What the SSL checker reads
- Valid or not: the checks a browser makes. The certificate must chain to a trusted root, be inside its dates and name the host you asked for.
- Why not: expired, not yet valid, wrong name, incomplete chain, self-signed or revoked.
- Issuer, start date, expiry date and days left.
- Names: the Subject Alternative Names the certificate lists, and whether the bare domain and www are both covered.
- TLS version the server agreed to use with us.
Why a certificate gets rejected
- Expired. Renewal stopped working: a cron job or timer that no longer runs, a DNS or HTTP challenge that now fails, or a server that renewed the file but was never reloaded.
- Not valid for this name. The certificate covers example.com but someone opened www.example.com, or the server sends a default certificate for another site. Common on shared hosting after adding a domain.
- Incomplete chain. The server sends its own certificate without the intermediate one. The site may look fine in one browser and fail in another tool or on another device.
- Self-signed. Fine for testing, never for a public site.
- Not yet valid. The start date is in the future, usually a wrong clock on the server that issued it.
Expiry and renewal
Let's Encrypt certificates are valid for 90 days today, and Let's Encrypt has announced it will cut that to 45 days by 2028. It recommends renewing at about two thirds of the lifetime when the client doesn't support ACME Renewal Information. For a 90-day certificate that's about 30 days before expiry, so a certificate with fewer days left than that usually means renewal is failing.
We flag anything under 14 days, the same threshold the full report uses. Don't wait for it: run the renewal by hand and read the error it gives.
www and the bare domain need the same certificate
People type both. A browser checks the certificate before it ever sees a redirect, so if https://www.example.com has no valid certificate the visitor gets a warning even though your server would have sent them on to example.com.
The fix is to put both names on one certificate. With Certbot that's one command, for example certbot certonly -d example.com -d www.example.com, and hosting panels usually have a checkbox for the www version.