Certificate expiry and validity
SSL certificate monitoring before renewal becomes urgent
A website can respond today and still be approaching a certificate renewal problem. Use a TLS monitor to track certificate validity and remaining days separately from the page response.
Check the certificate visitors are served
Upteno connects to the public hostname and port, uses SNI, and verifies the hostname and certificate chain. The result includes certificate subject, issuer, validity dates, remaining days, fingerprint, and negotiated TLS details when available. Observations remain tied to their execution location. A CDN can legitimately serve different valid certificates in different regions; a difference is evidence to review, not automatically a failed check.
Set an expiry warning that leaves time to act
Create a TLS monitor, enter the public host and port, and choose an expiry warning window from 1 to 90 days. Port 443 is the usual choice for HTTPS. Select relevant locations and review the monitor confirmation settings. A valid certificate inside the warning window produces Degraded evidence. An expired or invalid certificate, hostname mismatch, or failed connection produces Down evidence. The saved monitor applies its configured state rules before notifications are generated.
Enable the right notification event
Connect and test the recipient contact, then enable Degraded notifications in the effective policy to receive expiry warnings. Down notifications cover invalid or unreachable TLS; Recovery reports the supported recovery transition. For example, a valid certificate with 12 days remaining is inside a 14-day warning window. It can trigger a Degraded state under your rules even while the website remains reachable. This is a configuration example, not a live measurement.
Review renewal and certificate changes
After renewal, inspect the latest certificate dates and the observed chain. Optional certificate-change settings can flag a fingerprint, issuer or chain, or negotiated-protocol change through the Degraded workflow. Certificate-change comparison is per execution node, so valid regional variants are not treated as a new change on every cycle. Review location evidence when a warning needs investigation.
Certificate monitoring is a distinct check
A TLS check does not test the HTTP response body, a login flow, or the domain registration expiry date. Add HTTP or API monitoring for the application and a domain-expiry monitor for registration renewal. A monitor reports evidence; it does not renew certificates or guarantee notification delivery. Keep the renewal process and its owner documented alongside your alert policy.