Risk vs Benefit: The Impact of Shorter 90-Day SSL Certificate Life Cycles (2024)

In today’s digital age, securing your website and ensuring your users’ safety has never been more critical. Secure sockets layer (SSL) certificates are the go-to solution for securing websites by encrypting the data transmitted between web servers and browsers.

Historically, SSL digital certificates could be valid for years, after which they had to be renewed or replaced. Following the announcement by Apple® to reduce certificate validity from 27 months to 13 months on its Safari® browsers, many others including Google® adopted the same approach on its Chrome browser beginning in September 2020. As a result, many certificate authorities (CAs) started to reduce the validity period of the SSL certificates they issue. Most recently, Google announced that it would further reduce certificate validity on Chrome to 90 days. Since Chrome is one of the most widely used browsers with approximately 65% market share[i], we expect many other browsers to follow suit.

SSL certificates issued for websites must comply with the new maximum validity period to be trusted by Chrome users. Shorter certificate life cycles bring about benefits to improve security and reduce the risks associated with long-lived certificates. Here are some of the risks associated with longer-lived SSL certificates:

  1. Increased vulnerability to attacks: Longer-lived SSL certificates offer a longer window of opportunity for hackers to exploit vulnerabilities and launch attacks on websites. By limiting the certificate’s lifespan to 90 days, the potential damage that could be caused by an attack is significantly reduced.
  2. Lack of agility: Websites using longer-lived SSL certificates are less agile in responding to changes in their security requirements. With a 90-day SSL certificate life cycle, website administrators can quickly update their security measures to adapt to emerging threats and vulnerabilities.
  3. Lack of accountability: Longer-lived SSL certificates reduce accountability as it becomes challenging to attribute security incidents to specific certificates or web servers. Shorter-lived SSL certificates increase accountability, as security incidents can be traced back to specific certificates and web servers, making it easier to identify the cause and take corrective action.

One of the primary challenges that organizations will face with shorter SSL certificate life cycles is the increased frequency of certificate renewals. Managing SSL certificates can be a complex and time-consuming task, especially for organizations with a large number of websites and web applications. If mismanaged, certificates could expire and pose significant risks to website security and the integrity of user data. Here are some of the risks:

  1. Data breaches: When an SSL certificate expires, the secure connection between the website and its users is broken, making it possible for hackers to intercept and steal sensitive data such as login credentials, credit card numbers, and personal information. This creates opportunities for cybercriminals to steal sensitive data transmitted between a website and its users.
  2. Loss of trust: When users see an expired certificate warning message in websites, they may perceive the website as insecure and untrustworthy. This negatively impacts user trust in the website and its owner, leading to a loss of business and reputation damage.
  3. Compliance issues: For websites that handle sensitive user data such as healthcare records, financial information, or other regulated data, certificate expiration can result in compliance issues. Compliance standards such as HIPAA, Payment Card Industry Data Security Standard (PCI DSS), and General Data Protection Regulation (GDPR) require websites to maintain SSL certificates and ensure they’re valid and up to date.
  4. Service interruptions: An expired SSL certificate can cause service interruptions that can lead to downtime and lost revenue for businesses, as users may be unable to access the website or may receive warning messages that the website is not secure.
  5. Search engine penalties: Search engines such as Google consider SSL certificates to be a ranking factor and may penalize websites that have expired certificates. Such search engine penalties can negatively impact website rankings and traffic for businesses.

With certificates expiring every 90 days, organizations must renew their certificates more frequently. This requires careful planning, investment in certificate management tools, and adjustments to processes and procedures to manage the increased volume of certificate renewals. Here are some best practices to reduce the risks associated with certificate expiration:

  1. Automated certificate management: Use automated certificate management tools that can track and renew certificates automatically, reducing the risk of manual errors and certificate expirations.
  2. Centralized certificate management: Centralize certificate management to reduce the complexity of certificate renewal and to ensure consistency across multiple websites and web applications.
  3. Regular certificate monitoring: Monitor SSL certificates regularly to detect any issues, such as certificate expirations, and take corrective action promptly.
  4. Use of CAA records: Use certificate authority authorization (CAA) records. Domain owners can specify which CAs are authorized to issue SSL certificates for their domain, and can even specify specific certificate types or validation methods that should be used, giving domain owners greater control over the SSL certificate issuance process, and can help prevent the issuing of fraudulent or unauthorized certificates.

In summary, while the 90-day SSL certificate life cycle offers improved security, agility, and accountability, it may pose some challenges for organizations, especially those with a large number of web properties. However, with careful planning, investment in automated certificate management tools, and adjustments to their processes and procedures, organizations can effectively manage shorter SSL certificate life cycles and ensure the security of their websites and web applications.

If you’re concerned about the upcoming shorter SSL certificate life cycles, our team of experts can help you better prepare for the changes and implement a comprehensive SSL certificate management strategy to keep your website secure and compliant. Contact us today.

[i] gs.statcounter.com/browser-market-share

Risk vs Benefit: The Impact of Shorter 90-Day SSL Certificate Life Cycles (2024)

FAQs

Risk vs Benefit: The Impact of Shorter 90-Day SSL Certificate Life Cycles? ›

Increased vulnerability to attacks: Longer-lived SSL certificates offer a longer window of opportunity for hackers to exploit vulnerabilities and launch attacks on websites. By limiting the certificate's lifespan to 90 days, the potential damage that could be caused by an attack is significantly reduced.

What are the risks of SSL certificate expiry? ›

Security dangers

Expired SSL certificates open up multiple attack vectors, including phishing attacks and data breaches, which can weaken your web application's security.

Why is certificate lifecycle management important? ›

A well-defined certificate management strategy is invaluable to businesses in the long run, since the increased visibility and control over their infrastructures helps them prevent application downtime and outages which are caused due to faulty, misconfigured, or expired certificates.

When Google announced plans to reduce the lifetime of publicly trusted certificates to 90 days? ›

In March 2023, Google announced plans to reduce the maximum validity period for publicly trusted TLS/SSL certificates from 398 days to 90 days. The proposal aims to improve security, promote faster adoption of security updates, and reduce the window of vulnerability for organizations.

What is the lifespan of SSL certificate? ›

SSL certificates expire at maximum 398 days from their issuance date, but most CAs will set their expiration date sooner, offentimes around 395 days. It is important to renew any of them BEFORE they expire. Waiting will cause serious disruptions for organizations and their customers.

What are the benefits of SSL certificate renewal? ›

Reduce the risk of server vulnerability.

Certificates help prevent malicious actors from making unauthorized changes to your servers and compromising your company's data—that's why it's so important to keep SSL certificates up to date.

What is the grace period for SSL certificate? ›

From September 2020 onwards, SSL certificates have a validity period of only 397 days or 13 months.

Why is life cycle management important? ›

Proper management of an asset's life cycle can help ensure that safety requirements are met throughout its entire operational life, reducing the risk of accidents or injuries. Asset Life Cycle Management helps to identify opportunities for cost savings and efficiency improvements, reducing overall lifecycle costs.

What are the three main goals of lifecycle management? ›

Confidentiality, integrity, and availability — often referred to as the CIA triad — are the three main goals of data lifecycle management.

What are the key stages in the lifecycle of a certificate? ›

The six stages of the certificate lifecycle
  • Certificate enrollment. Certificate enrollment is initiated by a user request to the appropriate CA. ...
  • Certificate validation. ...
  • Certificate revocation. ...
  • Certificate renewal. ...
  • Certificate destruction. ...
  • Certificate auditing.
Sep 20, 2023

Is reducing the public SSL lifespan from 398 days to 90 days? ›

In its “Moving Forward, Together” roadmap, Google announced intentions to reduce the maximum validity for all public SSL/TLS certificates to 90 days from 398 days. This will affect several businesses across domains using SSL/TLS certificates to secure their websites.

What is Google's 90 day disclosure policy? ›

Google's vulnerability disclosure policy

This is why Google adheres to a 90-day disclosure deadline. We notify vendors of vulnerabilities immediately, with details shared in public with the defensive community after 90 days, or sooner if the vendor releases a fix.

What is the validity period of Google SSL certificate? ›

Validity Period Update: Since September 2020, Google Chrome has enforced a maximum validity of 398 days (around 13 months) for TLS certificates. Google wants to reduce that to 90 days (as of April, 2024, this is not yet implemented).

