Your first HTTPS certificate renewal: issue, install, check
Your hosting dashboard says that a new certificate is ready. Does that mean your visitors are using it? The answer depends on where HTTPS is managed. For your first renewal, write down who obtains the certificate, which service uses it, and how you will check the connection that a visitor actually makes. Those are separate questions, even when a hosting provider handles all of them for you.…
When a new HTTPS certificate becomes ready for renewal, you must determine who acquires the certificate, which service utilizes it, and how to verify the connection during actual client visits. These are distinct steps even if a hosting provider manages all aspects. The renewal process, not the production test result, involves three key stages.
Firstly, obtain the new certificate. Certificate renewal typically involves obtaining a fresh certificate before the old one expires. It doesn't alter the expiry date printed within the old certificate. ACME, the Automated Certificate Management Environment protocol, enables automation of certificate requests. The client verifies control over the domain and requests the CA to issue a certificate.
The verification process varies based on the client and deployment, so record the names the certificate must cover and the responsible client or provider. Also, note where renewal failures are reported, ensuring someone is notified if a renewal fails.
Secondly, configure the HTTPS service to use the new certificate. The certificate's installation path and activation procedure depend on the specific product. Some services reload configuration, others require a managed upload or secret, while others handle it automatically. Follow the official procedure for your hosting platform, which should specify the certificate chain and key format to supply, how to activate the change, and how to recover in case of activation failure.
Remember, an existing connection may continue under its previous TLS state, so it's crucial to check a new connection to observe the service's current presentation.
Lastly, verify what the client receives. After activation, establish a new connection to the public hostname using a client that performs normal certificate verification. Record the certificate details, including the intended names and validity period. The client, time, and hostname should be documented for future reference. Certificate path validation and service names are governed by RFC 5280 and RFC 9525.
Keep in mind that one successful connection does not confirm the acceptance of the name and trust chain by all clients. A comprehensive deployment procedure should outline which destinations need verification. Notably, a certificate check does not replace an application health check.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.