Security Architecture 6 min read Published February 14, 2025

Google's 45-Day SSL Validity Proposal: Why Automated Monitoring Is Now Critical

Analysis of Google Chrome's "Moving Forward, Together" plan to reduce TLS certificate lifespan from 90 days to 45 days.

🛡️
CheckSSLExpiry Security Research Team SSL/TLS Security & Cryptographic Reliability

⚡ Check Your Domain's SSL Expiry Right Now

Instant certificate inspection and zero-login automated email alerts.

The Rapid Shrinkage of SSL/TLS Certificate Lifespans

Over the past decade, the maximum validity period for publicly-trusted SSL/TLS certificates has decreased dramatically:

  • Pre-2015: 5-year (1,825 days) and 3-year certificates were standard industry practice.
  • 2018: CA/Browser Forum reduced maximum lifespan to 2 years (825 days).
  • 2020: Apple, Google, and Mozilla unilaterally reduced lifespan to 398 days (~13 months).
  • Let's Encrypt / ACME Standard: 90-day certificates with recommended 60-day automated renewals.
  • Google Chrome's Roadmap ("Moving Forward, Together"): Reducing public certificate lifespans to 45 days (and eventually down to 10 days).

Why Are Certificate Lifespans Becoming So Short?

  1. Mitigating Compromised Private Keys: In the event of a heartbleed-style memory leak or private key theft, an attacker can only impersonate your website for a maximum of 45 days rather than over a year.
  2. Revocation (CRLs and OCSP) Is Broken: Online Certificate Status Protocol (OCSP) and Certificate Revocation Lists (CRLs) suffer from severe privacy and latency flaws, with most browsers soft-failing when revocation endpoints time out. Short lifespans eliminate the need for unreliable revocation checks.
  3. Cryptographic Agility: Shorter lifespans allow the internet to rapidly transition to post-quantum cryptographic (PQC) algorithms without waiting years for old certificates to expire.

The Operational Danger: 8x Higher Risk of Outages

When certificates were renewed every 2 years, an organization performed the renewal process once every 24 months. With 45-day certificates, your servers will execute at least 8 to 12 automated certificate renewals per year per domain.

If an organization manages 20 domains, that equals over 200 automated renewal events every year. If your automated ACME client (Certbot, Caddy, Traefik, acme.sh) experiences a single silent failure, your website will experience an unexpected outage.

Common Automated Renewal Failure Modes

  • Firewall / Port 80 Blocks: A DevOps engineer tightens security groups, blocking HTTP-01 challenge verification on port 80.
  • Web Server Reload Glitches: Certbot successfully fetches the new certificate files onto disk, but Nginx or Apache fails to execute nginx -s reload, continuing to serve the old in-memory certificate until it expires.
  • DNS-01 API Token Expiry: Cloudflare or AWS Route 53 API tokens used for DNS challenge verification expire or lose permissions.
  • ACME Rate Limits: Hitting Let's Encrypt's duplicate certificate rate limits during CI/CD redeployments.

⚡ Audit Your Website's Remaining Expiry Window

Check your certificate's exact days remaining and setup automated external alerts now.

Check SSL Expiry Now →
Advertisement
Ad Space Reserved