SSL Expiry Is Predictable: How to Catch It on Client Sites
TL;DR
Every certificate carries its expiry date, so an expired one is a process failure, not a surprise. Auto-renewal still breaks: the site moved host, DNS changed, a renewal job stopped. Since 15 March 2026 public certificates last at most 200 days, falling to 47 days in 2029, and Let's Encrypt stopped sending expiry emails in June 2025. Check a certificate with one openssl command, and for many sites let a monitor read the date every day and warn you 30, 14, 7 and 1 day ahead. Baromio does exactly that: it reads the expiry date and issuer, from one location, and does not check the chain or ciphers.
Most outages arrive without warning. An expiring certificate is different: the expiry date is written into the certificate itself, months ahead. When that date passes, browsers replace the site with a full-page security warning.
It still happens to teams that should know better. On 3 February 2020 Microsoft Teams was down for a few hours because an authentication certificate had expired, as Microsoft confirmed at the time.
Why certificates still expire on client sites
Most client sites today get free certificates that renew automatically. Renewal is the part that fails, and it fails quietly. Common reasons:
- The site moved. DNS now points to a new host or a CDN, but the old server keeps trying to renew, or the new one was never set up to.
- The renewal job stopped. A server update, a changed PHP version or a full disk, and the cron job or ACME client no longer runs.
- The renewal worked, the server did not reload. The new certificate is on disk, the web server still serves the old one.
- Someone bought it by hand. A paid certificate from the client's former agency or the client's own account, renewed by whoever remembers.
- Hostnames nobody tracks.
wwwand the bare domain, a shop subdomain, a staging site: each can have its own certificate.
Two changes make this more likely, not less:
- Let's Encrypt stopped emailing expiry reminders on 4 June 2025. If renewal fails, nobody tells you unless you monitor it.
- Certificates are getting shorter. Under the CA/Browser Forum ballot SC-081, public TLS certificates issued from 15 March 2026 are valid for at most 200 days, from 15 March 2027 for 100 days and from 15 March 2029 for 47 days. Let's Encrypt certificates already last 90 days by default, with renewal recommended every 60. A certificate bought today can no longer last a year, so manual renewals come round at least twice as often.
Check a certificate by hand
For one site, this prints the expiry date and the issuer:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -enddate -issuer
-servername matters: a server hosting several sites picks the certificate by name. Run it for www.example.com too, and for every subdomain the client uses. In a browser, click the icon to the left of the address and open the certificate details.
A useful rule for Let's Encrypt certificates on the default 90-day cycle: renewal should happen when about 30 days remain. If a certificate is down to 14 days, renewal has most likely already failed. Do not wait for the 7-day warning.
Warnings you will actually act on
A warning 30 days out is easy to ignore, and one that arrives in the same channel as every other notification gets lost. Two habits help:
- Treat each stage differently. The 30-day warning is a note to check the renewal setup; the 7-day and 1-day warnings mean fix it today.
- Send the late warnings somewhere you read every day, not to a busy shared channel.
What Baromio checks
- What it reads: once a day, and shortly after you switch it on, Baromio connects to the monitor's host on port 443 (or the port in the URL) and reads the certificate's expiry date and issuer. The monitor page shows the issuer and "Valid until" with the days left; the monitor card shows the same count as an SSL badge.
- When it warns you: when 30, 14, 7 and 1 day remain, and once when the certificate has expired. Each stage alerts once, by email and to any Slack, Discord or webhook channel you have connected (Telegram on Pro and Business). A renewed certificate resets the stages.
- Where to switch it on: Monitor SSL Certificate on an HTTP or keyword monitor with an
https://URL, in Add New Monitor or Edit. It is off by default, including for monitors created by bulk import, so turn it on for each site. It is available on every plan: 20 monitors on Free, 30 on Pro (9 EUR a month), 100 on Business (29 EUR a month). - What it does not do: it does not validate the certificate chain, check that the name matches, test protocol versions or ciphers, or check from more than one location. It does not renew anything; the renewal stays with you or the host.
A short routine for client sites
- List every hostname for each client: bare domain,
www, subdomains, staging. - Put a monitor with the SSL check on each one that serves HTTPS.
- When a warning arrives for a certificate that should renew itself, find out why renewal failed; do not just renew by hand and move on.
- After moving a site to a new host or CDN, check the certificate the same day with the openssl command above.
Sources
- Engadget, Microsoft Teams went down because of an expired certificate, 3 Feb 2020.
- Let's Encrypt, Ending Support for Expiration Notification Emails, 22 Jan 2025: the service ended on 4 June 2025.
- Let's Encrypt, FAQ: default certificates are valid for 90 days, renewal recommended every 60 days.
- CA/Browser Forum, Ballot SC081v3, passed 11 Apr 2025.
- DigiCert, TLS certificate lifetimes will officially reduce to 47 days, 16 May 2025: the dated schedule (200 / 100 / 47 days).