Renewing SSL certificates and handling expiry

Step-by-step guide to SSL renewal, expiration warnings, fixing common errors, and preventing service downtime. Suitable for server administrators and webmasters.

6 min Updated 5 Oct 2026

Why SSL Renewal Is Critical and When Should You Act?

An SSL certificate is one of the few components of web infrastructure that has a definite expiration date. If you miss the SSL renewal, browsers will show users a "Not Secure" warning, your site's credibility will be questioned, and in severe cases, API-dependent services or online payments will completely fail. The important point is that SSL renewal is not just an administrative task; it is a technical process that must be performed carefully and at the right time.

The best time to renew SSL is 30 to 60 days before expiration. Modern certificates are usually issued for 90 days (such as Let's Encrypt), and some commercial providers offer one-year certificates. In any case, the golden rule is: never wait for a browser warning. If you see "Not Secure" in Google Chrome, it means your SSL renewal is at least a few days overdue.

Warning Signs of Impending Expiration

  • Receiving warning emails from the certificate provider (usually 30, 14, and 7 days before)
  • Seeing the SSL certificate expired error in server logs
  • Alerts in the hosting control panel or monitoring tools such as UptimeRobot
  • Sudden drop in traffic due to browser warnings

If you see any of these signs, start the SSL renewal process immediately. Even a one-day delay can mean losing user trust and a drop in SEO ranking.

Automatic SSL Renewal; The Best Solution to Avoid Forgetfulness

The most modern and reliable method for SSL renewal is using automatic renewal. This method is specifically designed for free Let's Encrypt certificates and is enabled by default in most hosting control panels (such as cPanel, DirectAdmin, and Plesk).

Implementing Automatic Renewal with Certbot

If you have a dedicated server or VPS, the certbot tool is the gold standard for automatic SSL renewal. Follow these steps:

  1. Install Certbot on your Ubuntu or Debian server:
sudo apt update
sudo apt install certbot python3-certbot-apache
  1. Obtain the initial certificate for your domain:
sudo certbot --apache -d example.com -d www.example.com
  1. Test the automatic renewal process (dry run):
sudo certbot renew --dry-run

If the output includes the message Congratulations, all renewals succeeded, then automatic renewal is configured correctly. Certbot creates a timer in systemd by default that checks twice a day whether the certificate is nearing expiration (usually 30 days before) and renews it if needed.

Common Error in Automatic Renewal

One of the most common issues is the Failed to renew certificate error, which usually occurs because ports 80 or 443 are closed in the firewall. Certbot must be able to access your server via HTTP or HTTPS to validate the domain. To fix this issue, make sure the following ports are open in the firewall:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw reload

Also, if you are using nginx, you should install the python3-certbot-nginx package instead of python3-certbot-apache.

Manual SSL Renewal; When You Want Full Control

If you are using commercial certificates (such as Comodo, Sectigo, or DigiCert), SSL renewal is usually done manually. This process involves the following steps:

Steps for Manual Renewal of Commercial Certificates

  1. Generate a new CSR: Generate a new Certificate Signing Request (CSR) on your server. Be careful to keep the previous private key so you don't have to change it.
openssl req -new -newkey rsa:2048 -nodes -keyout example.com.key -out example.com.csr
  1. Submit the CSR to the provider: Upload the example.com.csr file in the certificate provider's user panel.
  2. Perform validation: This is usually done via email to standard addresses (such as admin@example.com) or via DNS. For DNS validation, you need to add a TXT record like this:
_dnsauth.example.com.  TXT  "2019123456789abcdef"
  1. Download the new certificate: After approval, download the issued certificate. You will usually receive a ZIP file containing the main certificate and intermediate certificates.
  2. Install on the server: Place the certificate files in the standard path (e.g., /etc/ssl/) and restart the web server.
sudo systemctl restart apache2

Common Mistake in Manual Renewal

Many server administrators also change the private key when renewing SSL. This is not wrong, but if the old certificate is still installed on CDN servers or load balancers, it can cause inconsistency. The best practice is to keep the previous private key and only generate a new CSR with the same key:

openssl req -new -key example.com.key -out example.com.csr

This prevents the Private key mismatch error.

Immediate Actions When Your SSL Certificate Has Expired

If your certificate has expired and your site is down, don't panic. By following these steps, you can resolve the issue in less than 30 minutes:

Emergency Steps to Fix Expiration

  1. Check the exact expiration date: Use the following command to check the current certificate's expiration date:
echo | openssl s_client -servername example.com -connect example.com:443 2>/dev/null | openssl x509 -noout -dates
  1. Renew immediately with Certbot: If your certificate is from Let's Encrypt, run the following command:
sudo certbot renew --force-renewal
  1. Emergency manual renewal: If you have a commercial certificate, go to the provider's panel and select the "Reissue" or "Renew Now" option. Some providers offer emergency renewal with fast DNS validation.
  2. Install and restart: After receiving the new certificate, install it and restart the web server.
sudo systemctl restart nginx

Final Testing After Renewal

After SSL renewal, be sure to perform these tests:

  • Check the new expiration date with the openssl command mentioned above
  • Test the site in a browser (should show a green padlock or security icon)
  • Check the certificate chain with the online SSL Labs tool
  • Test APIs and web services that use HTTPS

Monitoring Tools to Prevent Future Expiration

To never face SSL expiration issues again, use monitoring tools. These tools automatically check the expiration date and alert you:

  • UptimeRobot: A free service that checks your SSL status every 5 minutes and alerts you from 30 days before expiration.
  • Online SSL Checker: Tools like sslshopper.com or sslchecker.com that display the expiration date.
  • Custom script: You can write a simple script with a cronjob that checks the expiration date daily and sends an email when it's nearing the end:
#!/bin/bash
expiry=$(echo | openssl s_client -servername example.com -connect example.com:443 2>/dev/null | openssl x509 -noout -enddate | cut -d= -f2)
expiry_epoch=$(date -d "$expiry" +%s)
now_epoch=$(date +%s)
days_left=$(( (expiry_epoch - now_epoch) / 86400 ))
if [ $days_left -lt 30 ]; then
    echo "SSL certificate expires in $days_left days" | mail -s "SSL Expiry Warning" admin@example.com
fi

Place this script in crontab to run daily:

0 9 * * * /usr/local/bin/ssl-check.sh

Final Tips for Smart SSL Renewal Management

SSL renewal is a recurring process that you can fully automate with proper planning. Summary of key points:

  • For free certificates, be sure to enable automatic renewal and run the certbot renew --dry-run command once a month.
  • For commercial certificates, set a calendar reminder for 45 days before expiration.
  • Always keep the private key in a secure location and back it up.
  • If you have multiple domains, use Wildcard certificates to simplify management.
  • If using cloud services, make sure SSL renewal is coordinated with load balancer and CDN settings.

Finally, if your infrastructure is complex and you don't have enough time for manual management, you can use certificate management services offered by hosting providers. Many Iranian providers like ServerNet have enabled automatic SSL renewal in their control panels, which can free you from this concern. But in any case, understanding the SSL renewal process helps you act quickly and confidently in emergency situations.

Was this page helpful?