Environment
Legacy certificate management using WASUP and new certificate issuance methods.
Issue
As a user managing certificates with WASUP, I experience delays accessing the main page and am concerned about upcoming browser restrictions on certificate validity periods.
Resolution
We strongly recommend avoiding the use of WASUP for obtaining new certificates. Instead, use ACME or the InCommon Certificate Manager web app for new certificates. For those managing legacy certificates with WASUP, note the following:
- Access certificates via the link provided in the notification email for direct access.
- Be aware that WASUP requires manual requesting, installation, and renewal of certificates.
- Certificates currently can be valid for up to 398 days, with renewal notifications starting at 365 days.
- Starting March 15, 2026, browsers will reject certificates valid for longer than 200 days, with renewal notifications beginning at 180 days.
- In 2027, the maximum valid certificate duration will reduce to 100 days.
- By 2029, browsers will no longer accept certificates valid for more than 47 days, with renewal notifications starting at 30 days.
Plan to transition away from WASUP to avoid compatibility issues with browser certificate policies.
Additional Information
Need additional information or assistance? Contact the ITS Service Center.