Uptime
Certificate expiry
The days-left number on each HTTPS monitor, and what to do when it turns amber.
An SSL certificate is what makes the padlock and https:// work. Certificates
expire — free ones from Let's Encrypt last 90 days — and when one does,
every visitor gets a full-page browser warning telling them your site is
unsafe. Sales stop that minute.
Renewal is normally automatic. It also quietly stops working more often than anyone expects.
Where to see it
Every HTTPS monitor reads the certificate as part of its normal check and shows days left next to the monitor.
| Colour | Meaning | Do |
|---|---|---|
| Normal | More than 30 days | Nothing |
| Amber | 30 days or fewer | Check that automatic renewal is working |
| Red | Expired | Fix today. Visitors are already seeing warnings |
Why automatic renewal stops working
Nearly always one of these:
- The renewal job was removed or disabled. Check
Scheduled for a
certbotjob and look at what it logged last. - The renewal check cannot reach the server. Renewal proves you control the domain by answering a request on port 80. A firewall change or an nginx config that redirects everything to HTTPS can break it.
- The DNS moved. The domain now points somewhere else, so the challenge fails.
- Disk full. Renewal cannot write the new certificate. Check the health card.
- The certificate was renewed but nginx was never reloaded, so it is still serving the old one. This one is invisible from the server and obvious from outside — which is exactly what this monitor catches.
Fixing it
Two guided tasks cover this end to end:
- SSL certificate expired — diagnose and renew now.
- Set up free SSL (https) — issue a certificate for a domain that has none, including the automatic renewal job.
See Guided tasks. Or ask in a chat: "the certificate for example.com expires in 12 days, check that renewal is working."
Certificates we cannot read
If a monitor shows no certificate information, the site is either plain HTTP, or behind something that terminates TLS elsewhere (a CDN or load balancer) — in which case the certificate you are shown is theirs, not your server's, which is still the one your visitors see.
