Certificate Validity Calculator
Calculate certificate security level, validity period recommendations, and certificate strength analysis.
About this calculator
This calculator estimates the real-world cryptographic strength of an RSA certificate and its signing hash, then reports whichever one is weaker as the certificate's overall security margin. Certificate Security is not simply half the RSA key length -- RSA's best known attack is the sub-exponential General Number Field Sieve, not brute force, so its strength doesn't scale linearly with key size the way a symmetric cipher's does. Instead this figure interpolates between the equivalence points published in Table 2 of NIST SP 800-57 Part 1 Revision 5, the federal government's own reference table for comparable cryptographic strength (nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf): a 2048-bit RSA key is treated as roughly 112-bit strength, 3072-bit as 128-bit, 7680-bit as 192-bit, and 15360-bit as 256-bit, with values outside that tabulated range extrapolated from the nearest segment's slope rather than a separately invented constant. Hash Collision Resistance, by contrast, genuinely is half the hash's output length -- that's the standard birthday-bound result for collision resistance, distinct from the (larger) preimage-resistance figure, and it scales directly with the SHA-256/384/512 selection.
Overall Security Level always takes the smaller of the two, since a certificate's real-world strength is bounded by its weakest cryptographic component, and Recommended Renewal Period is tiered off that same Overall Security Level figure rather than off the raw key length. It is then capped at the CA/Browser Forum's maximum public TLS certificate lifetime, which Ballot SC-081v3 stepped down to 200 days in March 2026 and steps down again to 100 days in 2027 and 47 days in 2029 -- so for a publicly-trusted certificate the calendar ceiling, not the key strength, is what actually sets your renewal cadence. Key Strength Status flags what the bit figure does not: RSA below 2,048 bits is below the NIST SP 800-131A and CA/Browser Forum minimum and no public CA will issue it, and below 1,024 bits it is factorable with commodity hardware regardless of what the extrapolated bit count says.
Inputs
Results
Overall Security Level
112 bits
Recommended Renewal Period
200 days
Key Strength Status
Acceptable — 112-bit strength, the current NIST transitional floor.
Figures current as of 2020. Source: NIST SP 800-57 Part 1, Revision 5, "Recommendation for Key Management: Part 1 – General", Table 2, National Institute of Standards and Technology
How to Use This Calculator
- Enter the certificate's RSA key length (Certificate Key Length) and the requested validity period in days.
- Select the Hash Algorithm the certificate is signed with (SHA-256, SHA-384, or SHA-512).
- Review Overall Security Level -- the weaker of the RSA key's NIST-equivalent strength and the hash's collision resistance -- since a chain is only as strong as its weakest link.
- Compare Certificate Security against Hash Collision Resistance to see which one is limiting Overall Security Level.
- Use Recommended Renewal Period as a starting point for renewal cadence, and treat Expiration Risk as this calculator's own relative 0-100 scale, not a published industry metric.
How the result changes with Certificate Key Length
| Certificate Key Length | Overall Security Level | Recommended Renewal Period | Key Strength Status |
|---|---|---|---|
| 1,024 | 80 bits | 90 days | DEPRECATED — below the NIST SP 800-131A / CA-Browser Forum 2048-bit minimum. |
| 1,536 | 96 bits | 90 days | DEPRECATED — below the NIST SP 800-131A / CA-Browser Forum 2048-bit minimum. |
| 3,072 | 128 bits | 200 days | Recommended — 128-bit strength or better. |
| 5,120 | 128 bits | 200 days | Recommended — 128-bit strength or better. |
What each input means
- Certificate Key Length
- RSA certificate key length
- Validity Period
- Requested certificate lifetime in days. Publicly-trusted TLS certificates are capped by the CA/Browser Forum at 200 days as of 2026-03-15, dropping to 100 days in March 2027 and 47 days in March 2029. Longer periods are only reachable on private/internal CAs.
- Hash Algorithm
- Hash algorithm used in certificate
How this is calculated
Formula
Security Level = min(Certificate Security, Hash Collision Resistance)Worked example, using the default values
- Identify Input ParametersCertificate Key Length = 2048, Validity Period = 200, Hash Algorithm = 0 = 3 input(s) provided
- Calculate Overall Security LevelOverall Security Level112 = 112
- Calculate Recommended Renewal PeriodRecommended Renewal Period200 = 200
- Calculate Certificate SecurityCertificate Security112 = 112
- Calculate Hash Collision ResistanceHash Collision Resistance128 = 128
Figures and sources
- Comparable security strengths for symmetric, RSA/DSA/DH (Table 2), and elliptic-curve algorithms (2020) — NIST SP 800-57 Part 1, Revision 5, "Recommendation for Key Management: Part 1 – General", Table 2, National Institute of Standards and Technology
Engine last updated . Checked against 4 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why doesn't Certificate Security just show half the key length in bits?
Because RSA security doesn't work like a symmetric cipher's brute-force keyspace. The best known attack against RSA is the General Number Field Sieve, a sub-exponential algorithm, so a 2048-bit RSA key provides roughly 112 bits of real security strength per Table 2 of NIST SP 800-57 Part 1 Revision 5 -- not 1024 bits, which is what a naive key-length-divided-by-two estimate would suggest.
Is Hash Collision Resistance calculated the same simplified way?
No, and for good reason: half the hash output length genuinely is the correct collision-resistance figure for a well-designed hash function, per the birthday-bound result in cryptography -- SHA-256 provides 128-bit collision resistance, SHA-384 gives 192-bit, and SHA-512 gives 256-bit. That's a different (smaller) number than the hash's preimage resistance, which equals its full output length.
Which figure actually limits Overall Security Level in practice?
At the calculator's default RSA-2048 with SHA-256, it's the RSA key: Certificate Security comes out around 112 bits versus SHA-256's 128-bit Hash Collision Resistance, so Overall Security Level tracks the RSA figure. You'd need roughly a 3072-bit key or larger before the hash algorithm becomes the limiting factor instead.
Does the Validity Period I enter change the security level?
No. Validity Period only affects Expiration Risk, this calculator's own relative 0-to-100 scale for how long the certificate stays valid -- it has no bearing on Certificate Security, Hash Collision Resistance, or Overall Security Level, which depend entirely on key length and hash algorithm.
How does Recommended Renewal Period respond to a longer Validity Period?
It doesn't -- Recommended Renewal Period is the shorter of two things: a key-strength tier (730 days at 128-bit-or-higher strength, 365 days at the 112-bit NIST minimum, 90 days below that) and the CA/Browser Forum's maximum TLS certificate lifetime, which is 200 days as of March 2026 and drops to 100 days in March 2027 and 47 days in March 2029. In practice the CA/B ceiling binds for every key size a public certificate would use, so a stronger key buys you security margin, not a longer certificate. Validity Period plays no role in the recommendation at all.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
RSA Key Strength Calculator
Calculate RSA key strength, equivalent symmetric key length, brute force time, and security margins.
Cryptography & SecurityHash Collision Probability Calculator
Calculate hash collision probability using birthday paradox. Find collision probability and birthday bound for hash functions.
Security ToolsCertificate Expiration Tracker Calculator
Plan SSL/TLS certificate lifecycle management: renewal workload, annual costs, risk scoring, and alert thresholds based on your certificate portfolio.
Cryptography & SecurityPassword Entropy Calculator
Calculate password entropy, brute force time, and security strength. Measure password complexity and cryptographic strength.
More in Technology & Computing.