# An expired certificate counted as downtime

Your site is otherwise working fine, but the moment its TLS certificate expired, your **Website/HTTPS** monitor
started reporting the site down. This is expected behavior, not a bug - and there's a better way to track
certificate expiry that doesn't mix it in with your uptime record.

## Why it happens

A Website/HTTPS check over `https://` performs a full TLS handshake before it can even request the page. When a
certificate has expired, the handshake itself fails - most clients (browsers included) refuse to proceed past an
expired certificate. HostTracker's check behaves the same way: the handshake failure is recorded as the check
failing, which becomes downtime, even though your server is up and would happily serve the page over a valid
connection.

## What to do about it

- **Use a dedicated SSL/TLS certificate expiry check** alongside your uptime monitor. It watches the
  certificate's expiry date directly and alerts you *before* the certificate lapses, so you can renew it without
  ever hitting this situation. See [SSL/TLS certificate expiry](/monitors/types/ssl-expiry/).
- **If you need the uptime monitor to keep passing regardless of certificate validity** (for example, while
  testing, or on an internal endpoint with a self-signed or soon-to-expire certificate you don't control), you
  can turn off certificate validation for that specific monitor under its TLS handshake policy. This is a
  deliberate trade-off: the monitor will no longer catch certificate problems for you, since that's exactly what
  the dedicated expiry check is for. See [TLS handshake policy & certificate validation](/monitors/advanced/tls-policy/).

Using both together - the expiry check for advance warning, and leaving certificate validation on for the uptime
monitor - is the setup that catches the most.

## How to verify what happened

A failed check's error carries the codename **`TlsCertRejected`** (handshake rejected the certificate outright
- expired, self-signed or otherwise untrusted) or **`TlsHandshakeFailed`** (a different handshake problem) -
see [Common check errors](/troubleshooting/common-errors/) for how to read it through the API or app. To see
the certificate's actual expiry date: a dedicated SSL/TLS expiry monitor publishes `expirationDate`/
`certNotBefore` directly on `GET /monitor/{id}`; a Website/HTTPS monitor with certificate expiry **attached**
instead carries the same dates inside the `sslExp` block of `GET /monitor/{id}?expand=attached`.

## Related

- [SSL/TLS certificate expiry](/monitors/types/ssl-expiry/)
- [TLS handshake policy & certificate validation](/monitors/advanced/tls-policy/)
- [Common check errors and what they mean](/troubleshooting/common-errors/)
