Skip to content

An expired certificate counted as downtime

View as Markdown

Your site is otherwise working fine, but the moment its TLS certificate expired, your Website/HTTPS monitor started reporting the site down. This is expected behavior, not a bug - and there’s a better way to track certificate expiry that doesn’t mix it in with your uptime record.

A Website/HTTPS check over https:// performs a full TLS handshake before it can even request the page. When a certificate has expired, the handshake itself fails - most clients (browsers included) refuse to proceed past an expired certificate. HostTracker’s check behaves the same way: the handshake failure is recorded as the check failing, which becomes downtime, even though your server is up and would happily serve the page over a valid connection.

  • Use a dedicated SSL/TLS certificate expiry check alongside your uptime monitor. It watches the certificate’s expiry date directly and alerts you before the certificate lapses, so you can renew it without ever hitting this situation. See SSL/TLS certificate expiry.
  • If you need the uptime monitor to keep passing regardless of certificate validity (for example, while testing, or on an internal endpoint with a self-signed or soon-to-expire certificate you don’t control), you can turn off certificate validation for that specific monitor under its TLS handshake policy. This is a deliberate trade-off: the monitor will no longer catch certificate problems for you, since that’s exactly what the dedicated expiry check is for. See TLS handshake policy & certificate validation.

Using both together - the expiry check for advance warning, and leaving certificate validation on for the uptime monitor - is the setup that catches the most.

A failed check’s error carries the codename TlsCertRejected (handshake rejected the certificate outright

  • expired, self-signed or otherwise untrusted) or TlsHandshakeFailed (a different handshake problem) - see Common check errors for how to read it through the API or app. To see the certificate’s actual expiry date: a dedicated SSL/TLS expiry monitor publishes expirationDate/ certNotBefore directly on GET /monitor/{id}; a Website/HTTPS monitor with certificate expiry attached instead carries the same dates inside the sslExp block of GET /monitor/{id}?expand=attached.