Skip to main content

Set the certificate validTo time

DigiCert sets certificate validity using specific UTC times to comply with RFC 5280, the CA/Browser Forum (CA/B Forum) Baseline Requirements, and Apple certificate requirements. Understanding how DigiCert sets these times explains why a certificate’s expiration date may appear one day earlier than expected.

Select the certificate validity period

When requesting or renewing a certificate, select the certificate validity period.

  1. On the certificate request form, find the Validity period section.

  2. Depending on the certificate type, one or more of the following options are available:

    • Standard validity period: Select one of the available validity periods for the certificate type.

    • Custom expiration date: Specify the calendar date when the certificate should expire.

    • Custom length: Specify the certificate validity in days, up to the maximum allowed for the certificate type.

  3. Submit the request.

Notice

Available validity periods depend on the certificate type, your account configuration, and current industry maximum validity requirements.

Product examples:

  • TLS certificates issued through DigiCert Annual Plan default to a 199-day certificate.

  • Code Signing certificates default to a one-year certificate and currently support a maximum validity of 459 days.

If you specify a custom expiration date or custom length, the value can’t exceed the maximum validity allowed for the certificate type. For example, when requesting a TLS certificate, you can’t specify a custom validity longer than 199 days.

What's next

When DigiCert issues the certificate, the validTo value determines when the certificate expires.

ValidFrom and validTo times

DigiCert configures certificates as follows:

  • validFrom: 00:00:00 UTC on the certificate start date

  • validTo: 23:59:59 UTC on the certificate end date

Industry standards define maximum certificate validity in seconds rather than calendar dates. Adding even one extra second increases the calculated validity by a full day, causing the certificate to exceed the maximum lifetime permitted by the CA/B Forum Baseline Requirements and Apple’s requirements.

Setting validTo to 23:59:59 UTC ensures the certificate remains valid through the end of the expiration date without exceeding the permitted validity period.

Example

The following example illustrates how DigiCert sets these values for a certificate issued on October 15, 2026, with a one-year validity period:

  • validFrom: October 15, 2026, 00:00:00 UTC

  • validTo: October 14, 2027, 23:59:59 UTC

The certificate validity is exactly 365 days.

Weekend and holiday end date adjustment

CertCentral no longer adjusts certificate expiration dates that fall on weekends or United States holidays.

If you want to avoid a certificate expiring on a weekend or holiday, use the Custom expiration date or Custom length options when requesting or renewing the certificate.