Digital Certificates
These pages are produced and maintained by the ITS CSOL Certificates Team. If you have any questions, please send an email to
What is a Digital Certificate?
In the broadest terms, a digital certificate is block of cryptographic text that is used in many functions such as securing data transport or ensuring the identity or authenticity of sender or provider of information. Digital Certificates come a variety of types and formats to support various functions.
Current Status of the InCommon / Sectigo Certificate Manager Portal
As of August 1st, 2026, our transition from the previous InCommon/Sectigo Certificate Authority to the new InCommon/CERTInext Authority was successful.
All domains that end with *.utexas.edu are validated and certificates can be generated. Many other domains (including vanity domains) are still in the process of being validated. You can check the status of the domains (validated or pending) via this Splunk Dashboard: InCommon/CERTInext Domain Inventory & DCV Status.
Please contact ISO (security@utexas.edu) for any questions regarding domain validation.
Certificate Lifespan to move to a 47-day lifecycle in 2029.
Even before that date, the lifecycle period shortens:
IN EFFECT March 15, 2026: Maximum certificate lifespan reduced to
daysMultiExcerpt IncludeUPCOMING January 1, 2027: Maximum certificate lifespan reduced to 90 days. This is different from the industry announcement - our certificate authority (InCommon/CERTInext) has established this new time table.
March 15, 2027: Further reduction to 100 days
March 15, 2029: Enforcement of the 47-day maximum certificate lifespan
AUTOMATION is a MUST!! The digital certificates team is here to help!
NO ONE should be replacing certificates manually! You should have this process happening through self-implemented automation or proprietary application based automation process.
MONITOR: You should monitor certificates expiration dates! Plenty of internal tools to assist with that task, as well as internet tools for externally hosted servers and hists.
Button | Mosaic | |
SSL / TLS Certificate | Code Signing Certificates |
SSL or Secure Socket Layer and TLS (Transport Layer Security) certificates come in a private and public key pair. With this combination of keys, a web browser (client) that connects to a server can:
In web browsers, an established encrypted/secure connection will present as a padlock in the URL bar of the browser along with starting string of " Renewing CertificatesLooking to renew a certificate or update an existing one to extend it or make changes? Take a look here. | Code Signing Certificates are used to digitally sign software or files that are downloaded over the internet. The files are signed by the developer/publisher of the software. Their purpose is to guarantee that the software or file is genuine and comes from the publisher it claims to belong. They’re especially useful for publishers who distribute their software for download through third-party sites. Code signing certificates also act as a proof that the file hasn’t been tampered with since download. |
Button | Mosaic | Button | Mosaic |
Effective July 17, 2026, Client Certificates (also known as Digital IDs or Email Certificates) will no longer be provided as a centrally funded Common Good service. If you currently use a Client Certificate, or think you may need one in the future, click Learn More below for information about the change, available options, and next steps.
Client Certificates are digital credentials that verify the identity of a person or system. They are commonly used to digitally sign or encrypt email, authenticate users when accessing secure applications or services, and enable certificate-based or multi-factor authentication for sensitive systems.
Information, Knowledge, and Technical Articles Button | Mosaic |
Page Index
- (DC) CERTInext Platform
- (DC) How to …
- (DC) Renewal Reminder Tools
- (DC) Certificate Format Conversion
- (DC) Certificate Expiration Check
- (DC) Creating Certificate Signing Requests (CSR)
- (DC) [OS X] Signing and Encryption, using Apple Mail
- (DC) [OS X] Export / Back Up Client Certificates
- (DC) [OS X] Signing/Encryption using Outlook 2016
- (DC) [Windows] Back Up or Move Digital Certificate
- (DC) [Windows] Signing / Encryption using Outlook 2010/2013
- (DC) [Import] Digital Certificate (macOS)
- (DC) [Import] Digital Certificate (Windows 10/11)
- (DC) [Import] Client Certificate (Android OS)
- (DC) [Import] Digital Certificate (Linux)
- (DC) Decoding Certificates / Private Keys
- (DC) Knowledgebase (KB)
- (DC) Certificate Chain (Root and Intermediate)
- (DC) InCommon Certificate Chain Issue
- (DC) Managing Certificates
- (DC) Data Encryption Glossary
- (DC) Troubleshooting problems reading signed or encrypted email
- (DC) Educational Resources
- (DC) What is the ACME Protocol?
- (DC) ACME Error when requesting certificates
- (DC) Technical Articles
- (DC) SHA-2 versus SHA-1
- (DC) Sectigo Public Root CAs Migration (2025)
- (DC) Certificate Lifespans Shrinking
- (DC) Using 1Password w/ Automation
- (DC) SPLUNK Dashboards
- (DC) Which do I need?
- (DC) Code Signing Certificate
- (DC) SSL Certificates
- (DC) Client Certificate
- Links Page for Digital Certificates