Expiry is the failure that always surprises someone
An expired certificate does not degrade gracefully. Every browser shows a full-page security warning, and most visitors leave immediately. API clients fail outright, often with an error that points nowhere near the real cause.
Automated renewal has made this rarer and, when it does happen, more surprising - because everyone assumes it is handled. Renewal breaks quietly when a validation record changes, a cron job stops, or a certificate is deployed on a load balancer that nobody automated. Checking the actual expiry date on the live host is the only way to know what is really being served.
Chain problems that only some visitors see
A certificate is presented with the intermediate certificates that link it to a trusted root. If the server is configured with only the leaf certificate, the site still works in browsers that happen to have cached the intermediate - and fails on those that have not.
This produces the worst kind of bug report: works for you, fails for the customer, works again when they try later. Mobile browsers and older API clients are the usual victims. Checking the chain explicitly makes an incomplete chain visible instead of intermittent.
Hostname coverage
A certificate is valid only for the names listed in it. A certificate for example.com does not cover www.example.com unless that name is listed too, and a wildcard covers only one level - it matches a subdomain but not a sub-subdomain.
Mismatches usually show up when a new subdomain is launched, or when a service is moved behind a different hostname and the certificate is not reissued to match.
Frequently asked questions
- How do I check when an SSL certificate expires?
- Enter the hostname and the expiry date is read from the certificate the server is currently presenting - which is the one that matters, rather than whatever your control panel claims.
- What happens when a certificate expires?
- Browsers show a full-page security warning and most visitors leave. API clients fail with connection errors that rarely name the certificate as the cause.
- What is an incomplete certificate chain?
- The server is not sending the intermediate certificates that link its certificate to a trusted root. It works in clients that have cached the intermediate and fails in those that have not, which makes it look intermittent.
- Does a wildcard certificate cover every subdomain?
- Only one level. A wildcard for *.example.com covers app.example.com but not api.staging.example.com.