Skip to main content

SSL guides and articles

Every CompleteStatus blog post tagged SSL — 15 articles, newest first.

Articles

ssl tls

Seven Months to 100-Day Certificates: A Prep Plan for March 2027

The 200-day certificate cap has been live since March. The 100-day step, and shorter domain validation reuse, land on 15 March 2027. A month-by-month plan.

7 min read
ssl tls

SSL Certificate Monitoring: Never Get Caught by an Expired Cert Again

Expired TLS certificates are a common self-inflicted outage. Why auto-renewal isn't enough, what to monitor, and how to get warned weeks before expiry.

5 min read
ssl tls

47-Day Certificates Are Coming: What SC-081 Means for Your Renewal Process

The CA/Browser Forum approved ballot SC-081, cutting TLS certificate lifetimes from 398 days to 47 by 2029. How to get your renewals ready.

6 min read
ssl tls

Let's Encrypt Is Ending Expiry Emails and OCSP: What to Replace Before June

Let's Encrypt will stop sending expiration emails and is winding down OCSP in 2025. What that removes from your safety net, and what to put in its place.

7 min read
ssl certificates

Chrome Stops Trusting New Entrust Certificates: Check Your Chain This Week

Entrust TLS certificates issued after October 31 are no longer trusted by Chrome. How to find Entrust certificates on your estate and switch CAs cleanly.

5 min read
ssl certificates

Google Wants 90-Day Certificates: Get Ready Before It Becomes a Rule

Chrome's root program plans to propose 90-day maximum TLS certificate lifetimes. No date yet, but manual renewals are on borrowed time. Here's how to prepare.

6 min read
ssl lets-encrypt

Let's Encrypt Renewal Failures — When 90-Day Automation Silently Stops

Let's Encrypt automation fails quietly: broken certbot upgrades, rate limits, blocked port 80, lost cron jobs. Independent expiry monitoring is the net.

6 min read
tls ssl

TLS 1.0 and 1.1 Are Being Shut Out — Time to Check What Your Server Negotiates

Chrome, Firefox and Edge now block TLS 1.0 and 1.1. How to test what your server negotiates, enable TLS 1.2/1.3 on nginx and Apache, and handle legacy clients.

6 min read
ssl tls

One-Year Certificates Are Coming — Apple Just Changed the Rules

From September 1, Safari will reject new TLS certificates valid longer than 398 days. What Apple's unilateral move means and how to get renewals ready.

6 min read
tls pci

PCI's June 30 Deadline: Turning Off TLS 1.0 Without Locking Out Customers

PCI DSS requires SSL and early TLS to be gone from payment environments by June 30. How to check what you negotiate, change it safely, and spot who it breaks.

6 min read
ssl tls

Certificate Lifetimes Just Got Cut to 825 Days, and the Trend Points Shorter

Newly issued TLS certificates are now capped at 825 days. Why the industry keeps cutting lifetimes, and why calendar reminders are no longer enough.

5 min read
ssl certificates

Chrome Is Distrusting Symantec Certificates: Your Replacement Timeline

Chrome plans to stop trusting certificates from Symantec's old CA infrastructure in two steps during 2018. How to tell if you're affected and when to act.

5 min read

More topics