Changes coming to SSL Certifications and Domain Validation
Two domain validation policy changes are expected to take effect before the end of 2021 which will affect how website information is validated for SSL Certificates.
These policy changes apply to all new certificate requests, renewals, and reissues. These changes won’t affect certificates already issued.
What is changing?
Domain revalidation will be required every 398 days
Mozilla and the CA/B Forum are reducing the timeframe for domain validation to 398 days. This will require SSL Certificates to be revalidated each year. The policy change is expected to take effect on 1 October 2021.
Validating domains using file-based authentication
The CA/B Forum is changing file-based domain authentication (also known as file auth, token auth, http auth, or method 18 and 19). The change will disallow the use of the file-based domain control validation method for wildcard certificates and thus limit the use of the method for subdomains. Email and DNS validation methods will not be affected.
Currently, the industry allows domain validation at the primary domain level (example.com) to also apply to wildcard certificates (*.example.com) and all subdomains (support.example.com). The policy change will require separate file-based validation for each fully-qualified domain name. The policy change is expected to take effect at the end of 2021.
Any action needed?
No immediate action is required. Please be aware that SSL Certificates and Domain Validation will need to be done annually from 1 October 2021 onwards. If you have a service with us that relates to this, we will automatically manage your services under this new schedule.