Security

Certificate Expiry Planner

Track certificate expiry dates across an estate, see which are overdue for renewal against your alert thresholds, and get the renewal calendar and automation recommendations.

Last reviewed by the Radiatus Cloud team

Renewal schedule appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Expiry is a scheduled outage nobody scheduled

A certificate expiring in production is an outage with a known date that was allowed to arrive. Microsoft Teams, Spotify, LinkedIn, Ericsson and many others have all had major public incidents from exactly this cause. It is the most predictable failure in infrastructure and it keeps happening, because the certificate is renewed by someone who has since changed role, the reminder went to a shared mailbox nobody reads, or the renewal was done and the new file was never deployed.

Validity periods keep shrinking

Public certificate lifetimes fell from five years to two, then to 398 days in 2020, and the CA/Browser Forum has agreed a schedule reducing them to 47 days by 2029. Manual renewal is already marginal at 398 days and becomes impossible at 47. Anything not automated by then will fail, which makes ACME automation a migration to plan now rather than an optimisation.

Alert thresholds and the deployment gap

A single alert thirty days out is not enough, because the person who receives it may be away and the renewal may need a change window. Layered alerts at sixty, thirty, fourteen and seven days give escalating urgency, with the last one paging. Critically, the alert should be based on what the server is actually serving rather than on what was issued: a renewed certificate sitting on a build server has not renewed anything.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

When should renewal alerts fire?

Layered: 60 days for planning, 30 days for action, 14 days as a warning and 7 days as a page. A single alert relies on one person being available at one moment, which is how expiry incidents happen.

Why are certificate lifetimes getting shorter?

To limit the window in which a compromised or mis-issued certificate remains valid, and because revocation checking has never worked reliably in browsers. The CA/Browser Forum has agreed a schedule reducing the maximum to 47 days by 2029.

Should I automate renewal?

Yes, for anything public facing. ACME clients such as certbot, acme.sh, lego and Caddy handle issuance and deployment together. At a 47 day maximum lifetime, manual renewal will not be viable for any estate of meaningful size.

Why do renewed certificates still cause outages?

Because renewal and deployment are separate steps. A certificate issued but not installed, installed on one node of a cluster, or installed without reloading the service, all present the old certificate. Monitor what the endpoint actually serves rather than what was issued.

What about internal certificates?

They cause the same outages with less visibility, because internal monitoring often does not check them and internal CAs issue long lifetimes that make the problem rare enough to be forgotten. Track them in the same inventory as public ones.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Add each certificate with its expiry date to see the renewal schedule and risk ranking.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.