phas.nz

SSL expiry warnings

A daily certificate check, warnings at 30, 14 and 3 days, and what to do when one arrives.

Along with the uptime checks, Monitoring inspects each site's SSL certificate once a day and records when it expires. You are emailed as the date approaches:

Days left Email
30 First warning
14 Second warning
3 Final warning

Each threshold sends once. The countdown resets when a new certificate is seen, so a renewed certificate produces no further emails.

Sites hosted with phas

Certificates for sites on a phas plan renew automatically, weeks before they expire, so a warning usually means renewal could not complete. The common cause is DNS: the domain no longer points at the plan, or a proxy or another provider's records sit in front of it. Check the domain resolves to the plan, then open a ticket if the warning does not clear within a day.

Sites with a certificate from elsewhere

If the domain is proxied through phas DNS, the certificate visitors see is managed at the edge and renews on its own. If the certificate comes from a provider you manage, the warning is your cue to renew it there.

Why a certificate matters for uptime

Browsers refuse to load a site with an expired certificate, so from a visitor's point of view it is down even though the server is answering. Monitoring treats it the same way: an expired certificate fails the check and opens an incident.


Didn't find what you needed? Get in touch.