AGP Picks
View all

SSL Dragon warns renewed certificates are still taking sites down

Jul. 21, 2026
By AI, Created 17:00 UTC, Jul 21, 2026, AGP -

SSL Dragon says certificate renewals are not enough if the live server still serves the wrong file, pointing to rising outage rates as certificate lifespans keep shrinking. The company urges teams to verify what browsers actually receive after every renewal, not just what automation logs report.

Why it matters: - Certificate renewals are meant to reduce downtime, but SSL Dragon says many outages now happen after a renewal succeeds on paper and fails in production. - Shorter certificate lifespans leave less room to catch mistakes before visitors see browser warnings and leave. - The risk affects site availability, trust, and conversions when users cannot reach a secure version of a website.

What happened: - SSL Dragon, a San Jose-based provider of SSL certificates and digital security solutions, warned that renewed SSL certificates are still taking sites down. - The company pointed to CyberArk’s 2025 State of Machine Identity Security Report, which found that 72% of organizations had at least one certificate-related outage in the prior 12 months. - The same survey of 1,200 security leaders found 45% of organizations faced weekly outages, up from 12% in 2022. - SSL Dragon said the core problem is no longer renewal itself because automation can renew certificates, but that does not prove the live site is serving the right one.

The details: - Renewal software records that a certificate was requested and issued, but it does not confirm what a visitor’s browser actually receives. - SSL Dragon said the difference between those two checks is where outages begin. - Common failure points include a web server that is not restarted after renewal and keeps serving the expiring certificate. - Another failure mode is an incomplete installation that works for an administrator’s browser but fails for mobile visitors. - Load balancers can also keep presenting an old certificate even after the backend server has the new one. - In each of those cases, the renewal log still shows success. - SSL Dragon said it has documented this problem before and argued that shorter certificate lifespans shift risk from forgotten renewals to broken automation. - A 200-day validity cap has applied since March 15, 2026. - The cap drops to 100 days in March 2027 and 47 days in March 2029. - SSL Dragon said each renewal creates another opportunity for something to break. - Shorter cycles also create more renewal events and less time to detect a failure before visitors do. - SSL Dragon’s free SSL Checker checks a public site the way a browser does and reports what certificate is actually live. - The tool can reveal when a renewal did not reach production or when a server fails to provide everything needed to trust the certificate. - That gap can separate a site that appears fine at an administrator’s desk from one that fails on a phone. - Roman Munteanu, SSL Dragon’s CEO and founder, said: “Automation reports what it issued. Your server reports what visitors actually receive.” - Munteanu said outage risk lives in the gap between those two answers and that a renewal log is a record of intent, not evidence of delivery.

Between the lines: - The warning reflects a shift in security operations from remembering renewals to proving deployment. - As certificate windows shrink, teams have to treat validation as part of the renewal process, not a separate task. - The message also suggests many organizations may be monitoring the wrong signal if they only check issuance records and not external browser behavior.

What’s next: - SSL Dragon advises verifying certificate delivery from outside the network after every renewal instead of waiting for a fixed audit cycle. - The company says automated renewal through the ACME protocol can handle the higher renewal frequency, but automation still needs independent checks. - As validity periods continue to shorten, more organizations are likely to face the same production validation problem unless they add post-renewal testing.

The bottom line: - Renewing a certificate is not the same as making a secure site work for visitors, and SSL Dragon says the live browser check is the one that matters.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Today on the Internet

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Today on the Internet

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.