Certificate renewal · Practical guide
How to check SSL certificate expiry and renewal
The certificate visitors receive is the one that matters. A hosting dashboard may show a successful renewal while a different certificate remains active on a CDN or load balancer. Check the public hostname and compare its validity dates before treating renewal as complete.
Read the validity window in context
CheckSSL shows the certificate validity dates and days remaining when those details are available. Its current rules flag certificates expiring within 30 days. That warning is a prompt to check renewal, not proof that renewal has failed: a short-lived certificate may be within that window during normal operation.
Read the trust and hostname findings alongside the dates. A certificate with time remaining is not enough to establish a verified connection. If details came from a diagnostic handshake, they describe an untrusted observation rather than a successful verification.
Treat renewal and deployment as separate checks
Automated renewal needs to complete early enough to recover from failure. Let’s Encrypt recommends automating renewals and deploying renewed certificates without manual intervention. Build your monitoring around the certificate actually served, not only the success of an issuance job.
Identify where visitors connect first. With a CDN in front of your site, the edge certificate and origin certificate have separate roles. Checking the public hostname tells you about the endpoint reached by the scan, not every internal connection in the infrastructure.
Reference: Let’s Encrypt: Integration guide
Investigate an old certificate after renewal
Compare the public result with the certificate expected in your hosting configuration. Check the selected virtual host, certificate file or managed certificate assignment. If several endpoints serve the hostname, confirm that deployment reached each of them.
Review the renewal job and deployment logs for the actual failure rather than repeatedly requesting a new certificate. A correct new certificate cannot help if the listener still points to the old one. After fixing the configuration, run a fresh public check.
Make the renewal check repeatable
Record the hostname, observed expiry and endpoint responsible for serving the certificate. Give the renewal process a clear owner so a warning has an actionable destination.
- Check the exact public hostname, including any www or service subdomain.
- Compare the served validity dates with your expected renewal result.
- Verify the automated renewal and deployment jobs, then check the public endpoint again.
- Use monitoring for future expiry; CheckSSL provides an on-demand snapshot and does not send renewal alerts.
Keep reading
Related guides
How to troubleshoot an SSL certificate name mismatch
Understand hostname coverage, wildcard limits and why an HTTPS redirect cannot fix a certificate for the wrong name.
Read guide Certificate trustSSL certificate chain errors: what to investigate
Understand leaf, intermediate and root certificates, and investigate a failed trust check without guessing the cause.
Read guide