Tools / Certificate Renewal Planner

Certificate Renewal Planner

Pick a renewal date and see how much runway you have.

Why a planner for something that should be automatic

Ideally you never think about certificate renewal because your host or an ACME client does it for you. In practice many sites have at least one certificate that is not automated: a purchased one on a legacy server, a certificate on a mail host, an internal system. Those are the ones that expire at awkward times.

A renewal routine that holds up

  1. Know where every certificate lives. Make a list of hostnames and where each is installed.
  2. Enable automatic renewal wherever possible.
  3. For manual ones, calendar reminders at 30 days and 7 days before expiry.
  4. Use a monitoring service that alerts you if a certificate is within two weeks of expiry.
  5. After renewing, check with an external tool that the new certificate is actually being served, since some servers need a reload.

When automatic renewal fails

The lead time in the tool is your safety margin. Thirty days is a sound default; shorter if your certificates are short-lived and renew automatically. See SSL Certificates Explained for background.