← Back to Articles
Guide2026-04-08•10 min read

SSL Certificate Guide 2026

· CSR.plus Team

SSL Certificate Guide 2026
  • •DV certs are free and automatic; OV and EV add verified organization identity but cost more and take longer.
  • •Wildcard covers one domain and all subdomains; multi-domain (SAN) covers several distinct names.
  • •As of 2025, public TLS certificates are valid for at most 90 days — automation is now the standard.
90 days
Maximum validity
for public certificates since 2025
Minutes
DV issuance
fully automated validation
256-bit
Encryption strength
typical AES session keys

How certificates work

An SSL/TLS certificate is a signed statement binding a public key to a domain. When a client connects, the server presents the certificate, the client verifies the signature against a trusted root, and the two sides negotiate a session key. A certificate never travels with the private key — the key stays on the server.

Validation levels: DV, OV, EV

Domain Validation only proves you control the domain; issuance takes minutes and it is free through Let’s Encrypt. Organization Validation additionally verifies the legal entity and shows its name in the certificate. Extended Validation performs the deepest checks and used to display the green address bar; browsers have since standardized the UI, so EV now mainly signals organizational trust.

Coverage: single, wildcard, multi-domain

A single-domain certificate covers one name. A wildcard like *.example.com covers the domain and all its subdomains, which suits sites with many services. A multi-domain (SAN) certificate lists several distinct domains — good for consolidating example.com, example.org and a mobile API under one certificate.

The 90-day certificate era

Public CAs now issue certificates valid for at most 90 days. Short validity shrinks the damage window when a key leaks, but manual renewals three times a year are painful. ACME clients such as certbot or caddy handle renewal automatically, which is why the industry pushed hard for automation.

How to choose

Start with a free DV certificate from Let’s Encrypt and automate renewal. If you run multiple subdomains, add a wildcard. If your business, payments or compliance require verified identity, upgrade to OV or EV from a commercial CA. Whatever you choose, verify the result with our SSL Checker after installation.

FAQ

Are free certificates as secure as paid ones?

Yes. DV, OV and EV certificates use the same TLS encryption. The difference is identity verification, not cryptographic strength.

What happens when a certificate expires?

Browsers refuse the connection and visitors see a security warning. Automate renewals with an ACME client to avoid the risk entirely.

Do I need a certificate for each subdomain?

No. Use a wildcard certificate (*.example.com) or a multi-domain certificate listing each name.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles