XiaTools

How to Verify SSL Certificate Expiration and Errors

Updated 30 Sept 2026

Verifying your SSL certificate status regularly prevents unexpected downtime, browser security warnings, and lost customer trust. By testing your certificate chain, cipher suites, and expiration dates proactively, you ensure secure end-to-end encryption for your web users.

Understanding SSL Certificates and Common Errors

Transport Layer Security (TLS), commonly referred to as SSL, relies on a cryptographic system to encrypt data between a client (such as a web browser) and a server. When this system fails, users encounter frustrating warning pages. Understanding the underlying anatomy of these errors helps you troubleshoot faster.

Common SSL Warning Messages

When a browser flags an SSL connection, it usually displays a specific error code. Knowing what these codes mean points you directly to the source of the configuration issue:

  • NET::ERR_CERT_COMMON_NAME_INVALID: The domain name requested does not match the common name or Subject Alternative Names (SAN) listed on the certificate.
  • NET::ERR_CERT_AUTHORITY_INVALID: The browser does not recognize or trust the Certificate Authority (CA) that signed the certificate. This is very common with self-signed certificates.
  • NET::ERR_CERT_DATE_INVALID: The certificate has either expired or its validity period starts in the future (usually due to a server clock mismatch).
  • ERR_SSL_PROTOCOL_ERROR: The server and browser cannot negotiate a mutually supported SSL/TLS protocol version or cipher suite.

The Importance of the Certificate Chain

A secure connection requires more than just your server's leaf certificate. It requires a complete chain of trust that links your certificate back to a trusted root certificate authority via one or more intermediate certificates. If your web server fails to serve these intermediate certificates during the TLS handshake, clients using strict trust stores will throw validation errors.

How to Check SSL Expiration and Details Manually

Before diving into automated diagnostic tools, you can use built-in command-line utilities to inspect an SSL certificate directly from your terminal. These tools give you raw, unfiltered data regarding expiration dates, issuer details, and SAN configurations.

Using OpenSSL to Inspect a Remote Certificate

OpenSSL is the Swiss Army knife of cryptography. You can query any public-facing HTTPS server to retrieve its complete certificate chain and operational details.

openssl s_client -connect example.com:443 -servername example.com

When you run this command, OpenSSL prints the certificate chain followed by the active certificate details. Look for the subject and issuer lines, as well as the validity dates:

notBefore=Nov  1 00:00:00 2023 GMT
notAfter=Dec 31 23:59:59 2024 GMT

To quickly extract just the expiration date without reading the entire certificate block, pipe the output into openssl x509:

echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -dates

This yields a concise output:

notBefore=Nov  1 00:00:00 2023 GMT
notAfter=Dec 31 23:59:59 2024 GMT

Checking Certificates with cURL

Another quick way to test if a site resolves its SSL configuration properly is using cURL. By default, cURL fails if the certificate is invalid. You can pass the -v (verbose) flag to inspect the handshake process:

curl -v https://example.com

In the output, look for the handshake confirmation:

* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384
* Server certificate:
*  subject: CN=example.com
*  start date: Nov  1 00:00:00 2023 GMT
*  expire date: Dec 31 23:59:59 2024 GMT
*  issuer: C=US; O=Let's Encrypt; CN=R3
*  SSL certificate verify ok.

If the verification fails, cURL will output an explicit error message explaining why the handshake was aborted.

Step-by-Step Guide to Comprehensive SSL Auditing

A thorough SSL audit goes beyond checking the expiration date. Follow this step-by-step framework to validate your entire cryptographic posture.

Step 1: Verify Domain Name Matching

Ensure that the domain you are typing into the browser matches the domains protected by the certificate. Check both the Common Name (CN) and the Subject Alternative Names (SAN). Modern browsers completely ignore the CN if SAN entries are present.

Step 2: Test Protocol Support

Disable outdated and insecure protocols like SSLv2, SSLv3, TLS 1.0, and TLS 1.1. Your server should exclusively support TLS 1.2 and TLS 1.3 to meet modern compliance standards and protect user data against known cryptographic vulnerabilities.

Step 3: Analyze Cipher Suite Strength

Weak cipher suites allow attackers to downgrade connections or decrypt traffic. Ensure your web server configuration prioritizes modern, forward-secret cipher suites utilizing algorithms like AES-GCM or ChaCha20-Poly1305.

Step 4: Perform a Complete Chain Check

Use a dedicated free utility like the XiaTools ssl checker to instantly inspect your certificate installation, verify intermediate chain completeness, and check expiration dates without needing terminal access.

Step 5: Test Automated Renewal Scripts

If you use short-lived certificates (such as those provided by automated CAs), verify that your renewal cron jobs or systemd timers execute correctly. Simulate a renewal dry-run to catch permission or port-binding errors before your certificate actually expires.

SSL Verification Checklist

Keep this quick checklist handy when deploying a new certificate or troubleshooting an existing web service:

  • Certificate expiration date is at least 30 days in the future.
  • All intermediate certificates are correctly installed and served by the web server.
  • Domain name matches the SAN (Subject Alternative Name) list accurately.
  • Insecure protocols (SSLv3, TLS 1.0, TLS 1.1) are disabled on the server.
  • Strict Transport Security (HSTS) is enabled with an appropriate max-age header.
  • Automated renewal scripts or reminders are active and tested.

By executing these checks regularly, you maintain a robust security posture and prevent unexpected outages that impact your SEO rankings and user trust.

Frequently asked questions

What causes an SSL certificate expiration warning?

A browser displays an expiration warning when a certificate's 'notAfter' date has passed. This happens when automated renewal scripts fail, or when a system administrator forgets to manually renew and deploy a long-term certificate before its deadline.

How can I check my SSL certificate expiration date from the command line?

You can use OpenSSL with the s_client command combined with x509 parsing. Running a command like 'echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -dates' instantly prints the start and end dates of the active certificate.

Why does my SSL certificate show as untrusted even though it is valid?

This typically occurs when your web server fails to serve the required intermediate certificates. While your primary certificate is valid, the client's browser cannot find a path of trust back to a recognized root authority, resulting in a trust error.

What is the difference between Common Name and Subject Alternative Name?

The Common Name (CN) specifies the primary host name protected by the certificate. Subject Alternative Names (SAN) allow a single certificate to secure multiple distinct domain names, subdomains, or wildcard variations under one deployment.

How often should I check my SSL certificate status?

It is best practice to monitor your SSL certificates continuously using automated monitoring tools or alert systems. For manual reviews, checking your setup at least 30 days before expiration and after any major infrastructure change ensures uninterrupted service.

Related articles

Free tools