SSL Certificate Inspector

The lamp reveals all. Especially expiry dates.

Reading a certificate

A TLS certificate is how a server proves it is who it claims to be. The fields that matter in real work: the subject and SAN list (which names the certificate actually covers — a cert for example.com does not cover www.example.com unless it says so), the issuer (a public CA or something self-signed), and the expiry date, which ends more services than any attacker ever has. This tool reads the live certificate the server presents, including the chain it sends — if the chain is incomplete, some clients will refuse to connect even though your browser is fine with it. Weak signature algorithms like SHA-1 are flagged because modern clients reject them. Nothing here probes ciphers or runs a full grading scan; it reads the certificate, the same thing every browser checks, and puts the expiry math where you can see it. Paste the output into the renewal ticket and set the reminder before the canary starts sweating.