SSL Certificates for UMB Systems
A guide to requesting and managing server certificates, including which certificate type to choose and how long it will last.
A guide to requesting and managing server certificates, including which certificate type to choose and how long it will last.
200 days is the current maximum, dropping to 100 days in March 2027 and 47 days in March 2029. See Certificate Validity Periods below for a full phase-out schedule.
InCommon is UMB's certificate provider, a higher-education-only service that gives the university unlimited TLS/SSL certificates under one institutional subscription. Certificates are requested and managed through InCommon's certificate portal at us.certinext.io.
The InCommon Certificate Service is available only to UMB system owners and IT staff requesting certificates for university-owned domains and servers. It is not a certificate option for personal or third-party sites. It's intended for anyone managing a UMB website, application, or server that requires a trusted TLS/SSL certificate, including departmental IT staff, system administrators, and researchers running grid or computing environments.
Note: UMB branding (Name, logo, and identity marks) may only be used on systems that are managed and supported on university-owned domains and servers.
Not sure what to request? For most systems, the default is an OV (Organization Validation) SSL Certificate.
|
Your Situation |
Recommended Certificate |
|
A single production website or service |
OV SSL Certificate (Standard profile) |
|
Multiple subdomains under one system (e.g. mail, portal, hr) |
OV SSL Certificate — UCC profile |
|
Payment processing or high-security login page |
EV SSL Certificate |
|
Non-sensitive development or test environment |
DV SSL Certificate |
Covering multiple subdomains? Request an OV SSL Certificate using the UCC profile and list each subdomain individually as a Subject Alternative Name (SAN).
UMB does not issue, support or permit the use of wildcard certificates (e.g., *.umaryland.edu) on any system, for any purpose.
Why this matters: A wildcard certificate uses a single private key to secure every current and future subdomain under a domain. If that one key is ever compromised, an attacker can impersonate any subdomain under it, including systems that don't exist yet, without needing a new certificate issued. This turns one key exposure into a university-wide risk instead of a single-system incident.
If you need to secure multiple subdomains, request an OV SSL Certificate using the UCC profile and list each subdomain explicitly as a Subject Alternative Name (SAN). This keeps each subdomain's trust independent, so a compromise of one does not expose the others.
If your system has a requirement you believe cannot be met without a wildcard certificate, contact DL-CITSCertificatesSupport@umaryland.edu to discuss your use case before proceeding.
Public Certificate Authorities are phasing in much shorter maximum certificate lifetimes industry-wide (this is not a UMB-specific policy). If you manage a server or service, you should have a plan for automated renewal.
|
Effective Date |
Maximum Validity |
Status |
|
March 2026 |
200 days |
Current maximum |
|
March 2027 |
100 days |
Upcoming |
|
March 2029 |
47 days |
Upcoming |
Move to automated renewal now. As maximum validity periods keep shrinking, manual certificate management will not be sustainable. If your system does not yet support automated renewal, start planning that migration today rather than waiting for the next deadline. For guidance on setting up automation, contact DL-CITSCertificatesSupport@umaryland.edu
Don't have a portal account yet? Contact DL-CITSCertificatesSupport@umaryland.edu to be registered before submitting a request.
Not sure which certificate fits your situation? Email us before submitting your request:
DL-CITSCertificatesSupport@umaryland.edu
601 W. Lombard St.
Suite 540
Baltimore, MD 21201
The University of Maryland, Baltimore is the founding campus of the University System of Maryland.
620 W. Lexington St., Baltimore, MD
21201 | 410-706-3100