Auto-Renewal
You can enable auto-renewal to let the system renew your certificate before it expires. The system automatically renews a certificate within 30 days before it expires.
Auto-Renewal Restrictions
- In the list view, only the last certificate in the subscription period can be automatically renewed. In the subscription view, you can click the auto-renewal button to renew the subscription period. The new certificate automatically adopts the original's auto-renewal status, and the auto-renewal function of the original certificate is disabled.
- To ensure automatic application of certificates, do not cancel privacy authorization. Once you revoke the authorization, the platform will no longer store your information. The contact name, phone number, email address, and organization details will be deleted.
- Only paid SSL certificates that have been purchased in Huawei Cloud SCM and are about to expire can be renewed. Uploaded certificates, free certificates, and single-domain expansion packages cannot be renewed.
- If auto-renewal is enabled for a certificate, the system automatically purchases a new certificate that has the same specifications with the original one 30 days before the original one expires and submits a certificate application using the application information of the original certificate. You still need to cooperate with the CA to complete domain name ownership and/or organization verification. The CA will not issue the certificate until they validate your domain name ownership and identity.
- The renewal certificate and the original certificate are two independent certificates. Once the renewed certificate is issued, you need to install it on the web server or deploy it on the Huawei Cloud product the original one is deployed.
- The new certificate validity period is the renewal validity period (for example, 200 days) plus the remaining validity period of the original certificate. For example, if you have issued a 200-day certificate that will expire on October 1, 2026, and you renew and issue the certificate on September 25, 2026, the validity period of the renewed certificate will be five days plus April 17, 2027, that is, April 22, 2027.
- CCM starts a renewal of a DigiCert DV (basic) wildcard-domain certificate 15 calendar days before the certificate expires.
Procedure
- Log in to the CCM console.
- In the navigation pane on the left, choose SSL Certificate Manager > SSL Certificates.
- In the row containing the certificate you want to renew, click
. - After confirming that the entered information is correct, read through the Cloud Certificate & Manager Statement, Privacy Statement, the authorization statement, and check the box to agree to the disclaimer and statements.
- Click OK. If Auto-renewal enabled is displayed in the upper part of the page, the auto-renewal function is enabled successfully.
After automatic renewal is enabled, check the email notification for verification. After receiving the email, complete the verification operations in Follow-up Operations within 3 to 10 working days before the old certificate expires.
Follow-up Operations
- Verify the domain name ownership.
You must complete domain name verification to prove your ownership of the associated domain name. For details, see Verifying the Domain Name Ownership.
- Verify the organization (required for OV and EV certificates only).
The CA validates the organization used to submit the certificate application. For details, see Verifying the Organization.
- Issue the certificate.
It will take some time for the CA to review your information. The CA will issue the certificate only after they validate your information.
- Install the certificate.
Install the renewed certificate on your web server or deploy it on Huawei Cloud products to replace the old certificate that is about to expire. For details, see Installing an SSL Certificate.
- Check whether the new certificate is successfully installed.
After the new certificate is installed on the web server, check whether the certificate has been updated.
- Visit your website using a web browser.
- Click
in the address box of the browser to check whether the validity period of the certificate has been updated. If the validity period of the new certificate is displayed, the new certificate has taken effect.
Figure 1 Validity period
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot