Uptime

SSL expiry

Also called certificate expiry.

SSL expiry is the date a site's certificate stops being valid. After it, browsers show a full-page warning and many API clients refuse to connect.

How it is measured

Connect to the host on 443, read the leaf certificate's notAfter, and compute days remaining. Alert at 30, 14, 7, and 3 days. Check every hostname, including www, api, mail, and wildcard names, from outside your network.

Also verify the chain served: a renewed certificate with a missing intermediate fails on some devices. Compare the expiry the public sees with the one in your certificate manager.

Worked example

A boutique's Let's Encrypt certificate on shop.example.test is meant to renew at 30 days left. The 30-day alert fires on 14 February and everyone ignores it as auto-renew. The 7-day alert on 7 March gets a real look: the certbot timer was disabled during a server move. Renewal on 8 March takes 4 minutes.

Without the check, expiry would have hit on 14 March, a Saturday, with the shop's ad campaign live. Visitors would have seen Your connection is not private.

How it differs

SSL expiry is a date on the certificate. TLS certificate is the document itself, with its names, issuer, key, and chain. Expiry excludes problems such as name mismatch or weak keys. The certificate covers all of them.

Common errors

Trusting auto-renew. Checking only the apex. Forgetting subdomains and non-HTTP services such as SMTP. Alerting at 3 days only. Renewing but not reloading the web server. Checking the cert in the store instead of the one served.

In practice

List every hostname with a certificate and check each one remotely. Alert at 30 and 7 days to different people. After a renewal, reload and recheck the live site.

See also

TLS certificate, HTTP check

Sources

Count this on a real site.

Watch my website