security / ssl / tls / certificate expiry
SSL / TLS

Certificate expiry

Every certificate has an expiry date. If it lapses, your site immediately starts showing security warnings to every visitor.

Severity if missing
High
Category
SSL / TLS
Standard
RFC 5280

What it is

SSL/TLS certificates are issued for a fixed period — typically 90 days to a year. Once that period ends, the certificate is no longer valid, and browsers treat your site as untrusted until it's renewed.

Expiry is one of the most common causes of sudden site outages, precisely because it happens silently on a date set months earlier.

Why it matters

An expired certificate takes a working site offline in the eyes of every browser — instantly, and for everyone. It's an entirely avoidable outage, but a surprisingly frequent one. Knowing how many days remain lets you renew comfortably in advance.

The risk
An expired certificate causes every browser to show a security warning and block access, effectively taking your site down until it's renewed.

How Pentrawl checks it

Pentrawl reads the expiry date from your certificate and reports how many days remain. Plenty of time passes the check; an expiry that is near or already passed is flagged so you can renew in time.

How to fix it

Use automatically renewing certificates so expiry is handled for you. If you manage renewal manually, set a reminder well before the expiry date.

Recommended
Enable automatic renewal (Certbot renews Let's Encrypt certificates before they expire).
Check your domain's Certificate expiry in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →