Key Takeaways
- Newfold Digital just picked DigiCert to handle SSL/TLS certificate issuance & fulfillment across its major hosting and domain brands.
- Starting in March 2027, public TLS certificates will be limited to 100 days in 2027 and just 47 days two years later.
- For hosting providers, keeping millions of certificates renewed is fast-becoming an automation problem.
Newfold Digital is officially putting its SSL/TLS certificate operation in DigiCert’s hands.
The web-hosting giant announced on September 10 that DigiCert will now handle certificate issuance and fulfillment across Newfold’s core, including Bluehost, HostGator, Network Solutions, Crazy Domains, and Register.com.
DigiCert will support standard certificate offerings, including domain-validation, organization-validation, extended-validation, wildcard, and multi-domain certificates. As for when this goes into effect: Existing certificates will remain active until they need to be renewed or reissued, and new purchases and renewals will move through DigiCert.
SSL Certificate Lifespans Are Shrinking Fast
From 5 years to 47 days: How TLS certificate validity has changed over time
“Hosting providers operate trust infrastructure at a scale most small businesses never see and should never have to manage themselves,” said Dave Packer, Chief Revenue Officer at DigiCert. “Newfold is taking a forward-looking approach by building on a platform designed to manage shorter certificate lifecycles at scale and adapt as AI and post-quantum cryptography reshape digital trust.”
For the millions of small businesses using those brands, this probably will not feel like much of a newsworthy story. Nobody wakes up excited to think about SSL certificates and most people only notice them when their browser throws a security warning at them.
But new rules from the CA/Browser Forum cut the validity period for public certificates to 200 days, down from 398 days. It’ll fall to 100 days in March 2027, and then to 47 days in March 2029. So, yeah: The old “set a reminder and deal with it later” approach is pretty much dead.
Do Shorter Certificates Mean More Work for Hosts?
Sure, it was not a great system to begin with, but when certificates could last more than a year, there was at least some room to be sloppy. If someone missed a renewal reminder, there was still a good chance they would catch it before the certificate expired.
When certificates eventually need to be replaced every few weeks, keeping up with them manually gets pretty ridiculous for hosts managing hundreds of domains. In fact, DigiCert found that more than one-third of organizations it surveyed had experienced an outage caused by an expired certificate.
It also is not as simple as clicking “renew” and moving on for hosts. The new certificate has to be issued, deployed wherever the site actually terminates TLS, loaded by the right services, and checked to make sure the live website is serving the new version. A renewal can look successful in an admin panel while one server, CDN edge, or load balancer is still delivering the old certificate.
One CA Could Rule the Back End
Newfold has accumulated a pretty long list of hosting and domain brands over the years, and that means there are a lot of different systems. From the customer’s perspective, it is all “just their hosting account.”
SSL certificate management is one place where providers can simplify some of that. Using one certificate authority (CA) should mean fewer moving parts for Newfold to deal with when it is time to renew a certificate. It should also make it easier to automate the process across all those different brands, which is good news for anyone using any of Newfold’s brands.
The Brands Behind Newfold’s 6 Million Customers
| Brand | Primary Offering | Region | Description |
|---|---|---|---|
| BigRock | Domains and hosting | India and international | Domain registration, web hosting, business email, and related online services. |
| Bluehost | Hosting and WordPress | International | Shared hosting, WordPress hosting, website tools, domains, and related services. |
| Crazy Domains | Domains, hosting, and web services | Australia and international | Domain registration, hosting, website products, email, and online business services. |
| Domain.com | Domains, hosting, and web services | International | Domain registration, website hosting, website-building tools, and related services. |
| HostGator | Web hosting | International | Shared, VPS, dedicated, and WordPress hosting, along with domains and website services. |
| iPage | Hosting and website services | International | Website hosting, domain services, website-building tools, and small-business web products. |
| Network Solutions | Domains, hosting, and web services | United States and international | Domain registration, hosting, website services, email, and small-business online solutions. |
| Register.com | Domains, hosting, and web services | United States and international | Domain registration, website hosting, email, website tools, and business web services. |
| ResellerClub | Reseller hosting and domains | International | Hosting, domains, and related products designed for resellers, agencies, and web professionals. |
Obviously, Newfold Digital is not the only hosting provider trying to figure out automatic SSL management. Shorter certificate lifespans are making it harder to put on the backburner like we used to, and outsourcing that work makes sense when you’re dealing with millions of domains.
But we’ve also seen plenty of examples this year of what happens when a shared piece of internet infrastructure has a bad day, from Cloudflare’s six-hour February outage to an AWS CloudFront incident in July that knocked some websites and services offline across multiple regions. The more you rely on one provider, the more you have to trust them. That’s a pretty big responsibility to hand over, even if most customers never notice the change.
