All features

Automatic renewal

sslbrain renews your certificates in the CA's recommended window or at 75% of lifetime and installs them where they are used. Shorter lifetimes stop being your problem.

  • Follows the CA's recommended renewal window (ARI)
  • Otherwise renews when 75% of the lifetime has elapsed
  • Safety net, anything with 7 days or less left renews immediately
  • Built for 200, 100, and 47 day lifetimes

Renewal is a scheduling problem

When a certificate expires in production, the root cause is rarely technical. It is a calendar reminder nobody saw, a cron job on a forgotten server, or a colleague on holiday. sslbrain moves the responsibility to a central scheduler that knows every certificate you manage and renews each one automatically, long before it becomes urgent.

How the timing is chosen

When the CA offers ARI (ACME Renewal Information), sslbrain follows the CA’s own recommended renewal window. That means a certificate also renews early if the CA asks for it, for example around a revocation event. Without ARI, sslbrain renews when 75% of the lifetime has elapsed. For a 90 day certificate that is around day 67, leaving solid margin to detect and fix failures.

Certificates from a configured source never renew later than the configured days before expiry, 30 by default. And regardless of policy, a safety net applies: anything with 7 days or less remaining is renewed immediately. Failed renewals are retried automatically and reported to you while the old certificate is still valid.

Ready for 47 days

The CA/Browser Forum has scheduled maximum lifetimes to step down toward 2029: 200 days today, 100 days in 2027, and 47 days in 2029. With 50 servers on 47 day certificates you are looking at hundreds of renewals per year. A central scheduler scales with that, no matter how short lifetimes get. More detail on the 47 day certificates page.

Ready to automate your certificates?

Get started in under 5 minutes with the Free plan.