Q: When should an SSL expiry alert fire? The day before?
A: Way earlier. Alert at 30 days, again at 14, and again at 7. A single day-before alarm assumes someone's awake, available, and that renewal is instant, which it often isn't.
Why the 30-day head start matters: certificate authority validation can hang, DNS changes take time to propagate, and some certs need manual approval. A cert that "auto-renews" can still silently fail and you want runway to notice.
Also monitor the certificate your users actually receive over the live connection, not just the file on disk. A renewed cert that was never deployed to the load balancer still serves the old, expiring one.
And watch intermediate certs in the chain too, not only the leaf. They expire and break trust just as hard.
Got a question? Drop it in the comments.
Pingback Clinic
@PingbackClinic
Q: When should an SSL expiry alert fire? The day before?
Этот пост опубликован в Telegram-канале Pingback Clinic. Подписаться можно по ссылке: @PingbackClinic.