A valid date is only one part of the check
“SSL certificate” remains a common name for a certificate used with modern TLS. A browser evaluates several things: whether the certificate covers the requested hostname, whether its validity period includes the current time, and whether a valid chain leads to a trusted authority. The service-identity rules are specified in RFC 9525.
A certificate helps authenticate the connection endpoint. It does not certify the accuracy of a page, honesty of a merchant, or safety of a downloaded file. Treat a successful check as evidence about the connection, not a general endorsement of the site.
Worked example: renewal succeeded, visitors still see expiry
Imagine your certificate manager reports a successful renewal, while one hostname still serves an expired certificate. First compare the certificate actually presented at that hostname with the newly issued one. An issuance event does not prove that a server or load balancer installed the certificate.
- Record the exact hostname, port, time, and observed expiry.
- Check the endpoint used by the visitor, including any CDN or reverse proxy.
- Compare results across the relevant public endpoints; different nodes may be serving different certificates.
- Verify deployment and reload behavior using the server or hosting provider’s procedure.
- Repeat the original check after deployment and watch the next renewal cycle.
Keep separate records for apex and subdomain names. A successful check of one name is not a check of every name that users reach through redirects.
Classify the problem before changing configuration
| Symptom | Next check |
|---|---|
| Expired or not yet valid | Served certificate dates and the client clock |
| Name mismatch | Requested hostname and certificate SAN entries |
| Untrusted chain | Intermediate certificates and client trust store |
| Handshake failure | Protocol negotiation, listener, and server logs |
| Checker timeout | Reachability and provider availability; result is inconclusive |
Do not remove certificate validation to make a failing check appear successful. Correct the endpoint, chain, name coverage, or deployment problem. A private enterprise authority can be trusted on managed devices without being trusted by a public checking service; record which perspective produced the result.
Why a 502 is a different clue
A browser can establish TLS successfully to a proxy that then fails to connect to its origin. The resulting 502 or 504 is an HTTP response from that proxy. The public certificate checker cannot inspect a private upstream’s trust configuration. Use the gateway-errors guide and correlate the response with logs at the layer that produced it.
Use the tool as a snapshot
Utiliverse sends the entered hostname to an external checking API. The result reflects the service’s location, capabilities, and time of observation. It is not continuous monitoring, and it does not reproduce every client trust store or network route. Copy the hostname and timestamp along with the result when reporting a problem.
For renewal planning, consult your certificate authority and hosting platform rather than assuming every certificate uses the same lifetime or renewal schedule. Let’s Encrypt’s FAQ provides authority-specific background. The important operational check is that the new certificate reaches every relevant endpoint before the old one expires.
Try the related tools
Continue reading
Sources and review
Examples are illustrative. Reviewed September 29, 2026 against the listed references and the related tool behavior. Methodology · Report a correction.