Your SSL certificate renews automatically. What if it does not?
Renewal can fail because of DNS, permissions or configuration. Monitor the certificate visitors actually receive.

Certificates are often renewed automatically today. That simplifies operations considerably, but it does not eliminate failure. A proxy, DNS or permission change can quietly stop renewal. Expiration then becomes visible only when someone visits: a browser warning or a rejected API connection.
Check the certificate on the public connection
A new certificate can exist on disk while the proxy continues serving the old one. External checks should inspect the certificate presented to the client for a specific hostname. Monitor its validity dates, name match and trusted chain. With multiple entry points, verify that the update reaches every one.
Include subdomains, APIs and less frequently used services. The main website's certificate may not cover every address. Wildcards have a defined scope too; they do not imply coverage at arbitrary subdomain depths.
Renewal depends on successful domain validation
HTTP-01 requires validation content to be available at the expected HTTP path; DNS-01 requires the correct TXT record. Changes to firewalls, routing or DNS API permissions can interrupt this process. Inspect the result of the last renewal rather than merely checking that the automation service is running.
Restrict DNS validation tokens to the permissions they need. Store them outside the repository and track their validity. Credential rotation should include a renewal test so a failure does not remain hidden until the certificate's last days.
Leave enough time to fix the problem
Set more than one advance warning and assign a clear owner. Choose the number of days based on certificate lifetime and team operations. The margin must accommodate a weekend or holiday. An alert a day before expiration often leaves too few options.
Verify deployment after renewal
Successful issuance does not necessarily mean successful deployment. Confirm that the proxy or web server loaded the certificate, then perform a public test. Record the hostname and next expiry date with the result. In automation, distinguish issuance failures from deployment failures.
- Did the last renewal succeed?
- Does the client receive the new certificate and complete chain?
- Does the certificate cover the correct hostname?
- Will the owner receive a warning early enough to act?
What to take away
Automatic renewal and external monitoring complement each other. One obtains the certificate; the other verifies that the service actually presents it and leaves time to act when something fails.


