TLS Certificate Renewal
A certificate that has expired, or is about to, replaced and installed properly. We issue or collect the new one, install it with the full chain, and check the handshake from outside afterwards — because a certificate that is installed but missing an intermediate still throws a warning on about half the devices that visit.
What you get
- One certificate issued or installed, with the intermediate chain in the right order
- An external handshake check across desktop and mobile clients, not a local curl that happens to trust your own machine
- Automatic renewal left configured wherever the platform supports it, so the next one does not need us
- The old certificate and key kept until you confirm the new one is live
What this does not cover
- The cost of the certificate itself, if you want a paid organization or extended validation one — this price is the work, not the certificate authority invoice
- HSTS, CSP and the rest of the security headers, which are HTTP Security Header Hardening in Security and risk
- Certificates that are not server certificates: code signing, client authentication, document signing
- Changing the application if it pins or hardcodes the old certificate
Who it fits
One certificate, once. If certificates keep catching you out, Uptime and Alert Monitoring warns you 30, 14 and 3 days ahead for $19 a month, and every hosting tier renews them as routine rather than as a purchase.