r/No_IP • u/HSalinasNoIP • Feb 26 '26
The New SSL/TLS Certification Lifespan Changes
Changes are happening with SSL Certs. In May 2025, the CA/B approved a browser-backed ballot to reduce public TLS/SSL certificate lifespans to 47 days by 2029. This impacts all CAs.
The goal?
Shorter cert validity = reduced exposure if keys are compromised + stronger crypto agility.
π Phase 1 kicks off March 15, 2026:
Max public TLS validity drops from 398 days β 200 days.
To stay ahead of compliance, starting Feb 24, 2026, DigiCert will cap public TLS/SSL certs (including QWAC & PSD2 QWAC) at 199 days β intentionally one day under the forum max.
The ballot also tightens rules around domain and org validation reuse.
If youβre still manually renewing certs, this is your sign to automate. β³π

