Skip to content

Certificate errors explained and how to avoid expiry surprises

Expired, mismatched and untrusted certificates, intermediate chains, SNI and renewal monitoring.

By the UptimeMonitor360 team · updated

Expired

The certificate's notAfter is in the past. Renew and automate renewal; monitor expiry with warnings at 30, 14, 7, 3 and 1 days.

Hostname mismatch

The certificate's subject alternative names do not include the hostname used. Add the name or fix the DNS record.

Untrusted chain

The server did not send the intermediate certificate, or the root is not in public trust stores. Serve the full chain.

SNI

Servers hosting several names select the certificate from the SNI extension. Checks must send SNI with the hostname; connecting to an IP without SNI returns a default certificate.

Renewal changes

A changed fingerprint after renewal is normal. An unexpected change in issuer or SANs is worth a look.

Monitor the behaviour described here continuously: start free with 5 monitors or try the free tools.