SSL/TLS & Transport
critical Severity
Free Check
SSL Certificate Expiry Monitoring
Tracks certificate expiration dates and triggers alerts before certificates lapse, avoiding browser security warnings.
Why It Matters
An expired certificate causes immediate full-screen security warnings, destroying user trust and dropping web traffic.
How We Check This
We parse the peer certificate validity dates and calculate days remaining until expiration (warning below 30 days, critical below 14 days).
How to Fix & Implement
Copy-paste configuration blocks tailored for your web server or edge proxy.
nginx snippet
certbot renew --dry-run # Set up automated Let's Encrypt cron renewal
Frequently Asked Questions
How often should SSL certificates renew?
Modern certificates have a maximum validity of 398 days (and standard Let’s Encrypt renews every 60–90 days).