Uptime
SSL expiry
Also called certificate expiry.
SSL expiry is the date a site's certificate stops being valid. After it, browsers show a full-page warning and many API clients refuse to connect.
How it is measured
Connect to the host on 443, read the leaf certificate's notAfter, and compute days remaining. Alert at 30, 14, 7, and 3 days. Check every hostname, including www, api, mail, and wildcard names, from outside your network.
Also verify the chain served: a renewed certificate with a missing intermediate fails on some devices. Compare the expiry the public sees with the one in your certificate manager.
Worked example
A boutique's Let's Encrypt certificate on shop.example.test is meant to renew at 30 days left. The 30-day alert fires on 14 February and everyone ignores it as auto-renew. The 7-day alert on 7 March gets a real look: the certbot timer was disabled during a server move. Renewal on 8 March takes 4 minutes.
Without the check, expiry would have hit on 14 March, a Saturday, with the shop's ad campaign live. Visitors would have seen Your connection is not private.
How it differs
SSL expiry is a date on the certificate. TLS certificate is the document itself, with its names, issuer, key, and chain. Expiry excludes problems such as name mismatch or weak keys. The certificate covers all of them.
Common errors
Trusting auto-renew. Checking only the apex. Forgetting subdomains and non-HTTP services such as SMTP. Alerting at 3 days only. Renewing but not reloading the web server. Checking the cert in the store instead of the one served.
In practice
List every hostname with a certificate and check each one remotely. Alert at 30 and 7 days to different people. After a renewal, reload and recheck the live site.