Skip to main content
DigiCert, Sectigo and GeoTrust SSL certificates
+90 850 259 76 06 WhatsApp Support Become a Reseller
SSL Certificates
Brands
Code Signing LEI Code
Tools
Support Contact WhatsApp Cart
Language
Currency
Get an SSL Certificate
SSL Guides

How to Check an SSL Certificate: Validity, Issuer and Chain

Is the certificate valid, issued for the right domain and installed completely? Three ways to check an SSL certificate: in the browser, with an online check and on the command line, plus the five things that matter.

3 min read

The quickest way to check an SSL certificate is to click the icon to the left of the address in your browser. For a full check including the certificate chain use an online check; for servers without a browser use the command line.

The five things that matter

CheckWhat is correctIf it fails
ValidityExpiry date is in the futureFull-page browser warning
DomainsThe name opened is in the certificate"Wrong name" warning
IssuerA publicly trusted certificate authority"Not trusted" warning
ChainIntermediate certificates are sent alongErrors on mobile devices and in apps
ProtocolTLS 1.2 or 1.3Connection refused

Method 1: in the browser

  1. Open the site and click the icon to the left of the address.
  2. Choose "Connection is secure", then "Certificate is valid".
  3. Read who it was issued to, who issued it and the expiry date.

The browser shows what it sees itself; a missing chain often goes unnoticed here.

Method 2: online check

An online check opens your site from outside and reports the expiry date, domains, issuer and the chain that is served. That is what visitors and search engines see. Enter your domain in the SSL checker; it is free.

Method 3: command line with OpenSSL

openssl s_client -connect example.com:443 -servername example.com < /dev/null | openssl x509 -noout -subject -issuer -dates

The output gives the subject, the issuer and the validity dates. For other services change the port, for example 465 for SMTP over TLS.

Checking a certificate file before installing it

If you have the certificate as a file, paste it into the certificate decoder: it shows who it was issued to, which domains it covers and when it expires. The matcher on the same page tells you whether a certificate and a CSR belong together. Never paste your private key.

How often?

Certificates are valid for at most 200 days, and 100 days from March 2027. Check immediately after every installation and set a reminder 30 days before expiry.

Share this post
Ali Yiğit
Yazar

Ali Yiğit

Recommended SSL Certificates

All Products
EV Certum

Certum Premium EV Multi-Domain SSL

Protect multiple domains at EV level with Certum Premium EV Multi-Domain SSL. Company name visible i

$419.00 /yr
Details
EV Certum

Certum Premium EV SSL

Get the most comprehensive identity validation with Certum Premium EV SSL. Extended validation, comp

$654.58 /yr
Details
OV Certum

Certum Trusted Multi-Domain SSL

Protect multiple domains at OV level with Certum Trusted Multi-Domain SSL. Company name visible, 4,

$50.00 /yr
Details

Yorumlar

No comments yet. Be the first to comment!

Yorum Yaz