Your SSL certificate renews automatically. What if it does not?

Renewal can fail because of DNS, permissions or configuration. Monitor the certificate visitors actually receive.

A laptop on a dark desk with its screen illuminated
Photography: Ales Nesetril / Unsplash

Certificates are often renewed automatically today. That simplifies operations considerably, but it does not eliminate failure. A proxy, DNS or permission change can quietly stop renewal. Expiration then becomes visible only when someone visits: a browser warning or a rejected API connection.

Check the certificate on the public connection

A new certificate can exist on disk while the proxy continues serving the old one. External checks should inspect the certificate presented to the client for a specific hostname. Monitor its validity dates, name match and trusted chain. With multiple entry points, verify that the update reaches every one.

Include subdomains, APIs and less frequently used services. The main website's certificate may not cover every address. Wildcards have a defined scope too; they do not imply coverage at arbitrary subdomain depths.

Renewal depends on successful domain validation

HTTP-01 requires validation content to be available at the expected HTTP path; DNS-01 requires the correct TXT record. Changes to firewalls, routing or DNS API permissions can interrupt this process. Inspect the result of the last renewal rather than merely checking that the automation service is running.

Restrict DNS validation tokens to the permissions they need. Store them outside the repository and track their validity. Credential rotation should include a renewal test so a failure does not remain hidden until the certificate's last days.

Leave enough time to fix the problem

Set more than one advance warning and assign a clear owner. Choose the number of days based on certificate lifetime and team operations. The margin must accommodate a weekend or holiday. An alert a day before expiration often leaves too few options.

Verify deployment after renewal

Successful issuance does not necessarily mean successful deployment. Confirm that the proxy or web server loaded the certificate, then perform a public test. Record the hostname and next expiry date with the result. In automation, distinguish issuance failures from deployment failures.

  • Did the last renewal succeed?
  • Does the client receive the new certificate and complete chain?
  • Does the certificate cover the correct hostname?
  • Will the owner receive a warning early enough to act?

What to take away

Automatic renewal and external monitoring complement each other. One obtains the certificate; the other verifies that the service actually presents it and leaves time to act when something fails.

Documentation and further reading

Mgr. Martin Hlavaj, MBA

Software Engineer

All articles

Hear about an outage early.

Add your website or API to UpBot and choose who receives the alert.

Start monitoring for free