Aller au contenu principal

Guides / monitoring

How to Monitor SSL Certificate Expiration

A Certificate expiration monitor connects to a TLS endpoint on a fixed schedule and reads back the server certificate's expiration date, so you find out weeks ahead of a lapse instead of when a browser starts showing visitors a warning page. It is one of HostTracker's "set it and forget it" check types: no request body, no response rule, no location picker. Enter a host and you are done. Pick this type when what you manage is the certificate, such as a Let's Encrypt renewal job or a purchased cert from a CA, rather than the domain registration itself. The comparison with domain expiration monitoring is further down, since the two are the pair of check types readers confuse most often.

Main Settings

Main Settings panel for a Certificate expiration monitor showing the Monitoring enabled toggle, a How this check works info link, a Tags field, and Full Log / Open Stats switches, with a summary reading enabled, every 6h

Two fields sit above this panel, and the panel itself holds four more:

  • Domain / IP - the host to connect to over TLS. Enter a bare domain or IP; port 443 is assumed unless you add one explicitly, for example example.com:8443 for a certificate served on a non-standard port.
  • Name (optional) - a short label for this monitor in alerts, reports, and your dashboard. Leave it blank and HostTracker falls back to the domain.
  • Monitoring enabled - pauses or resumes the check without deleting it. Turn it off ahead of a planned certificate swap so a brief gap between the old and new cert does not fire a false alert.
  • How this check works - a collapsed info note explaining the mechanics: the check connects over TLS and reads the certificate's expiration date, on a fixed schedule of every 6 hours from HostTracker's own monitoring network. There is no interval slider for this type; see below for why.
  • Tags - free-text labels for filtering and grouping this monitor on your dashboard.
  • Full Log - saves every individual check result instead of grouping consecutive identical ones. Turn it on for a complete history rather than just state changes.
  • Open Stats - generates a public, shareable stats page for this monitor. Leave it off for an internal or non-public host.

Why 6 hours and not a minute-scale interval: a certificate's expiration date does not move between checks. It only changes when someone issues a new one. Polling every few minutes would repeat the same answer for no benefit; checking four times a day is still fast enough to catch a botched renewal within the same business day. You also do not need to configure a lead time to get ahead of an expiration: HostTracker automatically sends an informational reminder at 30, 7, and 1 day before the certificate's expiration date, to every contact you have given an Up subscription below (every channel except voice calls, which are reserved for real downtime). Those reminders are separate from a Down alert. A certificate that is still valid but approaching expiry is a reminder, not a failure; the check only goes Down once the certificate has expired.

Alert Subscriptions

Alert Subscriptions panel with a Subscribe all contacts to Up/Down events toggle and a contact list showing Down, Up and Repeat columns

This is the same subscriptions panel every check type uses. Toggle Subscribe all contacts to Up/Down events to put every contact on your account onto both events at once, or use the search box and the per-contact Down / Up / Repeat switches to build a specific list:

  • Down - notified when the certificate has expired.
  • Up - notified when a check recovers after a Down (a new certificate was installed), and, for this check type specifically, is also who receives the automatic 30/7/1-day expiry reminders described above.
  • Repeat - keeps sending the Down alert on a schedule while the certificate stays expired, instead of alerting once and going quiet.

An expired public-facing certificate is the kind of failure that costs trust the moment a visitor's browser shows the warning page, so leaving this section empty defeats the point of the check. It records the expiration and tells nobody.

Report Subscriptions

Report Subscriptions panel with a Subscribe all contacts to Weekly/Monthly reports toggle and a contact list showing Daily, Weekly and Monthly columns

Reports are periodic summaries rather than event-driven alerts, useful if someone on your team wants a standing weekly or monthly digest of certificate health rather than being paged the moment something expires. They go to email contacts only. Leave this off if Alert Subscriptions above already covers who needs to know.

Worked example

You run a checkout page on pay.example.com behind a certificate that renews automatically via Let's Encrypt, but you have been burned before by a renewal job that failed without telling anyone. Create a Certificate expiration monitor for pay.example.com, leave Monitoring enabled on, add the tag payments, and subscribe your on-call email and Slack contacts to Up and Down (Up so they also get the 30/7/1-day reminders). Skip Full Log unless you want a complete per-check history. For a check that changes state maybe twice a year, the grouped view is easier to read. Nothing else to configure: the check runs every 6 hours from here on, and you will hear about a slipping renewal three separate times before it becomes an outage.

Troubleshooting

  • The monitor shows Down but the site loads fine in a browser. Browsers cache certificates and often tolerate a chain issue that a fresh TLS handshake will not. Confirm with the free SSL check tool from a clean session, or check whether the certificate on that exact host:port has changed.
  • You added a port but the check still connects on 443. The port has to be part of the Domain / IP field itself, written as host:port. There is no separate port field for this check type.
  • No reminder arrived at 30 or 7 days out. Reminders go only to contacts with an Up subscription on this specific monitor. Check that box first, then confirm the contact's channel is not voice call, which never carries these notices.
  • You renewed the certificate but still see a stale expiration date. The check runs on its own 6-hour schedule and is not tied to your deployment; wait for the next scheduled run, or open the monitor and use its check-now action if your plan includes one.
  • You meant to monitor the domain registration, not the certificate. Wrong check type; see the next section.
  • All monitoring guides - the hub for every HostTracker check type.
  • How to check an SSL certificate expiry date - the one-off version of this check, by browser and by command line.
  • Domain and TLS checks - the product page covering both certificate and domain expiration monitoring, including the full 30/7/1-day reminder ladder and how it differs from a real Down alert.
  • Free SSL check tool - a one-off certificate check with no account needed, useful for confirming what a monitor is reporting.
  • Domain expiration guide - the check for a lapsed registration, a different failure with a different owner.
  • HTTP check guide - certificate expiration is also available as an attached tile on an Http, Port, or API monitor, riding along with that check instead of running as its own separate monitor.

Check it now

Run the free check against your own site - no account needed.

SSL check

Monitor this permanently

Get alerted the moment it breaks: HostTracker checks from 300+ locations and notifies you by email, SMS, Slack, Telegram and more.

HostTracker features