all government websites are supposed to be on the <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-hypertext-strict-transport-security-hsts\/\">HSTS preload list<\/a>. HSTS is a security header that forces browsers to make secure connections. It&#8217;s a great idea, the only downside is if anything ever happens to your SSL\/TLS certificate, your website breaks. And by breaks I mean it becomes completely unreachable. That&#8217;s a problem when it happens to government organizations like the Department of Justice, the US Court of Appeals or NASA.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-ericsson-lets-certificate-expire-32-million-people-lose-cellular-service\"><a href=\"https:\/\/www.thesslstore.com\/blog\/expired-certificate-ericsson-o2\/\"><strong>Ericsson lets certificate expire, 32 million people lose cellular service<\/strong><\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In December of 2018, millions of people in the UK were without cellular coverage following the expiration of a digital certificate associated with Ericsson\u2019s network. Ericsson, which is a Swedish cellular company, manufactures myriad back-end equipment for the world\u2019s cellular networks. Thanks to an expired digital certificate in a version of Ericsson\u2019s management software that is widely used by European telecommunications companies millions of cellular users experienced downtime.The outages initially affected software used by O2 and its parent company, Telefonica, but eventually the outages showed up downstream, too.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-equifax-misses-a-breach-for-76-days-because-of-an-expired-certificate\"><a href=\"https:\/\/www.thesslstore.com\/blog\/the-equifax-data-breach-went-undetected-for-76-days-because-of-an-expired-certificate\/\"><strong>Equifax misses a breach for 76 days because of an expired certificate<\/strong><\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Equifax would have discovered the 2017 attack that compromised millions of peoples&#8217; personal information a lot sooner if not for an expired digital certificate. For ten months, following the expiration of the certificate, Equifax couldn&#8217;t inspect the traffic running through its own network. That, in turn, caused it to miss the high-profile breach for 76 days, until the certificate was finally replaced and inspection resumed.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cisco-lets-one-of-its-ssl-certificates-expire\"><strong><a href=\"https:\/\/www.thesslstore.com\/blog\/expired-ssl-certificate-in-cisco-vpn-kit-breaks-network-provisioning\/\" target=\"_blank\" rel=\"noopener noreferrer\">Cisco lets one of its SSL certificates expire<\/a><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the first half of 2018, Cisco had an issue that superseded regular SSL certificate expiration\u2014Cisco had a root expire. As we discussed a few days ago, <a href=\"https:\/\/www.thesslstore.com\/blog\/root-certificates-intermediate\/\" target=\"_blank\" rel=\"noopener noreferrer\">Roots certificates are an integral part of the SSL\/TLS trust model<\/a>. Seated at the top of the proverbial tree, Root certificates are used to sign and issue intermediates and end user SSL certificates. In this case, the root was attached to one of Cisco\u2019s VPNs, meaning every certificate it issued to end users could have potentially become invalid, too. Fortunately, that doesn\u2019t appear to have happened, users were just blocked from generating new end points.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Poke-Ball-300x300.jpg\" alt=\"Pokeball\" class=\"wp-image-10913\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Poke-Ball-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Poke-Ball-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Poke-Ball-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Poke-Ball.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The issue was resolved in APEC-EM Release 1.6.3.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pokemon-go-lets-its-ssl-certificate-expire\"><strong><a href=\"https:\/\/www.thesslstore.com\/blog\/expired-ssl-certificate-knocks-pokemon-go-offline\/\" target=\"_blank\" rel=\"noopener noreferrer\">Pokemon Go lets its SSL certificate expire<\/a><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Niantic seems to be having a bit of a resurgence with Pokemon Go, but back in January of 2018 the game was running into game-breaking bugs and a litany of other problems\u2014one of which was the expiration of one its SSL certificates. The outage was short, lasting just about half an hour, but it was more egg on Niantic\u2019s face at the time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fortunately, things seem to be going a lot better for the company lately.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-uk-conservative-party-lets-its-ssl-certificate-expire\"><strong><a href=\"https:\/\/www.thesslstore.com\/blog\/conservative-party-website-security-certificate-expire\/\" target=\"_blank\" rel=\"noopener noreferrer\">The UK Conservative Party lets its SSL Certificate Expire<\/a><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Tories, as they\u2019re known in the UK, don\u2019t have a great reputation when it comes to encryption, in general. <a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/brace-yourself-the-encryption-debate-is-coming-back\/\" target=\"_blank\">Former home secretary Amber Rudd<\/a> and soon to be ex-<a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/brace-yourself-the-encryption-debate-is-coming-back\/\" target=\"_blank\">Prime Minister Theresa May<\/a> have both publicly criticized encryption despite clearly not understanding very much about it. So it was ironic, then, on January 8, 2018 when the Tories\u2019 website went down following the expiration of its SSL certificate. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Or maybe you could say it Brexpired.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-linkedin-lets-its-ssl-certificate-expire\"><strong><a rel=\"noopener noreferrer\" href=\"https:\/\/www.thesslstore.com\/blog\/linkedin-ssl-certificate-expired\/\" target=\"_blank\">LinkedIn lets its SSL Certificate Expire<\/a><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">At the beginning of December 2017, LinkedIn allowed one of its SSL certificates to expire. It knocked out LinkedIn sites in the US, UK and Canada. As the VP of Venafi, Kevin Bocek said at the time:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&nbsp;&#8220;LinkedIn&#8217;s blunder demonstrates why keeping in control of certificates is so important. While LinkedIn will have thousands of certificates to keep track of, outages like yesterday&#8217;s show that it only takes one expiry to cause problems. To stay in control, organizations should look to automate the discovery, management and replacement of every single certificate on its network.&#8221;<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">LinkedIn quickly fixed the problem with a DigiCert Organization Validated SSL certificate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-time-warner-lets-its-mail-server-s-ssl-certificate-expire\"><strong><a href=\"https:\/\/www.thesslstore.com\/blog\/time-warner-ssl-expires\/\">Time Warner lets its Mail Server&#8217;s SSL certificate expire<\/a><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In early 2017 Time Warner compounded the boneheaded oversight that let its email server&#8217;s SSL certificate expire by offering its customers some equally boneheaded advice on remedying the situation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201c&#8230;going into your email settings and disabling SSL will stop the pop-up message and re-enable the webmail fetch.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This is terrible on so many levels. Let&#8217;s start with the fact that this is awful advice. Don&#8217;t ever disable SSL. Ever. Second, it&#8217;s incumbent upon the company that lets its SSL certificate expire to replace it in short order. It&#8217;s not the customers&#8217; job to change their settings to compensate for that company&#8217;s negligence. Third, who the hell is still using Time Warner as an email service?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-avoid-letting-your-ssl-certificate-expire\">How to Avoid Letting Your SSL Certificate Expire<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Enterprise businesses have a different set of problems when it comes to certificate management. Whereas Small and Medium Sized Businesses (SMBs) may just have one, or a handful of certificates, Enterprise companies have sprawling networks, myriad connected devices and just a lot more surface to cover in general. At the enterprise level, allowing an SSL certificate to expire is usually the result of oversight, not incompetence.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Cert-300x300.png\" alt=\"\" class=\"wp-image-10912\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Cert-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/12\/Expired-Cert.png 446w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The best way to avoid this issue, at any level &#8211; from enterprise to the smallest mom-and-pops operation &#8211; is automation. That may sound a bit abstract, but automation has never been easier now that the ACME protocol has been published as a standard by the IETF. We covered this a few days ago, proper configuration of the ACME protocol lets you set it and forget it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ACME protocol works by installing a client on your server that will act as an agent for the website(s) hosted on it. Following a process where the agent proves it&#8217;s authorized to act on behalf of the designated websites, it can be configured to contact the Certificate Authority of your choice at regular intervals to replace and renew SSL certificates. Originally, only Let&#8217;s Encrypt supported this. But each day more and more CAs are adding their own support, with major players like Sectigo and DigiCert leading the way. