Website security

Managed SSL Certificate Service

Managed SSL is not a stronger certificate. It is somebody else installing it, holding the expiry date and putting the replacement on the server before the old one runs out. If your host already does that for free, this page will tell you to keep your money.

Get Managed SSL Now Get help choosing

What managed SSL is, and what it is not

A certificate is a file. Managed SSL is the work around the file. What a certificate does, which type to buy and how to clear up mixed content afterwards are all on the SSL certificates page. This one is narrower: it is about who does the handling.

Split honestly, the service is three jobs, and only the first is the one people think they are paying for.

  • Installation. Getting the file onto the machine your site actually runs on, in the right place, and making the site serve it. A certificate bought at one company and a site hosted at another is where this goes wrong, which domain name versus web hosting untangles.
  • Watching. Holding the expiry date somewhere other than an inbox, and acting on it early rather than on the day.
  • Reinstallation. A renewed certificate is a new file. Issuing it is not installing it. The server keeps handing out the old one until somebody replaces it.

The third job is the one worth paying for. It is also the one most people assume is covered by the word renewal, and it is not.

If you have not decided which certificate you need yet, decide that first on the SSL certificates page. Managed SSL wraps around whichever one you buy. It is not a different grade of encryption.

Why the expiry date is the whole product

An expired certificate does not degrade. It stops.

There is no grace period. The moment the term ends, browsers stop trusting the file and show a full page warning that a visitor has to deliberately click through. Most people do not click through. They read it as a warning about you, back out, and take the next result in the list. A "not secure" label costs you some visitors. An expired certificate costs you nearly all of them.

It also fails everywhere at once, which is why the phone starts ringing.

  • Every page shows the warning, including whichever one your advertising is pointing at.
  • Forms stop submitting. Booking and payment tools loaded from another company refuse to run on a page the browser does not trust.
  • Anything talking to the site without a person watching, a supplier's system, an app, a feed, simply fails, and fails quietly.
  • If the same name covers your mail, mail programs start showing their own warnings. That reaches you as "our email is broken", not as a certificate problem.

It expires at the worst time by arithmetic, not bad luck

A certificate's term runs from the day it was issued, and the day it was issued is usually the day the site launched or the day of a rebuild. So the expiry date is the anniversary of a busy week, not of a quiet one. That is why so many of them lapse during a sale, a season or an event, and why it never feels like coincidence.

The other half of it is that nothing is watching. A site does not announce that it has gone untrusted. A customer does, usually the next morning.

Nothing is damaged by an expiry. No data is lost. The site is simply unusable until a valid certificate is installed, which makes it a strange kind of outage: completely preventable, and completely invisible until it happens. If you are in one now, work through the first hour when your site goes down.

Check whether your host already does this

Before anything else: a great many hosting plans now include a certificate that issues and renews itself at no extra cost. If yours does, and it covers the addresses people actually use, managed SSL is a purchase you do not need. Three ways to find out, quickest first.

  • Click the padlock in your browser and open the certificate details. It names the issuer and the expiry date. A short term, months rather than a year, usually means an automatic system is issuing it. That is good news, not a problem.
  • Open your hosting control panel and look for an SSL or TLS section. If your domain is listed with the word automatic beside it, the host is handling it. What cPanel is covers where to look if the panel is unfamiliar.
  • Ask the host in writing. The question to ask is specific: does my plan issue and renew a certificate for my domain and its www version automatically, with nothing required from me?

Where an automatic certificate quietly stops working

Automatic renewal is genuinely good, and it is not unconditional. It works by proving, every time, that the domain still points at that server. Which means:

  • DNS moved. Point the domain at a proxy, a page builder or a new host while the old hosting account still holds the certificate, and the check fails silently. The renewal never happens and nobody is told.
  • A name was added later. A shop, booking or portal subdomain created after the certificate was issued is often not covered by it. That address throws a warning while the main site looks fine.
  • There are two certificates. A site behind a proxy or a content network has one certificate visitors see and another on the origin server. Only one may be on anybody's list.
  • You bought the certificate separately. Organisation validated, wildcard and multi-domain certificates generally do not renew themselves the way a host's built-in one does.

Those four situations are what managed SSL is for. Not owning a certificate, which you may already do. The gap between a certificate existing today and one that is still valid next spring.

What the service actually does

  1. Establish what has to be covered

    Every address that reaches you: the plain domain, the www version, any subdomain serving a real page, and mail if it uses the same name. Getting this wrong is how a business ends up buying a second certificate three weeks later.

  2. Issue it and prove control of the domain

    A DNS record, a file on the server, or a reply to a message sent to a contact on the domain. Domain validation is quick. Organisation validation involves a person at the other end, so it gets started early rather than against a deadline.

  3. Install it where the site really runs

    On the hosting server, not at the registrar. If your domain sits at one company and your website at another, this is the step that gets done in the wrong place, and the symptom is that nothing changes.

