TLS Certificate Management

Welcome to the TLS Certificate Management tool. This is an application for IT professionals at Rutgers to manage TLS (SSL) certificate issuance for any domains used for University business.

Do you use TLS/SSL certificates at Rutgers?

Prepare for the upcoming reductions in certificate lifetime. Automate your certificate renewals with ACME. Use this tool to register an ACME account and learn how to set up automatic renewal.

Do you manage a domain name at Rutgers?

Prepare for more frequent DCV renewal requirements. A hands-free process for automatic domain control validation will be made available to domain managers with a one-time setup process. Please check back soon for updates.

This app is almost ready. Please check back soon!

Sign in with your NetID

Frequently Asked Questions

Expand/Collapse All

What is a TLS/SSL certificate? A TLS/SSL certificate is a digital document used by website and server operators to establish secure communications by proving the server's identity. Read more.
What are the upcoming changes to TLS/SSL certificate lifetimes? Certificate Authorities are reducing the maximum lifetime of publicly-trusted SSL/TLS certificates. The maximum duration will be reduced in three steps:
  • On March 15, 2026, the maximum lifetime was reduced to 200 days.
  • On March 15, 2027, the maximum lifetime will be reduced to 100 days.
  • On March 15, 2029, the maximum lifetime will be reduced to 47 days.
What is DCV? Domain Control Validation (DCV) is a process for proving that you control a particular domain name. Domain name managers must perform DCV in order to obtain publicly-trusted TLS/SSL certificates for a domain. Mechanisms for DCV include email, HTTP, and DNS.
What are the upcoming changes to DCV requirements? Certificate Authorities are reducing the maximum validity of Domain Control Validation (DCV). This means domain control will need to be re-validated more frequently than before. The maximum duration will be reduced in three steps:
  • On March 15, 2026, the maximum lifetime was reduced to 200 days.
  • On March 15, 2027, the maximum lifetime will be reduced to 100 days.
  • On March 15, 2029, the maximum lifetime will be reduced to 10 days.
What is ACME? Automatic Certificate Management Environment (ACME) is a protocol for issuance and renewal of TLS/SSL certificates. Designed to enable automation, ACME can also be used to manually request and renew certificates. Read more.
Who is this website for? This is a tool for university staff who use one or more TLS/SSL certificates at Rutgers and/or are responsible for managing one or more Rutgers domain names.
I manage a TLS/SSL certificate. How does this tool help me? This tool allows you to register an ACME account with a supported certificate vendor. The ACME account will be pre-authorized to create and renew certificates without further validation at time of issuance. This enables you to create and renew certificates automatically, and eliminates the need for you to validate the domain using DNS records or HTTP files. The domain must first be enrolled by the domain manager (see below).
I manage a domain name. How will this tool help me? This tool will perform Domain Control Validation (DCV) on your behalf, so you can create and renew certificates without editing DNS records or managing an HTTP validation process.
What Certificate Authorities are supported? At this time, this tool integrates with CertiNext. Licensed through InCommon, CertiNext is a universitywide provider for TLS/SSL certificates.
Do I have to use this tool? No. If you have an existing solution for automated certificate issuance as well as the associated DCV procedure, you might not need this tool.
Can I just use Let's Encrypt?

You can, but you should be aware of the Let's Encrypt Rate Limits.

In particular, note that the New Certificates per Registered Domain limit is applied at the domain name level. This means that certificates for yoursite.rutgers.edu and otherdepartment.rutgers.edu are counted against the same limit. This may prevent you from obtaining certificates as a result of certificate actions by other departments (which you cannot predict or control). This poses a risk of downtime for your website or service, especially with decreasing certificate lifetimes.

We do not recommend or support using Let's Encrypt for rutgers.edu certificates for this reason.

Can I use another certificate authority? You can, but you'll be responsible for performing domain validation and setting up any necessary automation. In light of decreasing certificate lifetimes and more frequent validation requirements, we strongly recommend automating domain validation and certificate renewals where possible. This may or may not be feasible with a third-party certificate authority, depending on your infrastructure and deployment details. In particular, consider whether and how you will be able to perform Domain Control Validation (DCV), and whether you can automate that process. Also consider any applicable policy constraints or rate limits (see Can I just use Let's Encrypt?).

Other questions?

The certificate vendor transition and lifetime decreases are big changes, but we're here to help. Please email ssl_support@oit.rutgers.edu if you have a question not listed here.