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ACME isn&#8217;t the only choice for automation, other certificate management platforms like Venafi&#8217;s can also be set up to automate all stages of the certificate lifecycle, including those oh-so-important renewals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We&#8217;ve got over a decade&#8217;s worth of experience helping organizations of all sizes tackle these challenges. Here&#8217;s some more actionable advice on avoiding certificate expiry in the event you&#8217;re not automating:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Whatever CA or SSL service you got your SSL certificates from will send you expiration notifications at set intervals starting at 90 days out. Make sure that you set these reminders to be sent to a distribution list and not just a single individual. The Point-of-Contact you used when getting the certificate issued may not be there by the time it expires. Maybe they moved on, got promoted or just drank a little too much at the office Christmas party and got canned\u2014whatever the case you need to make sure the notifications are reaching the right people.<\/li>\n\n\n\n<li>Identify the proper channels to escalate reminders as the expiry date approaches. For instance, at 90 days out you might just want to have the notification sent to your distribution list. At 60 days send it to your distro list, and to your system admin. At 30 days you send it to both the list and the system admin, and now your IT Manager gets looped in, too. Keep escalating all the way to the CIO or CISO if needed.<\/li>\n\n\n\n<li>Find a good certificate management platform. One of the biggest challenges facing enterprise businesses is visibility. You can\u2019t replace expiring certificates if you can\u2019t see them. We try to stay vendor agnostic, but <a href=\"https:\/\/www.thesslstore.com\/enterprise\/ssl-certificate-management.aspx\">DigiCert, Sectigo and Venafi<\/a> all have tremendous platforms that can help enterprises see and manage digital certificates across their entire infrastructure. Also, make sure you log in regularly so you can stay apprised of when you have renewals coming up.<\/li>\n\n\n\n<li>Decide on what CA(s) you want to work with and then set up <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-caa-record-certificate-authority-authorization\/\">CAA records<\/a> to restrict who can issue for your domains. This will help to eliminate the possibility of new rogue certificates being issued. The more you can consolidate your PKI into a single platform, the better off you\u2019ll be.<\/li>\n\n\n\n<li>Speaking of <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-rogue-certificate\/\">rogue certificates<\/a>, find a good scanning tool and then use it regularly to find and track rogue certificates by checking the various <a href=\"https:\/\/www.thesslstore.com\/blog\/certificate-transparency-april-30-2018\/\">CT logs<\/a>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-so-that-s-what-happens-when-your-ssl-certificate-expires\">So, that\u2019s what happens when your SSL certificate expires<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Forgetting to renew or replace an expiring SSL certificate can happen to anyone. But there are a lot of tools available to help minimize the risk that poses. The key, as we\u2019ve discussed, is either automation, or at least having visibility and good lines of communication so you can get out ahead of upcoming expirations. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check out our 3 steps for <a href=\"https:\/\/www.thesslstore.com\/blog\/your-security-certificate-has-expired-how-to-fix-it\/\">how to fix your security certificate once it has expired<\/a> to learn more. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, this problem isn&#8217;t going anywhere &#8211; even with the rise of automation &#8211; the sheer volume of digital certificates being issued to new websites, IoT devices and end points means somewhere, someplace, there&#8217;s always going to be one expiring. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any comments or questions below&#8230;<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>What happens when your SSL certificate expires? This. Editor&#8217;s Note: Industry to Shift to 47-Day SSL\/TLS Certificate Validity by 2029 One of the most common questions we get asked is&#8230;<\/p>\n","protected":false},"author":6,"featured_media":10918,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[8407],"class_list":["post-7247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-ssl-certificate-expiration","post-with-tags"],"views":383807,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Expiration-Feature.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=7247"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7247\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/10918"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=7247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=7247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=7247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}