Knowledge Base Article

How to Renew Your SSL Certificate Before Expiry | BuySSL.lk

Category: SSL Reissue & Renewal

Updated: Aug 10, 2026 SSL Reissue & Renewal

All commercial SSL certificates are issued with a maximum validity period of 1 year to comply with global browser security standards. Renewing your SSL certificate before its expiration date ensures that your website remains secure without experiencing browser "Not Secure" warnings or service interruptions.

This guide explains how to renew your SSL certificate, complete re-validation, and install the updated certificate via the BuySSL.lk Client Area

Step 1: Access Your Expiring SSL Certificate

  1. Open your browser and navigate to buyssl.lk.

  2. Enter your Email Address and Password, then click Log In.

  3. Access your expiring certificate using one of two methods:

    • First Method (Services Menu): Click Services > My Services from the top menu, then select your active SSL certificate.

    • Second Method (Unpaid Invoice): If BuySSL has already generated your renewal invoice, go to Billing > My Invoices and click on the pending renewal invoice.

Step 2: Pay the Renewal Invoice

  1. Review the renewal invoice details for your SSL certificate.

  2. Select your preferred Payment Method (Credit/Debit Card, Bank Transfer, Online Payment Gateway).

  3. Click Pay Now to complete the transaction.

  4. Once paid, the certificate status in your dashboard will update to allow configuration.

Step 3: Generate and Submit a CSR

To complete certificate reissue, you need a new Certificate Signing Request (CSR). You can generate one in two ways:

  • Method A (Via BuySSL Dashboard - Easy):

    1. Use the built-in CSR Generator tool available directly inside your BuySSL Client Area dashboard.

    2. Fill in your domain name, company details, and location to automatically generate your CSR and Private Key.

    3. Save your Private Key securely for installation later.

  • Method B (Via Your Hosting Server):

    1. Log in to your hosting server (cPanel, Plesk, IIS, or OpenSSL).

    2. Generate a fresh CSR for your domain name and copy the output text.

To Submit Your CSR:

  1. In the BuySSL Client Area, open your renewed SSL service.

  2. Click Configure Certificate.

  3. Paste the newly generated CSR into the designated text box, choose your web server type (e.g., cPanel / Apache or Microsoft IIS), and click Submit.

Step 4: Complete Domain Control Validation (DCV)

To verify domain ownership, choose one of the three standard validation methods:

  • Email Validation: Select an administrative email address (e.g., admin@yourdomain.lk or webmaster@yourdomain.lk) to receive a confirmation link.

  • DNS CNAME Record: Add a specific CNAME record provided in your dashboard to your domain's DNS management settings.

  • HTTP/HTTPS File Upload: Upload a small .txt file provided by the Certificate Authority (CA) to your website's /.well-known/pki-validation/ directory.

Note for OV / EV Certificates: The Certificate Authority will quickly re-verify your business registration details. If your corporate details have not changed since the last issuance, this verification process is usually completed rapidly.

Step 5: Download & Install the Renewed Certificate

  1. Once the CA issues the renewed SSL certificate, you will receive an email notification.

  2. Go to my.buyssl.lk > Services > My Services > click on your SSL certificate.

  3. Download the certificate files (.crt / .pem) along with the CA Bundle / Intermediate Certificate.

  4. Log into your hosting server/control panel and install the new certificate files over the old expiring certificate.