LEARN · TLS-CERTIFICATES
TLS certificates & HTTPS
What a TLS certificate is, why it expires and how to check your HTTPS is configured correctly.
WHAT IT IS
A TLS certificate proves your website is really yours and enables an encrypted connection (the padlock and "https"). It is issued by a trusted authority, covers specific names and has an expiry date.
WHY IT MATTERS
If the certificate expires, does not cover the visited name or has an incomplete chain, browsers show a full-screen danger warning and most visitors leave.
COMMON MISTAKES
- Renewing by hand and forgetting (automate it: Let’s Encrypt + certbot).
- Certificate valid for www but not for the bare domain (or vice versa).
- Not installing the intermediate chain.
- Keeping TLS 1.0/1.1 enabled.
EXAMPLE
certbot --nginx -d example.com -d www.example.com # DNS (opcional, recomendado): example.com. CAA 0 issue "letsencrypt.org"
HOW WE CHECK IT
- TLS_AVAILABLE v1.0.0 — That a TLS connection can be established on port 443.
- TLS_CERT_TRUSTED v1.0.0 — That the certificate is issued by a trusted authority, the chain is complete and it covers the visited name.
- TLS_CERT_EXPIRY v1.0.0 — Days left until the certificate expires.
- TLS_PROTOCOL v1.0.0 — The TLS version negotiated with a modern client (TLS 1.2 or 1.3 expected).
- DNS_CAA v1.0.0 — Whether CAA records restrict which authorities may issue certificates for the domain (the name and its parent are queried).