Slow Build

Checking certificate expiry from the shell

03 September 2026

Expired certificates are embarrassing and entirely avoidable. You do not need a monitoring product to look at one; openssl can ask the server directly:

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -enddate

The -servername option matters. Without it a server hosting several sites may present a different certificate than the one you want to check.

For a script, let openssl do the date arithmetic. This exits with a non-zero status if the certificate expires within 14 days:

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -checkend 1209600

Run it from a timer and mail yourself on failure. Automatic renewal is great until the day it silently stops working.