Articles
Seven Months to 100-Day Certificates: A Prep Plan for March 2027
The 200-day certificate cap has been live since March. The 100-day step, and shorter domain validation reuse, land on 15 March 2027. A month-by-month plan.
SSL Certificate Monitoring: Never Get Caught by an Expired Cert Again
Expired TLS certificates are a common self-inflicted outage. Why auto-renewal isn't enough, what to monitor, and how to get warned weeks before expiry.
47-Day Certificates Are Coming: What SC-081 Means for Your Renewal Process
The CA/Browser Forum approved ballot SC-081, cutting TLS certificate lifetimes from 398 days to 47 by 2029. How to get your renewals ready.
Let's Encrypt Is Ending Expiry Emails and OCSP: What to Replace Before June
Let's Encrypt will stop sending expiration emails and is winding down OCSP in 2025. What that removes from your safety net, and what to put in its place.
Chrome Stops Trusting New Entrust Certificates: Check Your Chain This Week
Entrust TLS certificates issued after October 31 are no longer trusted by Chrome. How to find Entrust certificates on your estate and switch CAs cleanly.
Google Wants 90-Day Certificates: Get Ready Before It Becomes a Rule
Chrome's root program plans to propose 90-day maximum TLS certificate lifetimes. No date yet, but manual renewals are on borrowed time. Here's how to prepare.
Let's Encrypt Renewal Failures — When 90-Day Automation Silently Stops
Let's Encrypt automation fails quietly: broken certbot upgrades, rate limits, blocked port 80, lost cron jobs. Independent expiry monitoring is the net.
TLS 1.0 and 1.1 Are Being Shut Out — Time to Check What Your Server Negotiates
Chrome, Firefox and Edge now block TLS 1.0 and 1.1. How to test what your server negotiates, enable TLS 1.2/1.3 on nginx and Apache, and handle legacy clients.
One-Year Certificates Are Coming — Apple Just Changed the Rules
From September 1, Safari will reject new TLS certificates valid longer than 398 days. What Apple's unilateral move means and how to get renewals ready.
PCI's June 30 Deadline: Turning Off TLS 1.0 Without Locking Out Customers
PCI DSS requires SSL and early TLS to be gone from payment environments by June 30. How to check what you negotiate, change it safely, and spot who it breaks.
Certificate Lifetimes Just Got Cut to 825 Days, and the Trend Points Shorter
Newly issued TLS certificates are now capped at 825 days. Why the industry keeps cutting lifetimes, and why calendar reminders are no longer enough.
Chrome Is Distrusting Symantec Certificates: Your Replacement Timeline
Chrome plans to stop trusting certificates from Symantec's old CA infrastructure in two steps during 2018. How to tell if you're affected and when to act.
More topics
Get notified when CompleteStatus opens
New accounts are closed while we're in private beta. Leave your email and we'll send one message the moment sign-ups open — nothing else.