security / ssl / tls / certificate validity
SSL / TLS

Certificate validity

A valid SSL/TLS certificate is what makes the padlock appear in the browser — it proves your site is who it claims to be and encrypts the connection.

Severity if missing
High
Category
SSL / TLS
Standard
RFC 5280

What it is

When a browser connects to your site over HTTPS, it checks your SSL/TLS certificate. A valid certificate is issued by a trusted authority, matches your domain, and hasn't expired or been revoked. Only then does the browser establish a secure, encrypted connection and show the padlock.

If any of those conditions fail, the browser warns the visitor with a full-page security error.

Why it matters

The certificate is what underpins all of HTTPS. Without a valid one, the connection either isn't encrypted or the browser can't trust it — and visitors are met with alarming warnings that drive them away. A valid certificate is the baseline for any site that handles logins, payments or personal data.

The risk
An invalid, untrusted or expired certificate breaks the secure connection and shows visitors a security warning, destroying trust and blocking access.

How Pentrawl checks it

Pentrawl connects to your site over HTTPS and inspects the certificate it presents — checking that it is valid, trusted, correctly formed and currently active. A valid certificate passes the check.

How to fix it

Install a certificate from a trusted authority. Free, automated certificates from Let's Encrypt are the standard choice and renew themselves, so most sites never have to think about it again.

Recommended
Use Let's Encrypt (via Certbot or your host's built-in SSL) for a free, auto-renewing certificate.
Check your domain's Certificate validity in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →