SSL certificates expire on a schedule you can see — plan for it
Nothing announces itself like an expired SSL certificate. Not your monitoring, not your users — your users, with a full-screen red warning that says your site is unsafe, because nobody wrote down the renewal date. Certificate expiry is the rare outage with a known, published ETA — which makes getting burned by it inexcusable.
What the certificate actually tells you
Open any site's certificate and you get four facts: who it was issued to, who issued it, when it expires, and which domains it covers. All four can fail independently. The common names match the common failures: expired validity window, wrong domain list (the cert covers www but not the apex), a chain that browsers reject even though the leaf is fine, or a signer your older clients do not trust.
The SSL certificate checker reads all of it from the live server: issuer, validity dates, SAN domain list, and chain details. Run it against production after every deploy that touches TLS — renewal automations fail silently more often than anyone admits, and the failure mode is "works for me, broken for half the internet."
The expiry that sneaks up on teams
Since 2020, certificates live 90 days at most for most issuance paths. Ninety days is shorter than many teams' release cadence, which is how expiry becomes a recurring emergency. What actually works:
- One calendar owner per domain, with the expiry in a shared tracker — not in one person's head
- A weekly automated check of every domain you operate; the HTTP availability checker catches the case where TLS is fine but the server is down, which presents to users the same way
- Renewal 30 days before expiry, never on the last weekend — Let's Encrypt rate limits and DNS propagation do not care about your launch
When the cert is fine but the site is not
A green padlock does not mean working. Certificate validity and service health are separate axes, and users experience both failures identically: the page did not load. After any TLS change, verify the full path — the DNS lookup confirms the name still resolves to the box you renewed the cert for, which catches the classic mistake: cert renewed on the old server, DNS pointed at the new one last week.
The discipline is small: one weekly check, one owner, one automated reminder. It costs ten minutes a month and removes the most embarrassing class of outage your product can have.