All Products
Search
Document Center

Certificate Management Service:SSL certificate renewal and expiration

Last Updated:Aug 18, 2026

When the subscription validity period of an SSL Certificate or the validity period of a single certificate is about to expire and you do not act in time, your website can no longer serve traffic over HTTPS. V2.0 and V1.0 certificates follow different renewal rules: when the subscription expires, you renew it to extend the subscription validity period; when a single certificate expires, you must apply for a new certificate instead. This topic starts from identifying the certificate version and checking the renewal conditions, then describes how to renew commercial certificates and uploaded certificates, what to do after a certificate has already expired, and answers frequently asked questions.

Renewal prerequisites

Step 1: Confirm the certificate version and type

SSL Certificate Management is split into V2.0 and V1.0, and the two versions have different management entries. If you hold certificates in both versions, open each of the following pages to confirm where the target certificate is located:

Entry

Description

SSL Certificate Management V2.0

The new management page. All newly purchased certificates are managed here, includingCommercial Certificates , and Uploaded Certificates.

SSL Certificate Management (V1.0 Discontinued)

The legacy management page. It holds existing Commercial Certificates only. New purchases are discontinued. If your account has no V1.0 certificates, the link opens the console homepage.

Step 2: Determine whether the subscription or the certificate is expiring

  • This step applies only to Commercial Certificates in V1.0 and V2.0. Skip it for other certificate types.

  • If you have already confirmed that the subscription is expiring, skip this step.

In this topic, renewal means extending the subscription validity period of an SSL Certificate, that is, the service duration you purchased. Global certificate industry policies impose a maximum single-issuance validity period. When the subscription duration exceeds that limit, the subscription is covered by multiple certificates issued in sequence. When the current certificate is about to expire but the subscription has not expired, apply for a new certificate instead of renewing.

The relationship between the subscription validity period and the certificate validity period is as follows:

image

The subscription duration is counted from the issuance date of the first certificate. For example, if you purchase a one-year subscription and the first certificate is issued on T, the subscription expires on T plus one year. After a renewal, the new expiration date is counted from the original subscription expiration date. For example, if you renew for two years and the original subscription expires on N, the subscription expires on N plus two years after the renewal.

Use the following methods to determine whether the subscription or the current certificate is expiring:

Subscription expiration date

Certificate expiration date

V2.0

On the Commercial Certificates tab, check the Subscription Period of the target certificate instance. If the subscription has not expired, simply apply for a new certificate.

On the Commercial Certificates tab, the date is displayed in the Status column of the target certificate instance.

V1.0

On the Commercial Certificates tab, check the target certificate. If a certificate is linked below it by a yellow linelinked certificate indicator, the subscription has not expired. If the status of the certificate below is:

  • Not Activated: the system automatically starts the application process for the new certificate 15 days (exclusive) before the current certificate expires. Monitor the application status. If the application fails, see Domain ownership verification to handle it manually.

  • Pending Application: in the Actions column, click View Certificate, find the next certificate, and submit the certificate application.

On the Commercial Certificates tab, check the Validity Period of the target certificate.

For how to apply for a certificate, see Submit a CA application. After the new certificate is issued, you must deploy it to your business systems again.

Step 3: Check whether the renewal conditions are met

V2.0

V1.0

Commercial Certificates

  • Status is Pending Expiration, which means the subscription validity period is less than 15 days (14 days or fewer remaining), and no certificate is linked below it by a yellow linelinked certificate indicator.

  • Alibaba brand certificates cannot be renewed. The console provides only a repurchase entry.

  • Expired certificates cannot be renewed. See Purchase a commercial certificate to purchase a new one.

Uploaded Certificates

Status is Pending Expiration, which means the subscription validity period is less than 15 days (14 days or fewer remaining). Renewal is equivalent to purchasing a new certificate on Alibaba Cloud.

Not applicable. Migrate to V2.0.

Note
  • V2.0 supports early renewal. As long as Status is Issued or About to Expire and the other conditions above are met, you can renew at any time within the subscription validity period. You do not have to wait until the certificate is close to expiration.

  • The V1.0 renewal entry appears automatically only after the certificate enters the Pending Expiration state, which is expected behavior. In practice, the renewal button may still be hidden on the day when 15 days remain, and usually appears the next day, when 14 days or fewer remain.

  • To handle a V1.0 certificate before the renewal entry opens, you can purchase a new certificate of the same specification and brand in V2.0. However, the subscription validity period of the new instance is calculated independently from the original instance, so the overlapping duration of the two instances is wasted. For more information, see What is the difference between renewal and direct purchase?.

  • The phrase "renew and update the certificate at least 5 business days in advance" in expiration reminder emails and text messages means that you should reserve at least 5 business days before the expiration date to complete the renewal, application, validation, and deployment. It does not mean that you must renew within 5 days after you receive the reminder. It is normal that the renewal window has not opened yet when you receive a reminder.

Commercial Certificates renewal

V2.0

  1. Go to the SSL Certificate Management V2.0 page.

  2. On the Commercial Certificates tab, find the target certificate subscription instance.

  3. In the Actions column of the target certificate subscription instance, click the more icon icon, and then click Renew in the dialog box.

    If the renewal conditions are not met, the console does not display the Renew button. For the renewal conditions, see Step 3: Check whether the renewal conditions are met.

  4. On the page that appears, select the renewal duration, select auto-renewal if needed, and complete the payment.

    Auto-renewal only completes the payment automatically and extends the subscription validity period. It does not apply for or deploy certificates automatically.

After the renewal, click Certificate Application in the Actions column of the current certificate instance to apply for and deploy the certificate again. For detailed steps, see Submit a CA application and Select a certificate deployment method. If the Managed Service is enabled for the certificate instance, the application and deployment process starts automatically when certain conditions are met. For more information, see What is certificate hosting.

V1.0

  1. Go to the SSL Certificate Management (V1.0 Discontinued) page.

  2. On the Commercial Certificates tab, find the target certificate. In the Actions column, click Renewal purchase.

    If the renewal conditions are not met, the Renewal purchase button is not displayed. For the renewal conditions, see Step 3: Check whether the renewal conditions are met.

  3. In the Certificate renewal panel, configure the following parameters:

    • CSR Generation: We recommend that you select Automatic, which follows key rotation security practices. You can also select Manual or Original Key Inherited. For more information, see How do I create a CSR file?.

    • Domain Verification Method: Defaults to the same method used for the old certificate. You can change it if needed.

    • Contact: Make sure the information is accurate and valid.

    • Renewal Period: If you have a remaining certificate quota, the renewal period is fixed at one year, one unused certificate quota is consumed, and no extra payment is required. If the remaining certificate quota is 0, you must pay separately, and the available renewal periods depend on the certificate brand.

      If you renew by paying separately because no quota remains, the new certificate is created under Commercial Certificates in V2.0, and subsequent operations must be performed on the V2.0 Commercial Certificates tab.

  4. Click Renewal immediately and complete the payment.

    After the renewal, the system generates a new certificate in the Pending Application state, and you must apply for and deploy the certificate again. For detailed steps, see Submit a CA application and Select a certificate deployment method. If the Managed Service is enabled for the certificate instance, the application and deployment process starts automatically when certain conditions are met. For more information, see What is certificate hosting.

Uploaded Certificates renewal

  1. Go to the SSL Certificate Management V2.0 page.

  2. On the Uploaded Certificates tab, find the target certificate and click Update in the Actions column.

  3. On the purchase page, select the configurations and complete the purchase. For the purchase parameters, see Purchase a certificate.

FAQ

The certificate has already expired. What should I do?

Expired certificates cannot be renewed. You must purchase a new one:

  • If Commercial Certificates has expired, see Purchase a commercial certificate to purchase a new one.

  • If Uploaded Certificates has expired, purchase a new one from the original provider, or purchase Commercial Certificates on Alibaba Cloud.

If the expired certificate has already interrupted your business, we recommend that you first purchase a domain validated (DV) single-domain certificate for emergency recovery. With DNS validation, such a certificate is usually issued within a few minutes to about 15 minutes. After access is restored, replace it with a certificate of the specification you need. organization validated (OV) and extended validation (EV) certificates require manual review and take longer to issue, so they are not suitable for emergency recovery.

Why is the certificate valid for only six months when I purchased a two-year certificate?

This is expected behavior. You need to distinguish between two concepts, the subscription validity period and the certificate validity period:

  • subscription validity period: the service duration that you purchased, such as one year, two years, or three years. It is counted from the date on which the first certificate is issued.

  • certificate validity period: the actual usable duration of a single certificate, counted from the date on which the CA issues it, not from the order date. Constrained by CA/Browser Forum industry policy, the maximum single-issuance validity period keeps getting shorter and is currently about six months.

As a result, you must apply for certificates several times within the subscription period to cover the full service duration. For example, a one-year subscription usually requires 2 applications, and a two-year subscription usually requires 4. The validity period of a single certificate is as displayed in the console.

