Articles
Seven Months to 100-Day Certificates: A Prep Plan for March 2027
The 200-day certificate cap has been live since March. The 100-day step, and shorter domain validation reuse, land on 15 March 2027. A month-by-month plan.
SSL Certificate Monitoring: Never Get Caught by an Expired Cert Again
Expired TLS certificates are a common self-inflicted outage. Why auto-renewal isn't enough, what to monitor, and how to get warned weeks before expiry.
HSTS Explained: max-age Strategy, includeSubDomains Pitfalls, and the Preload List
A practical HSTS guide: how Strict-Transport-Security works, ramping max-age safely, includeSubDomains pitfalls, preloading, and copy-paste configs.
47-Day Certificates Are Coming: What SC-081 Means for Your Renewal Process
The CA/Browser Forum approved ballot SC-081, cutting TLS certificate lifetimes from 398 days to 47 by 2029. How to get your renewals ready.
Let's Encrypt Is Ending Expiry Emails and OCSP: What to Replace Before June
Let's Encrypt will stop sending expiration emails and is winding down OCSP in 2025. What that removes from your safety net, and what to put in its place.
Chrome Stops Trusting New Entrust Certificates: Check Your Chain This Week
Entrust TLS certificates issued after October 31 are no longer trusted by Chrome. How to find Entrust certificates on your estate and switch CAs cleanly.
Google Wants 90-Day Certificates: Get Ready Before It Becomes a Rule
Chrome's root program plans to propose 90-day maximum TLS certificate lifetimes. No date yet, but manual renewals are on borrowed time. Here's how to prepare.
OpenSSL 3.0.7: The Critical Bug That Wasn't, and Why the Fire Drill Still Paid Off
OpenSSL pre-announced a critical fix, then shipped two high-severity bugs instead. How to find every OpenSSL 3 copy you run, and why the inventory matters.
Fixing Mixed Content Warnings — Finishing the HTTPS Migration You Started
Active vs passive mixed content, how browsers treat each, finding hardcoded http:// URLs, CSP upgrade-insecure-requests, and staying clean after migration.
TLS 1.0 and 1.1 Are Being Shut Out — Time to Check What Your Server Negotiates
Chrome, Firefox and Edge now block TLS 1.0 and 1.1. How to test what your server negotiates, enable TLS 1.2/1.3 on nginx and Apache, and handle legacy clients.
One-Year Certificates Are Coming — Apple Just Changed the Rules
From September 1, Safari will reject new TLS certificates valid longer than 398 days. What Apple's unilateral move means and how to get renewals ready.
TLS 1.3 Is Final: What RFC 8446 Changes and What to Do About It
TLS 1.3 is final as RFC 8446, after four years and 28 drafts. What changed, what was removed, and how to check what your servers negotiate.
More topics
Get notified when CompleteStatus opens
New accounts are closed while we're in private beta. Leave your email and we'll send one message the moment sign-ups open — nothing else.