The CA/Browser Forum (organization responsible for SSL standards) has recently decided that SSL certificates will have progressively shorter validity periods.
Commencing 15th March 2026, rather than new or renewed certificates being valid for a year as is the case currently, they will need to be issued every six months.
Furthermore, cert validity will reduce to a little over three months from March 2027. From March 2029 certs will need to be re-issued almost monthly.
The change is designed to increase internet security by limiting the amount of time fraudulently issued certs can remain valid.
Consequences of the change
As well as increased security, another intended consequence of the change is that automation is now required to ensure the smooth re-issue and updating of certs on websites and servers. Manual cert management will become twice as tedious and costly from this March, and by 2029 will become completely unpractical.
Hosting with us ? We've got you covered!
If you are using our hosting and have purchased RapidSSL certificates or PositiveSSL Multi Domain certs, we will convert your certificate to use the AutoInstall system to keep it up-to-date, usually no action is required on your part.
If you have a GlobalSign SSL certificate with us and are using our hosting, we will (on renewal) convert that to a similar certificate type that will be automatically reissued and updated as needed by our systems.
Essentially, SSL certificates are becoming a subscription linked to the AutoInstall service - as long as you renew your cert annually as before, AutoInstall will take care of re-issuing and updating the site cert at the appropriate times.
Not Hosting with us ? We'll give you more control!
If you have a certificate that is used externally on your own hosting or server systems, then it is usually not possible for us to automate the re-issue and re-install process for that.
Instead, and on renewal, we'll convert the certificate to a supported type, and expose additional controls to allow you to manage the re-issue and approval process from within your Irish Domains account.
It will now be possible for customers to configure the certs, request re-issues, select or change validation methods, and request validation checks, from the service page in their account.
Other changes:
GlobalSign (incl AlphaSSL) Certs: From 15th March 2026 we will no longer issue or renew any new GlobalSign SSL certs, unless there is a specific need for this cert type. Unfortunately, GlobalSign certs are not compatible with the AutoInstall system used on our servers, and it is not possible for us to expose additional cert controls on customer accounts.
Expiring Globalsign AlphaSSL certs will be converted to Comodo PositiveSSL certs at renewal, subsequent renewals will be at the same or lower price.
