Knowledge Base

How to renew a certificate in Sectigo Portal?

Overview

By the end of this article, you will understand what autorenewal does, what you must complete for a renewal order to be issued, and how the requirements differ by product type. The article first defines auto-renewal and lists its benefits, then explains the renewal steps common to all products — generating a Certificate Signing Request (CSR), completing Pre-Validation for Organization Validation (OV) and Extended Validation (EV) orders, and completing Domain Control Validation (DCV). It then covers the product-specific requirements for SSL, Code Signing, S/MIME (Secure/Multipurpose Internet Mail Extensions), and Document Signing renewals, and finally explains what to do when autorenewal is not enabled.

What is auto-renewal?

Autorenewal is the process of placing a new certificate order automatically, using the data already held by Sectigo, when the current certificate approaches its expiration date. The new order uses the same product type and duration as the previous certificate. This helps ensure the renewal process begins on time, without manual intervention.

When you renew a certificate, you may see an Enable Auto-Renewal option in the SSL Certificates dashboard. The auto-renewal option is presented during the current subscription period, ahead of the next billing date.

Benefits of autorenewal

  • Prevents certificate expiration caused by missed renewal deadlines.
  • Reduces manual effort by creating renewal orders automatically.
  • Maintains continuous coverage with a valid certificate.
  • Lowers the risk of service disruption caused by an expired certificate.

How auto-renewal works

These stages apply to every auto-renewed order.

  • A new renewal order is placed automatically before the existing certificate expires.
  • Generate and submit a new Certificate Signing Request (CSR) for the renewal order.
  • For Organization Validation (OV) and Extended Validation (EV) orders, complete pre-validation.
  • Complete Domain Control Validation (DCV) to verify domain ownership.
  • Once validation succeeds, the renewed certificate is issued and can be installed on your server.


    Figure 2: Certificate setup page for entering and submitting a Certificate Signing Request (CSR) before continuing to domain validation.

     

    Figure 3: SSL Certificates dashboard showing an SSL Wildcard certificate ready for setup, with options to enable auto-renewal or select Set Up.


     

    Copilot
     

    Figure 4: Provide your Certificate Signing Request (CSR) page for entering a CSR and continuing to domain validation for a SSLcertificate.

Related article for step 2: How to Generate a CSR Using OpenSSL (Apache with mod_ssl, NGINX, OS X) | Sectigo® Official

Renewal requirements by product type

Renewal requirements by product type
ProductValidity notesKey requirement at renewal
SSLSame duration as the previous certificateSubmit a new CSR, then complete Domain Control Validation (DCV)
Code Signing455 days, even when purchased for one yearClick Setup and submit details for Organization Validation or Extended Validation
S/MIMESame product and term as the previous certificateRemove the pre-existing CSR and submit a new one before completing validation
Document SigningSame as Code SigningClick Setup and submit details for Organization Validation or Extended Validation

Code Signing renewal

Code Signing certificates currently carry a validity of 455 days, even when purchased for a one-year term.

  • After the order is placed, click Setup to submit your details. The details required depend on whether the order is Organization Validation (OV) or Extended Validation (EV).
  • Click Person Information and submit all requested information to complete the setup of the order.


    Figure 5: Signing Certificates dashboard displaying Code Signing certificate orders with their setup status, validity details, renewal dates, and available actions such as Set Up and View.


    Figure 6: Organization Information page for a Code Signing certificate setup, where organization contact and registration details must be entered before proceeding to person information.


S/MIME renewal

S/MIME (Secure/Multipurpose Internet Mail Extensions) renewal reuses the pre-existing Certificate Signing Request (CSR) automatically, along with the product and term from the previous order. Replace that CSR before validation is completed.

  • Remove the pre-existing CSR from the renewal order.
  • Generate a new CSR using Microsoft Management Console (MMC) on Windows, Keychain Access on macOS, or an equivalent tool.
  • Submit the new CSR. An identifier is not required in the CSR.
  • Set the contact email to the email address for which the S/MIME certificate is issued.
  • Complete validation.



    Figure 7: S/MIME certificate orders page displaying renewal status, expiration dates, and available actions, including the option to complete certificate setup.



                           Figure 8: Provide Contact Person Information page for an S/MIME certificate renewal

Related article: How to Generate a Certificate Signing Request (CSR) and Obtain a Certificate in PFX Format for SMIME In Windows? | Sectigo® Official

Document Signing renewal

Document Signing renewal follows the same process as Code Signing renewal. After the order is placed, click Setup, submit the details required for Organization Validation (OV) or Extended Validation (EV), then click Person Information and complete all requested fields.

If autorenewal is not enabled

When autorenewal is not enabled and the order is close to expiring, you can either:

  • Click Purchase in the dashboard, which redirects you to shop, or
  • Contact the Sectigo sales team.




                       Figure 9:  Document Signing certificate listed in the Signing Certificates dashboard 

                         Figure 10:  Provide Contact Person Information page for a Document Signing certificate

How to verify success

The renewal is complete when validation succeeds for the renewal order, and the renewed certificate is issued. You can then install the issued certificate on your server.

Frequently asked questions

What does auto-renewal actually do?

It places a new certificate order automatically before the current certificate expires, using the same product type and duration and the data already held by Sectigo.

Do I still need a new CSR if autorenewal is enabled?

Yes. A new Certificate Signing Request (CSR) must be generated and submitted for the renewal order.

Why is my old CSR being reused on an S/MIME renewal?

S/MIME autorenewal carries the pre-existing CSR forward automatically. Remove it and submit a new CSR before completing validation.

How long is a renewed Code Signing Certificate valid?

455 days, even when the certificate is purchased for a one-year term.

What happens if I did not enable autorenewal?

Click Purchase in the dashboard to go to shop or contact the Sectigo sales team.

 

Related Articles:
https://www.sectigo.com/knowledge-base/detail/complete-domain-validation
https://www.sectigo.com/knowledge-base/detail/When-and-How-to-Replace-and-Reissue-an-SSL-Certificate

 

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today