SSLCloakBuy short-lived cert

Short-lived TLS certificates, without the busywork

For privacy-obsessed engineers who hate long-lived certs: tight lifetimes, minimal data, and rotation-friendly tooling — instead of bloated one-year certificates and intrusive data collection.

How it works

1. Tell us your domainsYour primary domain becomes the certificate's Common Name. Add extra hostnames (SANs) for any additional subdomains or services the same certificate needs to cover.Learn more in Help →

Add your primary domain and any additional hostnames you need covered.

2. Provide or generate a CSRA CSR (Certificate Signing Request) proves you control the private key without ever sharing it with us. Already have one? Paste or upload it. Otherwise we show you the exact OpenSSL command to generate one.Learn more in Help →

Paste an existing CSR or follow our guided steps to generate one.

3. Get your certificatePick 7, 14, or 30 days for tight rotation, or 90–200 days if you want less overhead. After DNS or HTTP validation clears, your certificate is issued and ready to download immediately.Learn more in Help →

Choose a duration from 7 to 200 days, validate ownership, and download.

Why short-lived?

The CA/Browser Forum has already mandated the industry-wide shift: 200-day maximum validity as of March 2026, dropping to 100 days by March 2027 and 47 days by March 2029. What's a differentiator today becomes the mandatory default within three years — SSLCloak just lets you adopt tight rotation now, with a process that stays clear even if you're not running your own ACME automation.

Privacy, precisely stated

Certificate Transparency logs make the domain names in any publicly trusted certificate public, regardless of issuer — that's not something any provider can change. What we control is data minimization: no tracking, no unnecessary retention, and no upsells built on your usage data.

  • No tracking, no ad pixels, no data resale
  • Real, immediate erasure - delete an order or your whole account yourself, any time, no request or waiting
  • We never disguise who signs your certificate
  • No SMS-based two-factor authentication - it's the weaker option (SIM-swapping) and would mean collecting a phone number we don't need, so to maximize your privacy we don't offer it at all
Read the full privacy policy →

Pricing preview

Certificates start at $3.00 for a 7-day cert, plus a small per-hostname fee for multi-domain orders.

View full pricing calculator →

FAQ

Why would I want a short-lived certificate?
Shorter lifetimes shrink the window a compromised or misissued cert stays valid, and match where the CA/Browser Forum is taking the whole industry (200-day cap in 2026, 100-day in 2027, 47-day in 2029). We just make the rotation part painless today.
Whose certificates are these?
We issue through established, publicly trusted ACME certificate authorities (Let's Encrypt / ZeroSSL). SSLCloak is the ordering, automation, and rotation layer on top — we're not hiding who signs your certificate.
Why do you offer two different CAs instead of just one?
Redundancy you don't have to build yourself. If Let's Encrypt has an outage, or — in the worst case — a CA is ever removed from a browser's trusted root store, having ZeroSSL as a genuinely independent option (different issuing hierarchy, not a fallback that's secretly the same infrastructure) means you're not stuck waiting on one company. You pick per order, right up until you submit it, and can switch any time without creating a second account or losing your order history.
What data do you keep?
The minimum needed to issue, bill, and support your order. Certificate Transparency logs already make domain names in any publicly trusted cert public — our privacy commitment is about not collecting or retaining more than that.