  4. Force HTTPS and check more than the homepage

    Redirect the unencrypted version once, cleanly, then look at an interior page, a blog post and a form page. Mixed content hides on those, not on the front page.

  5. Hold the renewal date outside a mailbox

    A date in a system a person reads, and a contact address that belongs to your business rather than to whoever built the site. A reminder sitting in an account you no longer control is not a reminder.

  6. Reissue, reinstall, then confirm

    Before the term ends, not on the day it ends. Then load the live site and read the new expiry date off it. A certificate counts as renewed when the server is serving it, and not one step earlier.

Step six is the product. Everything above it is setup you do once.

Who should not buy it

This one has a large and common no attached, larger than most products on this site. Read the left column first.

Leave it alone if

  • Your host already issues and auto renews one. If it covers every address you use, that is the answer. Paying for managed SSL on top buys you nothing at all.
  • You are comfortable doing it yourself. Installing a certificate is not hard. If you have done it before and the renewal date lives somewhere other than an email you might miss, you have the whole service already.
  • Your site is built on a platform. Squarespace, Wix, Shopify and similar run the certificate themselves and give you nowhere to install one. There is nothing here to manage.
  • Your web company maintains the site under contract. Ask what that contract covers first. Two people watching one renewal date is how it ends up watched by neither.
  • Nobody can say where the site is hosted. Settle that before anything else, because access has to exist before anybody can install anything. Who actually owns your website is the place to start.
  • You are moving or rebuilding the site shortly. Do the move, then set the certificate up once on the server it will stay on.

Worth having if

  • Your hosting includes no certificate, or includes one that does not cover the names you actually use.
  • You bought a wildcard, multi-domain or organisation validated certificate, which does not renew itself unattended.
  • The renewal notice goes to an address nobody at your business reads.
  • The site takes bookings, orders or payments, so a morning of full page warnings is measurable money.
  • You have been caught by an expiry before and would rather it were somebody else's diary entry than yours.

Get Managed SSL Now Ask whether you need it

Two ways a watched certificate still lapses

Worth knowing whether you buy the service or run it yourself, because neither is a technical failure.

  • The reminder belonged to a person, and the person left. Renewal dates should be attached to a role or a company, never to one individual's inbox.
  • Automatic renewal was on, and the card on file expired. A different date going stale, the same outcome. The same trap catches domains, which is on what happens when a domain expires.

How AldoMedia helps

AldoMedia, LLC. has been building and maintaining websites for Western New York businesses since 1999, and is an independent authorised reseller for the certificates sold here rather than the operator of the underlying platform. The managed part is deliberately unglamorous: decide what needs covering, issue it, install it on the right server, force HTTPS, clear the mixed content, then keep the renewal date somewhere it cannot quietly go stale.

It also means telling you when not to buy. If your hosting already issues a certificate that renews itself and covers your addresses, that is the answer, and it costs nothing to hear it. Call 716-771-2536 and tell us what your browser is showing, or start with the support pages.

Common questions

Managed SSL questions

What does managed SSL actually include?

Three jobs around the certificate rather than a different certificate. Installing it on the server your site really runs on and forcing HTTPS, holding the expiry date somewhere other than a mailbox, and issuing and installing the replacement before the current term ends. The encryption is identical to any other certificate of the same type.

My host already gives me a free certificate that renews itself. Do I need managed SSL?

Probably not, and that is a real answer rather than a polite one. If the automatic certificate covers every address people use to reach you, including the www version and any subdomain, it is doing the whole job. Check the padlock in your browser for the issuer and expiry date, then leave it alone.

I paid the renewal invoice and my site still shows a warning. Why?

Because renewing issues a new file and installing it is a separate step. Until somebody puts the new certificate on the server, the server keeps handing visitors the expired one. This is the single most common way a paid up certificate still takes a site down, and it is what a managed service exists to prevent.

Does my site go offline while the certificate is replaced?

No. The old certificate keeps working right up to the moment the new one is installed, so there is no gap to plan around and no reason to do it at midnight. The visible change is the expiry date, which you can read yourself by clicking the padlock afterwards.

How would I know my certificate is about to expire?

By checking, not by being told. Notices go to whatever address sits on the account, which is often a former designer's inbox or a role address nobody reads. Click the padlock in your browser and read the expiry date off your own live site. That is the only version that counts.

Related guides and services

SSL Certificates

The parent guide: what the padlock proves, which validation level you need, and clearing mixed content.

Read the SSL guide

What Happens When a Domain Expires

The same failure with a different renewal date, and the one that also takes your email with it.

Read about domain expiry

The First Hour When Your Site Goes Down

What to check, in order, when the site is throwing warnings and you do not yet know why.

Work through the first hour

Website Security

The other half of the job: updates, malware scanning and backups you have actually tested.

How website security works

Put the expiry date somewhere it cannot be forgotten

Tell us your domain and who hosts the site. If your host already issues a certificate that renews itself, we will tell you to keep your money.

Get Managed SSL Now Get help choosing