The HTTPS Lifecycle of a Domain: What NNS SSL Automation Does

3 days ago

Day One: The Domain Is Bound

A customer adds a primary domain, subdomain, or alias domain. Being bound means the website accepts the name, but it does not yet prove the domain is ready for certificate validation.

NNS SSL Automation reads the website's current domain set instead of relying on an old list saved at activation.

DNS Check: Certificates Are Not Issued Without Validation

The domain must point to the current node before ownership can be validated.

Correct domains enter certificate processing. Incorrect or pending domains wait without preventing other valid domains from completing HTTPS.

Installation: HTTPS Takes Over Only When Ready

Automatic HTTP-to-HTTPS redirection is enabled only after the certificate is successfully issued and installed.

Reversing this order would send visitors to HTTPS before HTTPS is available.

Day Ten: A New Domain Is Added

The entitlement does not process only the domains present on activation day.

NNS reads the updated bindings. A valid new domain enters the certificate, while a pending domain waits without affecting existing HTTPS domains.

Day Twenty: The Primary Domain Changes

The old certificate domain set no longer represents the current website.

NNS recalculates the certificate using the current primary, complimentary, subdomain, and alias bindings. Removed domains leave future processing, and new valid domains enter it.

One Day: The Certificate Becomes Invalid

A certificate may be missing, damaged, incomplete, approaching expiration, or no longer valid.

Inspections check whether the certificate works now, not whether installation succeeded once. A detected failure starts reissuance and installation.

After Website Migration

The SSL entitlement belongs to the hosting service, not the old node.

After migration or offsite recovery, certificates are processed using the new node and current domains without another purchase.

When Does a Customer Receive the Entitlement?

The service page shows the current SSL Automation status and available activation method. When direct activation is available, confirmation grants the entitlement immediately. When payment is required, processing begins automatically after payment.

No SSL invoice is forced before the customer chooses to activate it. The entitlement provides continuous automation for the hosting service, not one individual certificate.

Current Boundary: Ordinary Domain Automation

NNS SSL Automation covers ordinary domains that are actually bound and can be validated.

Wildcard certificates require ongoing control of DNS validation records and are outside this scope.

“Installed” Is Not the End of HTTPS

Domains change, certificates expire, and websites move. Valuable automation keeps HTTPS working after those changes.

NNS SSL Automation manages the full HTTPS lifecycle from first binding through long-term operation.