The duration you purchased is not reduced, and applying for certificates within the subscription period requires no extra payment. However, before each certificate expires, you must apply for the next certificate and deploy it again. If the Managed Service is not enabled, this means you must perform an application and deployment about every six months within the subscription period, so plan your operations in advance.

Why can't I find the renewal button?

First confirm which version your certificate belongs to in Step 1: Confirm the certificate version and type, and then troubleshoot with the corresponding section below.

General checks, applicable to both versions:

  • Has the certificate expired? Expired certificates cannot be renewed, the renewal entry is no longer available, and you must purchase a new certificate.

  • Are you looking in the wrong console? The SSL Certificate renewal entry is in the certificate list of the Certificate Management Service console, the console that manages your digital certificates. It is not on the Renewal or My Subscriptions page of the Expenses and Costs console.

  • Check whether the button is hidden behind the more icon icon. Click the icon to show it.

V2.0 certificates:

V1.0 certificates:

  • V1.0 does not support early renewal. The renewal entry opens only within 15 days before expiration.

  • The renewal button may still be hidden on the day when 15 days remain. You usually have to wait until 14 days or fewer remain, that is, until the next day.

Will the system automatically apply for the next certificate before expiration?

For a V1.0 certificate, if it is within the purchased duration and the next certificate is in the Not Activated state, the application process for the next certificate starts automatically. For a V2.0 certificate, you must enable the Managed Service for the next application to start automatically. Otherwise, you must submit the application yourself before expiration.

Note the following points about the Managed Service:

  • The Managed Service is a paid service. You must purchase Managed Service quota separately, and that fee does not include the cost of the certificate itself. Purchasing quota does not immediately issue a new certificate; quota is deducted only when the system automatically submits an application.

  • Trigger time: the system submits the application for the next certificate only when the remaining validity period of the current certificate is less than 15 days, not when the subscription reaches one year.

  • Validation-free authorization is required. If the domain name does not have validation-free authorization, for example because the domain name does not belong to the current account or does not use Alibaba Cloud DNS, you must still complete domain ownership validation within the time window. Otherwise the issuance fails.

  • Automatic deployment supports only associated Alibaba Cloud services, such as CDN, WAF, and SLB/ALB. For certificates deployed on a self-managed web server on ECS, such as NGINX or Apache, or on an on-premises server, you must still download and install the new certificate manually after it is issued.

What does the "Hosted, not activated" certificate status mean? Do I need to take action?

This is a normal state. It means the system has reserved the next certificate for you but has not triggered the issuance process yet. When the remaining validity period of the current certificate is less than 15 days, the system submits the application automatically. Expiration reminder text messages or emails that you receive during this period are routine notifications and do not affect the automatic renewal process.

You need to pay attention to two points:

To confirm whether the new certificate is deployed automatically to cloud services after issuance, check the status of the corresponding hosted deployment task on the Hosted Deployment for Cloud Services tab of the Deployment Management Deployment to Cloud Services page in the Certificate Management Service console.

How do I configure or disable certificate expiration reminders?

  • Customize reminders: expiration reminders are enabled by default for commercial certificates. To adjust them, find the target certificate on the Message Notifications page of the Certificate Management Service console and edit it. Batch editing is supported. You can configure the reminder contacts, notification channels, expiration reminder time, and reminder frequency.

  • Available values: the expiration reminder time can be 15, 30, 60, or 90 days in advance, and the default is 30 days. The reminder frequency can be once only, every day, every 3 days, every 5 days, or every 7 days, and the default is every day.

  • Notification channels: email, internal message, and Webhook are supported. Text messages are not supported.

  • Disable reminders: set the reminder switch of the target certificate to off on the Message Notifications page. After you disable reminders, monitor the certificate validity period yourself to avoid business interruptions caused by expiration.

  • In addition to console message notifications, the contact that you specify when you apply for a certificate receives expiration notifications independently, and you must maintain that contact separately in the certificate information.

Nothing changed in the console after I paid for the renewal, and I cannot find the new certificate. Why?

Renewal does not extend the validity period of the old certificate. It essentially has a new certificate issued. Therefore, after the payment, the old certificate still shows the About to Expire status, which is expected. Confirm and handle it as follows:

  • Look for the new certificate in the right place: see Step 1: Confirm the certificate version and type.

  • Confirm that the renewal has taken effect: check whether the Subscription Period of the certificate instance has been extended by the renewal duration.

  • If you renewed a V1.0 certificate by paying separately because no quota remained, the new certificate is created under Commercial Certificates in V2.0, and subsequent operations must be performed on the V2.0 Commercial Certificates tab.

