SSL certificates and HTTPS
HTTPS with automatically renewed SSL certificates protects every connection to your website. Expiry dates are monitored continuously.
Invalid certificates
Without a valid certificate, browsers show warnings, forms are flagged as insecure and visitors leave.
Automatic renewal
Public certificate lifetimes are falling step by step, to 47 days by 2029. Renewal therefore runs automatically via the ACME protocol, for example with Let's Encrypt.
Secure configuration
TLS 1.3 and 1.2 only
current cipher suites with forward secrecy
HSTS, which makes browsers use HTTPS only
HTTP requests and domain variants redirected to HTTPS
no unencrypted content on HTTPS pages
Choosing the right certificate
A domain-validated certificate is enough for most websites. Extended certificates cost more without stronger encryption and only make sense if policies or customers require them.
Internal systems, interfaces and mail servers are monitored as well.
Approach
We harden the existing configuration and automate renewal and monitoring for all domains and subdomains.