Expiring Certificates and Domains: Preventing Avoidable Outages

Some of the most embarrassing IT outages have a simple cause: something expired. A website suddenly shows a security warning, email stops flowing, a phone system cannot register, or staff cannot reach a clinical application because a certificate ran out overnight. Nothing was hacked and nothing broke, but a date passed and nobody was watching.

Expirations are among the easiest problems to prevent. All it takes is a list, an owner and reminders.

What expires

Domain names

Your domain registration, the right to use a name like yourfacility.org, is leased for a period, often one to ten years. If it lapses, your website and email can stop working, and someone else may register the name. The risk is real, and the consequences, such as lost email and phishing misuse of your brand, can be serious.

TLS or SSL certificates

Certificates prove that a website or service is genuine and enable encrypted connections. They have limited lifetimes, and the industry has been moving toward shorter ones. When a certificate expires, browsers and applications warn users or refuse to connect.

Certificates are used for public websites, patient or family portals, remote access gateways, email servers, VPNs, wireless authentication and internal applications.

Other things with expiration dates

Software subscriptions and support contracts

Security feature licenses on firewalls and other devices

Warranty and maintenance agreements

Cloud service plans

Code-signing certificates and API keys

Password and service account expirations used by applications

Email authentication records and the keys behind them, which may be rotated periodically

Why they get missed

The person who bought the item left the organization.

Renewal notices go to a former employee's mailbox or a spam folder.

Auto-renew fails because a payment card expired.

Certificates are installed in several places and one is forgotten.

No one is clearly responsible.

Step 1: Build the inventory

List every domain and certificate your organization depends on. Include:

The name or purpose

Where it is registered or issued

The expiration date

Where it is installed or used

Who is the owner, and who is the backup

How it is renewed, and whether renewal is automatic

The account and payment method tied to it

Check your domain registrar account, ask IT staff and vendors, and scan your known websites and services for certificate dates. Some tools can examine your public hostnames and report expiration, which also helps you find forgotten ones.

Step 2: Fix ownership and contact details

Register domains in the organization's name, not an employee's or a web developer's.

Use a role-based email address, such as a shared IT mailbox, for renewal notices, so messages survive staff changes.

Keep two administrators on registrar and certificate accounts.

Use a company payment method, and track its expiration date as well.

Enable registrar locks and multi-factor authentication to prevent unauthorized transfers.

Step 3: Automate where possible

Turn on auto-renewal for domains, and confirm that the payment method is valid.

Use certificate issuance and renewal automation if your systems support it. Automated renewal substantially reduces the chance of human error.

For certificates that cannot be automated, schedule specific renewal tasks.

Automation is not a substitute for monitoring, since renewals can still fail. Verify that new certificates are actually in place after a renewal.

Step 4: Set reminders and monitoring

Create calendar reminders at 90, 60, 30 and 7 days before each date.

Use a monitoring tool to alert when a public certificate is within a set number of days of expiring.

Review the list in a short monthly or quarterly meeting.

Escalate to a named manager if a renewal has not happened by a set date, such as 14 days before expiration.

Step 5: Plan the renewal process

Write a short procedure for each important certificate, since renewal often requires generating a request, installing the new file and restarting a service. Test it in a quiet period. Document who does what, so that renewal does not depend on one person's memory.

Step 6: After an expiration

If something does expire, treat it as a lesson. Restore service, then identify why alerts failed, update the inventory and add monitoring.

Why it matters in healthcare

Care organizations depend on connected systems, including pharmacy, labs, electronic records, family portals and remote access. An expired certificate can interrupt several of these at once, and downtime in a care setting affects residents and staff directly.

Let us help

UnityCare IT tracks domains, certificates and renewal dates as part of managed IT service so that the calendar, not an outage, drives renewals. If you do not have a list today, even a simple spreadsheet is a strong first step.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172