Why a planner for something that should be automatic
Ideally you never think about certificate renewal because your host or an ACME client does it for you. In practice many sites have at least one certificate that is not automated: a purchased one on a legacy server, a certificate on a mail host, an internal system. Those are the ones that expire at awkward times.
A renewal routine that holds up
- Know where every certificate lives. Make a list of hostnames and where each is installed.
- Enable automatic renewal wherever possible.
- For manual ones, calendar reminders at 30 days and 7 days before expiry.
- Use a monitoring service that alerts you if a certificate is within two weeks of expiry.
- After renewing, check with an external tool that the new certificate is actually being served, since some servers need a reload.
When automatic renewal fails
- A new CAA record that excludes the issuing authority.
- DNS changes that break the validation record.
- A firewall or redirect rule that blocks the validation request.
- A server that renewed the certificate on disk but never reloaded it.
The lead time in the tool is your safety margin. Thirty days is a sound default; shorter if your certificates are short-lived and renew automatically. See SSL Certificates Explained for background.