Uptime

Certificate expiry

The days-left number on each HTTPS monitor, and what to do when it turns amber.

An SSL certificate is what makes the padlock and https:// work. Certificates expire — free ones from Let's Encrypt last 90 days — and when one does, every visitor gets a full-page browser warning telling them your site is unsafe. Sales stop that minute.

Renewal is normally automatic. It also quietly stops working more often than anyone expects.

Where to see it

Every HTTPS monitor reads the certificate as part of its normal check and shows days left next to the monitor.

ColourMeaningDo
NormalMore than 30 daysNothing
Amber30 days or fewerCheck that automatic renewal is working
RedExpiredFix today. Visitors are already seeing warnings

Why automatic renewal stops working

Nearly always one of these:

  1. The renewal job was removed or disabled. Check Scheduled for a certbot job and look at what it logged last.
  2. The renewal check cannot reach the server. Renewal proves you control the domain by answering a request on port 80. A firewall change or an nginx config that redirects everything to HTTPS can break it.
  3. The DNS moved. The domain now points somewhere else, so the challenge fails.
  4. Disk full. Renewal cannot write the new certificate. Check the health card.
  5. The certificate was renewed but nginx was never reloaded, so it is still serving the old one. This one is invisible from the server and obvious from outside — which is exactly what this monitor catches.

Fixing it

Two guided tasks cover this end to end:

  • SSL certificate expired — diagnose and renew now.
  • Set up free SSL (https) — issue a certificate for a domain that has none, including the automatic renewal job.

See Guided tasks. Or ask in a chat: "the certificate for example.com expires in 12 days, check that renewal is working."

Certificates we cannot read

If a monitor shows no certificate information, the site is either plain HTTP, or behind something that terminates TLS elsewhere (a CDN or load balancer) — in which case the certificate you are shown is theirs, not your server's, which is still the one your visitors see.