How to investigate a certificate expiration warning
A certificate is usable only during the time window encoded in its Not Before and Not After fields. A warning that the end date is approaching is an operations signal: the endpoint may still work today, but renewal, deployment, and client verification need attention before the date arrives.
Why renewal can fail
Renewal problems often occur outside the certificate authority itself. Automation may have issued a new certificate without installing it, a load balancer may still serve an older copy, or one node in a cluster may have been missed. A certificate can also be renewed correctly while an intermediate certificate remains absent from the server’s configured chain.
A practical review sequence
- Check the expiration date on every public endpoint and listener, not only the primary web server.
- Confirm the certificate contains the names users actually request.
- Verify that all serving nodes present the same current certificate.
- Confirm the deployed chain and restart or reload the service if required.
- Test from a client path after deployment and record the renewal owner and next deadline.
What Certificate Inspector reports
The checker reports the certificate dates returned by the tested public endpoint and identifies an approaching or expired date. It does not know whether internal endpoints, private services, or backup systems use the same certificate. Treat the result as an endpoint-specific observation and confirm it against your certificate inventory.
Last reviewed: September 2026. This guide is original explanatory content, not a substitute for the certificate authority’s current instructions.