TLS certificate inspector
We open a TLS connection to the site the way a browser does and read its certificate, even a broken one. If something is wrong with it, you’ll know which of the usual failures you’re dealing with.
What a certificate is for
When your browser connects to https://example.com, something answers. Whether that something belongs to example.com is another matter. Anyone sitting on the network in between could have picked up instead.
So the server has to show ID. A certificate is a small file holding a public key, the list of hostnames that key may speak for, a start date, an end date, and the signature of a certificate authority (CA) that checked who controls those names. The browser goes down its list. The name in the address bar has to be on the certificate. Today has to fall between the two dates. The signature has to lead back to an authority the device already trusts. And the server has to prove it holds the matching private key. Miss any one of those and the visitor gets the full-page warning.
Encryption only starts once all of that checks out. The padlock means the server proved who it is, and the encryption rests on that proof.
What the inspector tests
It connects to port 443 twice. The first time it accepts anything, so it can read the certificate no matter what state it’s in. The second time it verifies everything against a standard list of trusted roots, the way a strict client would.
| Test | Result |
|---|---|
| Dates | Red if expired or not valid yet. Amber under 7 days left, a note under 21 days, green otherwise. |
| Names | Red if the hostname you entered isn’t covered. Amber if its twin (with or without www) exists in DNS but is missing from the certificate. |
| Trust | If verification fails, you get the cause: expired, wrong name, self-signed, incomplete chain, or the raw verification error. |
| Chain order | Amber if the certificates sent don’t sign one another in sequence. |
| Key and signature | Red for an RSA key under 2048 bits or a SHA-1 or MD5 signature. |
| Protocol | Red if the connection is negotiated with anything older than TLS 1.2. |
After that it requests the four forms of the address (http and https, with and without www) and shows where each one ends up and whether the site sends an HSTS header. If you want that part hop by hop, the redirect trace does it.
Works in Chrome, fails everywhere else
Authorities don’t sign your certificate with their root key. They sign it with an intermediate certificate, which the root has signed in turn. Devices only store roots, so your server has to send the intermediate along with its own certificate. The two together make the chain.
When a server sends only its own certificate, desktop Chrome and Edge are forgiving. They often download the missing intermediate or reuse one they saw on another site. Firefox on a fresh profile, older Android phones, curl, payment webhooks, mail servers and most programming libraries won’t do you that favor. That’s how you end up with a site that looks perfect to its owner and fails for an API client. The inspector calls this Incomplete chain, and reports it when verification fails and a single certificate was sent.
Fixing the usual failures
- Expired. Automated certificates renew about 30 days before the end, so if yours ran out, the renewal job has been failing for weeks. With Certbot, run
certbot renew --dry-runand read the error. It’s usually a DNS record that moved, a firewall closing port 80, or a redirect that swallows/.well-known/acme-challenge/. - Name not covered. Request the certificate again and list every hostname:
certbot -d example.com -d www.example.com. A wildcard*.example.comcovers one level of subdomains. It doesn’t coverexample.comitself, which catches a lot of people. - Incomplete chain. Point the server at the full chain file. In nginx:
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;. In Apache 2.4.8 and later,SSLCertificateFiletakes the same file. - Self-signed. Swap it for a certificate from a public authority. Let’s Encrypt, ZeroSSL and Google Trust Services hand them out for free.
- Old protocol. Enable TLS 1.2 and 1.3. In nginx:
ssl_protocols TLSv1.2 TLSv1.3;
You can see the same thing from a terminal with openssl s_client -connect example.com:443 -servername example.com.
The inspector talks to one IP address on port 443 and reports the protocol that got negotiated, not every version the server would accept. A site spread over several servers may present a different certificate on another address. Revocation isn’t checked.
Questions people ask
Is SSL the same thing as TLS?
TLS is the protocol’s current name. SSL came before it, and its last version was retired in 2015. People still say “SSL certificate” out of habit, but every certificate in use today works with TLS.
How long is an SSL certificate valid?
Let’s Encrypt certificates last 90 days. For all public authorities, the allowed maximum dropped from 398 to 200 days in March 2026, and it falls to 100 days in March 2027 and 47 days in March 2029. At that pace, renewing by hand stops being realistic.
My certificate is valid. Why does the browser still say “Not secure”?
Usually one of three things. The page was opened over http:// and nothing redirects it to HTTPS, the certificate doesn’t cover the exact hostname in the address bar, or the page loads scripts or images over plain HTTP. The redirects table in the result will tell you about the first one.
What does ERR_CERT_COMMON_NAME_INVALID mean?
The hostname you visited isn’t on the certificate’s list of names. It often happens on www when only the bare domain was requested, or on a new subdomain that is being served a default certificate.
Is a free certificate less secure than a paid one?
No. The encryption is identical and browsers treat the two the same way. What you pay for is support, a warranty or your organization’s details inside the certificate, and browsers no longer show those prominently.
How early should a certificate be renewed?
Automated clients renew when a third of the lifetime is left, about 30 days for a 90-day certificate. If you’re down to 7 days, which is where this check starts warning, the automation has probably stopped working.