How to Verify SSL Certificate Expiration and Errors
Verifying your SSL certificate status regularly prevents unexpected downtime, browser security warnings, and lost customer trust. By testing your certificate chain, cipher suites, and expiration dates proactively, you ensure secure end-to-end encryption for your web users.
Understanding SSL Certificates and Common Errors
Transport Layer Security (TLS), commonly referred to as SSL, relies on a cryptographic system to encrypt data between a client (such as a web browser) and a server. When this system fails, users encounter frustrating warning pages. Understanding the underlying anatomy of these errors helps you troubleshoot faster.
Common SSL Warning Messages
When a browser flags an SSL connection, it usually displays a specific error code. Knowing what these codes mean points you directly to the source of the configuration issue:
- NET::ERR_CERT_COMMON_NAME_INVALID: The domain name requested does not match the common name or Subject Alternative Names (SAN) listed on the certificate.
- NET::ERR_CERT_AUTHORITY_INVALID: The browser does not recognize or trust the Certificate Authority (CA) that signed the certificate. This is very common with self-signed certificates.
- NET::ERR_CERT_DATE_INVALID: The certificate has either expired or its validity period starts in the future (usually due to a server clock mismatch).
- ERR_SSL_PROTOCOL_ERROR: The server and browser cannot negotiate a mutually supported SSL/TLS protocol version or cipher suite.
The Importance of the Certificate Chain
A secure connection requires more than just your server's leaf certificate. It requires a complete chain of trust that links your certificate back to a trusted root certificate authority via one or more intermediate certificates. If your web server fails to serve these intermediate certificates during the TLS handshake, clients using strict trust stores will throw validation errors.
How to Check SSL Expiration and Details Manually
Before diving into automated diagnostic tools, you can use built-in command-line utilities to inspect an SSL certificate directly from your terminal. These tools give you raw, unfiltered data regarding expiration dates, issuer details, and SAN configurations.
Using OpenSSL to Inspect a Remote Certificate
OpenSSL is the Swiss Army knife of cryptography. You can query any public-facing HTTPS server to retrieve its complete certificate chain and operational details.
openssl s_client -connect example.com:443 -servername example.com
When you run this command, OpenSSL prints the certificate chain followed by the active certificate details. Look for the subject and issuer lines, as well as the validity dates:
notBefore=Nov 1 00:00:00 2023 GMT
notAfter=Dec 31 23:59:59 2024 GMT
To quickly extract just the expiration date without reading the entire certificate block, pipe the output into openssl x509:
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -dates
This yields a concise output:
notBefore=Nov 1 00:00:00 2023 GMT
notAfter=Dec 31 23:59:59 2024 GMT
Checking Certificates with cURL
Another quick way to test if a site resolves its SSL configuration properly is using cURL. By default, cURL fails if the certificate is invalid. You can pass the -v (verbose) flag to inspect the handshake process:
curl -v https://example.com
In the output, look for the handshake confirmation:
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384
* Server certificate:
* subject: CN=example.com
* start date: Nov 1 00:00:00 2023 GMT
* expire date: Dec 31 23:59:59 2024 GMT
* issuer: C=US; O=Let's Encrypt; CN=R3
* SSL certificate verify ok.
If the verification fails, cURL will output an explicit error message explaining why the handshake was aborted.
Step-by-Step Guide to Comprehensive SSL Auditing
A thorough SSL audit goes beyond checking the expiration date. Follow this step-by-step framework to validate your entire cryptographic posture.
Step 1: Verify Domain Name Matching
Ensure that the domain you are typing into the browser matches the domains protected by the certificate. Check both the Common Name (CN) and the Subject Alternative Names (SAN). Modern browsers completely ignore the CN if SAN entries are present.
Step 2: Test Protocol Support
Disable outdated and insecure protocols like SSLv2, SSLv3, TLS 1.0, and TLS 1.1. Your server should exclusively support TLS 1.2 and TLS 1.3 to meet modern compliance standards and protect user data against known cryptographic vulnerabilities.
Step 3: Analyze Cipher Suite Strength
Weak cipher suites allow attackers to downgrade connections or decrypt traffic. Ensure your web server configuration prioritizes modern, forward-secret cipher suites utilizing algorithms like AES-GCM or ChaCha20-Poly1305.
Step 4: Perform a Complete Chain Check
Use a dedicated free utility like the XiaTools ssl checker to instantly inspect your certificate installation, verify intermediate chain completeness, and check expiration dates without needing terminal access.
Step 5: Test Automated Renewal Scripts
If you use short-lived certificates (such as those provided by automated CAs), verify that your renewal cron jobs or systemd timers execute correctly. Simulate a renewal dry-run to catch permission or port-binding errors before your certificate actually expires.
SSL Verification Checklist
Keep this quick checklist handy when deploying a new certificate or troubleshooting an existing web service:
- Certificate expiration date is at least 30 days in the future.
- All intermediate certificates are correctly installed and served by the web server.
- Domain name matches the SAN (Subject Alternative Name) list accurately.
- Insecure protocols (SSLv3, TLS 1.0, TLS 1.1) are disabled on the server.
- Strict Transport Security (HSTS) is enabled with an appropriate max-age header.
- Automated renewal scripts or reminders are active and tested.
By executing these checks regularly, you maintain a robust security posture and prevent unexpected outages that impact your SEO rankings and user trust.