The CA/Browser Forum has established the following schedule for shortening the maximum validity period of SSL certificates:
| Effective Date | Maximum Validity Period |
| Starting February/March 2026 | 200 days |
| Starting March 15, 2027 | 100 days |
| Starting March 15, 2029 | 47 days |
Although the service still allows you to apply for a two‑year SSL certificate, you must reissue the certificate before each shortened validity period expires in order to use the remaining days. You will receive an email reminder when it is time to reissue, and you can use the same request form below to reissue the certificate for the remaining validity.
Getting started
To request an SSL certificate, follow these steps:
- Register your hostname in DNS
- Generate a CSR (Certificate Signing Request). (see instruction)
Note: The service only supports 2048-bit keys. CSRs signed with 1024-bit keys will not be accepted. - Store your key in a safe and secure location.
- Complete the online request form. The request will be forwarded to the Cyber Security Coordinator of requested department for reference.
We’ll send you the certificate through email once the certificate has been issued.
Certificate Renewal or Reissue
The process for certificate renewal or reissue is exactly the same as for requesting a new certificate. User is required to resubmit the CSR using the online request form.