SSL certificate expiration checks
Create an SSL certificate check, enter a bare public hostname and set positive warning/critical day thresholds. Critical must be less than warning.
| Setting | Behavior |
|---|---|
| Name | Required |
| Hostname | Bare hostname without a scheme or path |
| Warning days | At or below this remaining-day value: degraded |
| Critical days | At or below this remaining-day value: down |
| Schedule | Fixed hourly lookup |
| Notification groups | Assigned account groups |
Warning 30 and critical 7 mean that equality at either boundary is already
a breach. An expired certificate is down. Inspect the first recorded
expiration date to confirm you are monitoring the intended hostname.
This check watches certificate expiration, not the complete security posture of TLS or every certificate in your infrastructure. A TLS or lookup failure without a usable expiration date does not independently prove expiration; review the latest recorded result and date.
For endpoint availability and TLS connection errors use a separate website check. Pingstack does not issue or renew certificates on your behalf.