Emergency server help: get in touch

47-Day SSL Certificate Lifetime: Critical Automation for Hosts

Public TLS certificate validity drops to 200 days in 2026, 100 in 2027 and 47 in 2029, with DCV reuse shrinking alongside. What breaks on cPanel and DirectAdmin servers, and the automation, DNS and monitoring changes to make before it does.

Published Updated 7 min read

For most of the last decade a certificate was something you renewed once a year, often by hand for the paid ones. That era ended in March 2026, when the maximum validity for publicly trusted certificates dropped to 200 days. It falls to 100 days in March 2027 and to 47 days in March 2029, and domain validation results can be reused for progressively shorter periods on the same schedule, ending at ten days. A hosting provider with a few thousand certificates cannot run that by hand, and the panels have already changed how they issue. This guide sets out what changes, what breaks, and what to put in place now.

Short answer: Public certificates are capped at 200 days since March 2026, drop to 100 days in March 2027 and to 47 days in March 2029, with domain validation reuse shrinking to ten days, so every certificate must be issued, validated and installed by ACME automation with no manual step. On cPanel that means AutoSSL for every domain and service, on DirectAdmin the ACME TLS system introduced in 1.706, plus working DNS or HTTP challenge paths for every domain, correct CAA records, and monitoring that alerts on a failed renewal the same day.

What the schedule means in practice

At 200 days you renew roughly twice a year. At 100 days, quarterly. At 47 days, every month, with a renewal window of a couple of weeks. Any process that involves a person, a ticket, a CSR pasted into a vendor portal or a cron job that emails someone to “please renew” will fail at some point in that cadence and the site goes down. The only sustainable model is ACME or an equivalent API-driven issuance, with the renewal decision, the validation and the installation all automatic.

The validation reuse limit matters as much. Today a CA can reuse a completed domain validation for many months; by 2029 it can reuse it for ten days. Every renewal will effectively re-validate, so every DNS or HTTP challenge path must work every time, not just the first time.

What cPanel already does

cPanel 136 moved AutoSSL to a unified SSL/TLS interface and switched the default provider to Sectigo with short-lived certificates that reissue automatically well before expiry; Let’s Encrypt remains available as an alternative provider. The changes are described in our unified SSL/TLS guide and the short-lived certificate guide. AutoSSL runs daily and handles renewal for every domain it can validate. What it does not handle:

  • Certificates a customer bought elsewhere and installed manually. These will expire on the old cadence and then more often; migrate them to AutoSSL or to a DCV-capable process.
  • Domains whose DCV fails: proxied through a CDN without an HTTP exception, pointed elsewhere, or with a CAA record that excludes the CA. See the DCV troubleshooting guide.
  • Service certificates for the hostname (cpsrvd, Exim, Dovecot, FTP), which AutoSSL covers only when the hostname resolves to the server.

Check AutoSSL’s coverage regularly rather than assuming:

whmapi1 get_autossl_pending_queue
uapi --user=USER SSL installed_hosts | grep -E 'domain|not_after'

What DirectAdmin already does

DirectAdmin 1.706 replaced its older Let’s Encrypt integration with an ACME-driven TLS system in which domains opt in and issuance and renewal run every 24 hours, with acme_disable_after_failures stopping endless retries on broken domains. 1.707 added lego v5 and an automatic ZeroSSL account; 1.708 set 25 names per certificate and made wildcards cover the apex and first-level subdomains; 1.711 added External Account Binding for paid CAs and renews at 65 percent of lifetime. That last figure is the one to understand: at 47 days, 65 percent is about day 30, leaving 17 days to fix any failure. Confirm the settings:

da config-get acme_disable_after_failures
da config-get default_acme_profile
grep -c 'ssl_certificate_type=letsencrypt' /usr/local/directadmin/data/users/*/domains/*.conf

Domains still using manually pasted certificates show a different ssl_certificate_type; those are your migration list.

DNS is now on the critical path

HTTP-01 validation needs the domain to resolve to the server on port 80. DNS-01 needs the panel to write _acme-challenge records. Both need reliable DNS, and DNS-01 needs the panel to have write access. For domains hosted on the server’s own nameservers this is automatic. For domains at Cloudflare or another provider, either keep the site’s A record pointing at the server with the CDN’s HTTP challenge path exempted, or use the _acme-challenge CNAME delegation that DirectAdmin 1.708 detects, pointing the challenge name at a zone the server controls. Decide this per customer now; at 47 days there is no time to discover it at renewal.

Also add a CAA record naming the CAs your panel actually uses. A CAA record that names only a legacy CA blocks AutoSSL silently, and the failure only surfaces when the old certificate expires.

Monitoring that fits the cadence

An expiry check that warns at 30 days is useless when the certificate lives 47. Set thresholds relative to the renewal window: warn when a certificate has less than a third of its lifetime remaining and has not been renewed, and alert on any AutoSSL or ACME failure the same day. Our SSL expiry check script reports remaining days for every installed certificate and service; run it daily and feed the output to your monitoring rather than to a mailbox someone reads weekly.

Watch the services too. A renewed domain certificate does not help if Exim and Dovecot are still presenting the old hostname certificate; on cPanel, /scripts/checkallsslcerts runs daily and on DirectAdmin 1.710 syncs manual server certificates to services, but both should be verified after the first short-lived renewal.

Verify

Pick a domain, force a renewal, and confirm the new certificate is installed and served:

/usr/local/cpanel/bin/autossl_check --user=USER
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates

The notAfter date should be within the new lifetime and the process should have needed no human input. Repeat for a service port such as 993. The common pitfall is a customer-installed certificate with a private key the panel does not manage: AutoSSL will not replace a valid third-party certificate until it nears expiry, so the domain looks fine for months and then depends on a manual step nobody remembers. Find them now with uapi --user=USER SSL installed_hosts and look for issuers that are not your AutoSSL provider.

47-day SSL certificate lifetime at a glance

47-Day SSL Certificate Lifetime summary card: Public certificates are capped at 200 days since March 2026, drop to 100 days in March 2027 and to 47 days in March…
In short: Public certificates are capped at 200 days since March 2026, drop to 100 days in March 2027 and to 47 days in March 2029, with domain validation reuse shrinking to ten days, so every certificate must be issued, validated and installed by…

Official documentation: Let’s Encrypt documentation, DirectAdmin documentation, cPanel & WHM documentation.

Related guides: KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · CSF after ConfigServer: which fork should you run in 2026 (cPanel, DirectAdmin, Aetherinox, Sentinel)? · Migrating domains to DirectAdmin’s new ACME TLS system (1.706+) and running the migration task.

Frequently asked questions

Do the 47-day certificate limits apply to internal or private CA certificates?

No. The schedule comes from the CA/Browser Forum baseline requirements and binds only publicly trusted CAs. Certificates from an internal CA can keep any lifetime, although browsers still enforce the limit on public roots.

When exactly does the 47-day certificate lifetime start?

The maximum validity became 200 days in March 2026, becomes 100 days in March 2027 and 47 days in March 2029. Certificates issued before each date keep their original validity until they expire.

Will AutoSSL on cPanel handle 47-day certificates automatically?

Yes. AutoSSL runs daily and reissues short-lived certificates well before expiry for every domain whose DCV passes. Manually installed third-party certificates, domains that fail validation and hostnames that do not resolve to the server are the cases that still need attention.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.