SSL Certificates for UMB Systems

A guide to requesting and managing server certificates, including which certificate type to choose and how long it will last.

Certificate validity periods are being shortened across the industry. 

200 days is the current maximum, dropping to 100 days in March 2027 and 47 days in March 2029.  See Certificate Validity Periods below for a full phase-out schedule. 

What is InCommon?

InCommon is UMB's certificate provider, a higher-education-only service that gives the university unlimited TLS/SSL certificates under one institutional subscription.  Certificates are requested and managed through InCommon's certificate portal at us.certinext.io. 

Who This is For

The InCommon Certificate Service is available only to UMB system owners and IT staff requesting certificates for university-owned domains and servers.  It is not a certificate option for personal or third-party sites.  It's intended for anyone managing a UMB website, application, or server that requires a trusted TLS/SSL certificate, including departmental IT staff, system administrators, and researchers running grid or computing environments.

Note: UMB branding (Name, logo, and identity marks) may only be used on systems that are managed and supported on university-owned domains and servers. 

Choosing Your Certificate

Not sure what to request?  For most systems, the default is an OV (Organization Validation) SSL Certificate. 

Your Situation

Recommended Certificate

A single production website or service

OV SSL Certificate (Standard profile)

Multiple subdomains under one system (e.g. mail, portal, hr)

OV SSL Certificate — UCC profile 

Payment processing or high-security login page

EV SSL Certificate

Non-sensitive development or test environment

DV SSL Certificate

Covering multiple subdomains? Request an OV SSL Certificate using the UCC profile and list each subdomain individually as a Subject Alternative Name (SAN). 

Wildcard Certificates Are Not Permitted    

UMB does not issue, support or permit the use of wildcard certificates (e.g., *.umaryland.edu) on any system, for any purpose.

Why this matters: A wildcard certificate uses a single private key to secure every current and future subdomain under a domain. If that one key is ever compromised, an attacker can impersonate any subdomain under it, including systems that don't exist yet, without needing a new certificate issued.  This turns one key exposure into a university-wide risk instead of a single-system incident. 

If you need to secure multiple subdomains, request an OV SSL Certificate using the UCC profile and list each subdomain explicitly as a Subject Alternative Name (SAN). This keeps each subdomain's trust independent, so a compromise of one does not expose the others. 

If your system has a requirement you believe cannot be met without a wildcard certificate, contact DL-CITSCertificatesSupport@umaryland.edu to discuss your use case before proceeding.

Certificate Validity Periods

Public Certificate Authorities are phasing in much shorter maximum certificate lifetimes industry-wide (this is not a UMB-specific policy). If you manage a server or service, you should have a plan for automated renewal.

Effective Date

Maximum Validity

Status

March 2026

200 days

Current maximum

March 2027

100 days

Upcoming

March 2029

47 days

Upcoming

Move to automated renewal now.  As maximum validity periods keep shrinking, manual certificate management will not be sustainable.  If your system does not yet support automated renewal, start planning that migration today rather than waiting for the next deadline.  For guidance on setting up automation, contact DL-CITSCertificatesSupport@umaryland.edu

How to Request a Certificate

  1. Go to the certificate portal: us.certinext.io
  2. Log in using Single Sign-On (SSO) with your university credentials ** . 
    • Logging in: Once your account has been registered on the certificate portal, log in by choosing Single Sign-On (SSO) rather than creating a separate portal username and password.  You will be redirected to the university's standard login page to authenticate with your university credentials.
  3. When creating the certificate, select emSign as the certificate authority.
  4. Choose the certificate type using the guide above.
  5. Include the following in your request:
    • The fully qualified domain name (FQDN), or full list of subdomains if requesting a UCC certificate
    • The system owner and department
    • Whether automated renewal is configured
    • Any compliance requirements that apply (e.g., PCI-DSS, HIPAA)

Don't have a portal account yet? Contact DL-CITSCertificatesSupport@umaryland.edu to be registered before submitting a request.

Common Mistakes to Avoid

  • Using a basic (DV) certificate for a production system. DV certificates don't display your organization's name, which reduces user trust. Production systems should use OV or higher.
  • Requesting a certificate without automated renewal in place. As maximum validity periods shrink industry-wide, unmanaged certificates will expire more often and can cause an outage if renewal isn't automated.
  • Requesting a wildcard certificate. Not supported at UMB — request an OV SSL Certificate using the UCC profile instead, and list each subdomain individually as a SAN.
  • Requesting EV for internal tools. EV validation takes longer and is only needed where a higher visible trust indicator is required (e.g., public payment pages).

Questions

Not sure which certificate fits your situation? Email us before submitting your request:

DL-CITSCertificatesSupport@umaryland.edu