Certificate renewal · Practical guide

How to check SSL certificate expiry and renewal

The certificate visitors receive is the one that matters. A hosting dashboard may show a successful renewal while a different certificate remains active on a CDN or load balancer. Check the public hostname and compare its validity dates before treating renewal as complete.

Read the validity window in context

CheckSSL shows the certificate validity dates and days remaining when those details are available. Its current rules flag certificates expiring within 30 days. That warning is a prompt to check renewal, not proof that renewal has failed: a short-lived certificate may be within that window during normal operation.

Read the trust and hostname findings alongside the dates. A certificate with time remaining is not enough to establish a verified connection. If details came from a diagnostic handshake, they describe an untrusted observation rather than a successful verification.

Treat renewal and deployment as separate checks

Automated renewal needs to complete early enough to recover from failure. Let’s Encrypt recommends automating renewals and deploying renewed certificates without manual intervention. Build your monitoring around the certificate actually served, not only the success of an issuance job.

Identify where visitors connect first. With a CDN in front of your site, the edge certificate and origin certificate have separate roles. Checking the public hostname tells you about the endpoint reached by the scan, not every internal connection in the infrastructure.

Reference: Let’s Encrypt: Integration guide

Investigate an old certificate after renewal

Compare the public result with the certificate expected in your hosting configuration. Check the selected virtual host, certificate file or managed certificate assignment. If several endpoints serve the hostname, confirm that deployment reached each of them.

Review the renewal job and deployment logs for the actual failure rather than repeatedly requesting a new certificate. A correct new certificate cannot help if the listener still points to the old one. After fixing the configuration, run a fresh public check.

Make the renewal check repeatable

Record the hostname, observed expiry and endpoint responsible for serving the certificate. Give the renewal process a clear owner so a warning has an actionable destination.

  1. Check the exact public hostname, including any www or service subdomain.
  2. Compare the served validity dates with your expected renewal result.
  3. Verify the automated renewal and deployment jobs, then check the public endpoint again.
  4. Use monitoring for future expiry; CheckSSL provides an on-demand snapshot and does not send renewal alerts.

Keep reading

Related guides