  • Complete the remaining required steps: payment alone does not activate the new certificate. On the Commercial Certificates tab, find the new certificate in the pending application state, click Certificate Application in the Actions column to submit the application, complete domain ownership validation, wait for the CA to issue the certificate, and finally download and deploy the new certificate to replace the old one. Until the deployment is complete, your business still uses the old certificate.

  • If you have paid but still cannot find the new certificate, refresh the page and confirm that you are logged on with the account that purchased the certificate.

Why does the website still show an insecure or expired certificate warning after I deploy the renewed certificate?

Renewal only extends the subscription duration. It does not replace the certificate on your server automatically, so you must apply for and deploy the certificate again. For detailed steps, see Submit a CA application and Select a certificate deployment method.

If the warning persists after redeployment, troubleshoot with the following steps:

  • Confirm that the correct certificate file is deployed: make sure the newly issued certificate file, not the old one, is deployed on your server.

  • Confirm that the web service has been restarted: on NGINX, Apache, Tomcat, IIS, and similar web servers, you must restart or reload the service after replacing the certificate file before the new certificate takes effect.

  • Clear your browser cache: the browser may have cached the state of the old certificate. Try force-refreshing the page with Ctrl+F5, clearing the browser cache, or visiting the site in incognito or private mode.

  • Check intermediate services such as CDN and WAF: if your website uses content delivery network (CDN), Web Application Firewall (WAF), Global Accelerator (GA), or Server Load Balancer (SLB), you must also update the certificate to the new one in the consoles of those services. Otherwise, visitors still receive the old certificate served by those intermediate services.

  • Confirm that the certificate chain is complete: certificate files downloaded from Alibaba Cloud usually include the complete certificate chain. If you assemble it yourself, make sure it includes the server certificate and all intermediate certificates.

Why are there multiple records, including two identical ones, in the certificate list after a V1.0 renewal?

This is expected behavior. After a V1.0 certificate is renewed, the system generates a new certificate in the Pending Application state and adds a linked record under the original certificate. The linked record only shows the relationship between the old and new certificates; it is still the same certificate, and you are not billed twice.

What is the difference between renewal and direct purchase?

  • Commercial Certificates: the subscription validity period is calculated differently.

    • Certificate renewal: the new expiration date is counted from the subscription expiration date. For example, if the original subscription expires on June 1, 2026 and you renew for one year on May 18, 2026, the new subscription expires on June 1, 2027.

    • Direct purchase: the calculation is completely independent of the original certificate subscription instance. The subscription validity period is counted from the date on which the new certificate is first issued, so the overlapping period between the two instances is wasted.

  • Uploaded Certificates: there is no difference between renewal and direct purchase. In both cases the subscription validity period is counted from the date on which the new certificate is first issued.

I have multiple certificates. How do I know which ones need renewal?

SSL Certificates are renewed per instance, that is, per certificate, so you must check each certificate individually even when several certificates cover the same domain name. We recommend the following approach:

  • Check the certificate lists on the commercial certificate tab in both SSL Certificate Management V2.0 and V1.0, and look for certificate instances whose current status is about to expire or expired.

  • On the Message Notifications page of the Certificate Management Service console, review the list of certificates that have expiration reminders configured, so that you do not overlook certificates without reminders. We recommend that you enable reminders for critical certificates.

  • Renew each certificate that needs renewal by following the section on renewal of commercial certificates. After each renewal, every new certificate must be applied for, issued, and deployed separately.

  • A paid renewal order covers only one certificate instance. If you hold multiple certificates, you have multiple renewal tasks, so check them instance by instance to avoid missing one.

How do I choose between manual renewal, auto-renewal, and the Managed Service in V2.0?

Method

Scope

Scenarios

Manual renewal

Extends the subscription duration only. After the renewal, you must manually apply for, validate, obtain, and deploy the new certificate

You have few certificates and want to control the renewal timing yourself

Auto-renewal, selected when you purchase or renew

Automatically completes the payment and extends the subscription validity period only. It does not apply for or deploy certificates automatically, and the follow-up operations are the same as with manual renewal

You want to avoid forgetting the payment

Managed Service

A paid service. The system automatically applies for and obtains a new certificate before the current one expires, and can automatically deploy the new certificate to associated Alibaba Cloud services such as CDN, WAF, and SLB

You want to reduce renewal operations. For certificates deployed on self-managed servers, such as ECS instances or on-premises servers, you must still deploy them manually after issuance

If you only need to handle the current certificate, choose manual renewal. If you want less maintenance work later, consider enabling the Managed Service. For more information, see Will the system automatically apply for the next certificate before expiration?.