An SSL/TLS certificate lets browsers verify your domain and establish encrypted HTTPS. Certificates expire — Let’s Encrypt ones every 90 days — and rely on automated renewal that fails silently more often than anyone admits.
An expired certificate is a small outage with outsized damage: full-page browser warnings drive visitors away instantly. On multi-domain servers, the only sane approach is automated inventory — every certificate, days remaining, sorted soonest-first — with alerts long before expiry day.
Frequently asked questions
Why did my Let’s Encrypt renewal fail?
Common causes: DNS no longer points at the server, the validation path is blocked, rate limits, or the renewal cron/service stopped. The renewal log names the exact reason.
Is HTTPS needed for sites without logins?
Yes — browsers mark HTTP as “not secure”, search ranking favours HTTPS, and encryption protects visitors on hostile networks regardless of content.