What is the impact of SSL certificate expiry? ›

Once your certificate expires, site visitors will encounter the "Your connection is not private" message. All further communication will be displayed in plaintext and therefore, will no longer be encrypted.

Why is SSL no longer used? ›

SSL has not been updated since SSL 3.0 in 1996 and is now considered to be deprecated. There are several known vulnerabilities in the SSL protocol, and security experts recommend discontinuing its use. In fact, most modern web browsers no longer support SSL at all.

When did SSL become obsolete? ›

Should You Be Using SSL or TLS? Both SSL 2.0 and 3.0 have been deprecated by the Internet Engineering Task Force, also known as IETF, in 2011 and 2015, respectively. Over the years vulnerabilities have been and continue to be discovered in the deprecated SSL protocols (e.g. POODLE, DROWN).

What is the risk of invalid SSL certificate? ›

If the SSL certificate gets flagged as invalid by the browser, the data exchanged between you and the website you're trying to connect to will be transferred in cleartext. Potentially, any user credentials or other sensitive data communicated over the channel can be sniffed or stolen.

What to do if an SSL certificate is expired? ›

How to renew
  1. Create a certificate signing request (CSR). First and foremost, your web host will need to validate the identity of your server. ...
  2. Send the CSR to the CA. Your CSR is all set and you are ready to move forward with the renewal process. ...
  3. Validate your certificate. ...
  4. Install the certificate.
Jul 24, 2023

What is the impact of SSL TLS certificate expired? ›

Since TLS/SSL certificates facilitate encryption of data in transit, expired certificates also leave networks prone to attacks. A network is made up of interconnected points, and even if one of those points malfunctions, the entire infrastructure collapses.

What are the risks of SSL inspection? ›

Some drawbacks and risks when you inspect SSL traffic may include: A compromised CA: If the entity assigning SSL certificates experiences an attack that causes it to issue unauthorized (but still trusted) SSL certificates, attackers may bypass SSL inspections by impersonating legitimate domains.

Top Articles
Activate Office 2010 - Microsoft Support
Getting Honey Ready for Bottles
How To Start a Consignment Shop in 12 Steps (2024) - Shopify
Jail Inquiry | Polk County Sheriff's Office
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Alpha Kenny Buddy - Songs, Events and Music Stats | Viberate.com
His Lost Lycan Luna Chapter 5
سریال رویای شیرین جوانی قسمت 338
Local Dog Boarding Kennels Near Me
Panorama Charter Portal
Patrick Bateman Notebook
Carolina Aguilar Facebook
Walmart Car Department Phone Number
Icivics The Electoral Process Answer Key
Lakers Game Summary
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Www.publicsurplus.com Motor Pool
Boston Dynamics’ new humanoid moves like no robot you’ve ever seen
Shadbase Get Out Of Jail
Southland Goldendoodles
Asteroid City Showtimes Near Violet Crown Charlottesville
Jesus Revolution Showtimes Near Regal Stonecrest
Hdmovie2 Sbs
800-695-2780
2023 Ford Bronco Raptor for sale - Dallas, TX - craigslist
Danielle Moodie-Mills Net Worth
Keshi with Mac Ayres and Starfall (Rescheduled from 11/1/2024) (POSTPONED) Tickets Thu, Nov 1, 2029 8:00 pm at Pechanga Arena - San Diego in San Diego, CA
WPoS's Content - Page 34
Funky Town Gore Cartel Video
FREE Houses! All You Have to Do Is Move Them. - CIRCA Old Houses
Street Fighter 6 Nexus
Slv Fed Routing Number
Gerber Federal Credit
Gideon Nicole Riddley Read Online Free
Appleton Post Crescent Today's Obituaries
Polk County Released Inmates
Personalised Handmade 50th, 60th, 70th, 80th Birthday Card, Sister, Mum, Friend | eBay
Marcus Roberts 1040 Answers
Jasgotgass2
Atom Tickets – Buy Movie Tickets, Invite Friends, Skip Lines
Bunkr Public Albums
SF bay area cars & trucks "chevrolet 50" - craigslist
Kutty Movie Net
Payrollservers.us Webclock
R: Getting Help with R
Arcanis Secret Santa
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Theater X Orange Heights Florida
Rubmaps H
Bumgarner Funeral Home Troy Nc Obituaries
Intuitive Astrology with Molly McCord
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 5725

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.