My Tool Studio
Webmaster & Network·4 min read

Reading an SSL Certificate: Expiry, Chain and Names

Certificates do not fail gradually. One works for months, then at a precise second it expires and every visitor meets a full-screen browser warning instead of your site. Learning to read a certificate before that moment takes about five minutes. The issuer, subject, validity dates and protocol each answer a specific question, and together they tell you whether HTTPS is healthy, close to expiry, or misconfigured in a way that only some devices will notice.

SSL certificateFoundIssuerLet's EncryptValid2026-01-04Expires2026-04-04StatusValid

When reading the certificate stops being optional

Usually at the worst time.

The triggers are predictable. A renewal email arrives for a certificate you thought was automated. A customer sends a screenshot of a connection-not-private warning you cannot reproduce. A security scan flags an old TLS version. Or you have just installed a new certificate and need proof the server is actually sending it.

In every case, the truth is whatever the server presents during a live handshake, not what the control panel claims. SSL Certificate Checker opens a TLS connection on port 443 and shows the issuer, subject, valid from and valid to dates, TLS version and SHA-1 fingerprint, with a days-remaining banner on top. Each field has a copy button. If the handshake fails, you get a plain-English diagnosis instead: expired, name mismatch, missing intermediate, self-signed, not yet valid, or nothing listening on port 443.

A certificate with 30 days left, walked through

A worked example.

Check example.com and imagine an amber banner showing 29 days remaining, with Issuer: Example CA Intermediate R4, Subject: CN=example.com, Valid from about sixty days back, Valid to about a month ahead, and Protocol: TLSv1.3.

The banner turns amber under 30 days and red under 7. A start date sixty days ago on a ninety-day lifetime says this is an automated short-lived certificate, so the real question is why the renewal job has not already replaced it. Healthy automation usually renews with about a month to spare. TLSv1.3 confirms a modern server setup. Nothing is on fire, but this result deserves a look at the renewal logs today. Copy the fingerprint too: after the renewal, a new fingerprint is the quickest proof the server is sending the new certificate.

Chain problems: fine on your laptop, broken on Android

The invisible failure.

Browsers do not trust your certificate directly. They trust a root authority, which signed an intermediate, which signed your certificate, and the server is supposed to send the intermediate during the handshake. Leave it out and you get a familiar split: your desktop browser fills the gap from its cache and shows a padlock, while older Android devices, apps and API clients fail.

That split is the tell. If curl or a mobile app rejects a connection your laptop accepts, suspect the chain first. The checker connects from our server with no browser cache to lean on, so a missing intermediate shows up as a failed check with that diagnosis. The fix is to install the full chain or bundle file from your certificate provider, not the site certificate alone, then reload the web server.

Which names a certificate actually covers

Read the fine print.

A certificate is valid for an exact list of names, stored in its Subject Alternative Name entries, and nothing outside that list. A certificate for example.com does not automatically cover www.example.com. It only works when both names are listed, which most issuers handle by default but manual setups sometimes miss.

Wildcards have their own limits: *.example.com covers shop.example.com but not example.com itself, and not deeper names like api.eu.example.com. A successful result means the hostname you entered matched, and a name mismatch error means it did not. To read every listed name, press Load from CT logs in the checker, which pulls the certificate's SAN list from public Certificate Transparency logs, or open the padlock in your browser. When a subdomain throws a mismatch warning, check that exact hostname, since each subdomain can have its own certificate.

SSL certificate mistakes that end in outages

The same failures account for most HTTPS incidents:

  • Renewing the certificate but never reloading the web server, so the old one keeps being served until it expires.
  • Installing the site certificate without its intermediate bundle, which breaks every client that has no cached copy of the chain.
  • Watching only the main domain while a separately issued certificate on an API or shop subdomain lapses unnoticed.
  • Assuming automation worked without checking. A renewal job that has been failing for eighty days looks the same as a healthy one until day ninety.
  • Testing from a single browser and calling it done, which is exactly the test that chain problems pass.

Keeping ahead of certificate expiry

Make it a rhythm.

Staying ahead of expiry needs less machinery than people assume. Start with a list of every hostname that serves HTTPS and check each one monthly, because forgotten subdomains with their own certificates cause a large share of surprises.

After every renewal, check the live host and confirm the valid to date moved and the fingerprint changed. That catches the renewed-but-not-reloaded failure on the spot. And treat amber on an automated certificate as an alarm rather than a countdown, since healthy automation renews early and lateness means the job is broken. Note that the checker only connects on port 443, so services on other ports need a separate check.

SSL Certificate Checker beside the related tools

Adjacent questions, adjacent tools.

The certificate answers the trust question, but HTTPS health has neighbours. HTTP Header Checker includes strict-transport-security in its security checklist, the header that keeps browsers from trying plain HTTP against your domain. Website Uptime Checker shows SSL days left alongside its up or down verdict, which suits a quick daily glance.

For a name mismatch mystery, DNS Lookup shows whether the hostname points where you think it does, and its CAA records list which certificate authorities may issue for the domain. When a certificate on a domain you are evaluating looks freshly issued, WHOIS Lookup tells you whether the domain itself changed hands recently.

Try it now

Open SSL Certificate Checker

The tool is one click away. No sign up, no upload, no payment.

Open SSL Certificate Checker