SSL renewal and Multiyear Certificates Automatic reissue initiated for my (Subscription) SSL Certificate In August 2020, the major browsers decided to stop supporting SSL certificates with an expiration date longer than 1 year. As a result, our provider, Sectigo, has been issuing SSL certificates valid for a 1 year period, even if you purchased them for 2 years. These orders are called Subscription SSL certificates.  When you buy an SSL for 2 years, Sectigo issues the certificate for 1 year and after that, the second year will need to be ‘activated’ via a reissue. Openprovider will start reissuing the SSL certificate 15 days before its expiration date. That is the reason why you received the notification about the initiated reissue. It is important that the validation and the installation is done before the current SSL certificate expires, to prevent issues for the website. What action is required? We advise to check the validation of the ssl. The type of ssl (DV, OV or EV) will determine which validation steps are required. DV If it was validated by the  ‘DNS Validation’ method and the zone is managed by Openprovider, we will update the Cname record and validate the order for you.  If the validation is set to the ‘Email’, ‘HTTP(s)’ or ‘DNS’ methods (and the zone is not managed by Openprovider), the reseller or end customer will need to validate the SSL order. OV / EV Keep in mind that OV and EV orders will have extra validation requirements (such as passing a telephone verification call), which will need to be passed successfully. Our advice is to keep an eye on the SSL certificates that need to be reissued in order to activate their second year of validity and inform your end customers about it in advance. You can change the validation method for the reissuing process by using the buttons in the SSL panel Important! Once the new SSL certificate has been issued and delivered, it is important to reinstall it before the previous SSL certificate reaches its expiration date in order to avoid any issues. The CSR and the private key will not be changed or adjusted during the reissue. Refunds There will be no refunds in case the client does not want to extend the certificate for the second year anymore after completion of one year. Automatic Renewal for SSL Certificates Question Is it possible for certificates to be renewed automatically before their expiration date? Answer Yes. RCP lets you set an auto-renew option. To enable, in the SSL overview of your control panel you can find the option "Autorenew" (AR). If you enable the option, we will automatically create a new SSL order for you, 15 days prior to the expiration date using the same details as the old certificate. Important! We will place the SSL order, but the validation which is performed by the Certification Authority is still a necessary step before the certificate will be delivered.  Be aware you will receive a new certificate, which still needs to be installed with the "old" private key. AR = Auto-Renew RN = Renew RI = Reissue CN = Cancel If you request a certificate renewal within the last 30 days of SSL expiration, then a remaining period of the SSL certificate will be added to the new certificate. The remaining period won't be added if you start a new order instead of renewing an existing one. The button to renew your certificate is therefore only shown in the control panel in the last 30 days of the SSL expiration date. The renewal request will be initiated based on the same details as the previous request. No changes can be made. Do not want to use the auto-renew settings? Start a new order in your RCP and let the old SSL expire (disable autorenew) How to renew an expired SSL certificate? Question How to renew an expired SSL certificate? Answer That is not possible. You should request a new certificate instead. Multiyear SSL Certificates / Subscription SSL Certificates Question: Can I order multi year SSL Certificates? How does this work technically? Answer: Starting from March 12, 2026 any newly issued SSL certificate will have a maximum lifespan of approximately 199 days. This applies to • New orders • Renewals • Reissues What will happen with active certificates? Certificates issued before this date remain valid until their original expiration date unless they are revoked. Impact on reissues During the validity period of a certificate, you can always apply for a reissue. The validity period of certificates re-issued after March 12, 2026 will then be limited to 199 days. This does not mean that the certificate has lost its initial validity period, because if you reissue again at a later time it will be matched to the initial validity period. For example, a one year SSL product issued after March 12, 2026 will first be issued as a certificate valid for up to 199 days. When it expires a new certificate will be reissued for the remaining time. If 30 days remain the reissued certificate will be valid for 30 days. Options for a longer validity term Customers can continue to purchase one year and multi year SSL products. The commercial term does not change and there is no loss of paid time. What changes is how certificates are issued during that term. Instead of a single long certificate multiple certificates will be issued over the lifetime of the order. Example: A one year SSL product issued after March 12, 2026 will first be issued as a certificate valid for up to 199 days. When it expires a new certificate will be reissued for the remaining time. If 30 days remain the reissued certificate will be valid for 30 days. Refunds There will be no refunds, in case after completion of 199 days the client does not want to extend the certificate to second year anymore. How will it work? Effective March 12, 2026 all 2-year orders will be processed as 2-year subscriptions. The Openprovider API functionality will remain unchanged; however, when ordering a 2-year certificate, you will receive a 199 days certificate initially. The certificate will be automatically renewed, and you will be notified accordingly. It is the user's responsibility to install the renewed certificate.  What do you need to do? Re-installation: As the initial certificate expires after 199 days, it is very important to install the new certificate that you will receive after 199 days is installed on your server timely. You can find more information about the changes in this article. Note: Above rules are subject to change and are requirements set by CA.