About SSL Certificate Checker
Run this SSL certificate checker when a browser shows a security warning, before a certificate is due for renewal, or right after installing a new one on Nginx, Apache, a CDN or a hosting panel. Enter a host name, or host:port for a service on another port. We read the certificate and the chain the server actually sends, and test trust against the Mozilla root store, the list of authorities used by Firefox and many other programs. If the certificate checks out but the padlock is still missing, the Mixed Content Checker finds the http:// files to blame.
The checks cover days left, with a warning under 30 and a failure under 7, whether the certificate matches the host name (wildcards included), key type and size, the signature algorithm, a missing intermediate certificate, TLS 1.0 or 1.1 still enabled, TLS 1.3 support and a lifetime over 398 days. Details list the issuer, validation level (DV, OV or EV), covered names, serial number, SHA-256 fingerprint, OCSP address, SCT count, and the negotiated protocol and cipher, with a chain table and a protocol table. The IP address links to IP WHOIS.
How to use SSL Certificate Checker
- 1Enter the host
Type example.com, or example.com:8443 for a service on another port.
- 2Click Check
We connect from our server, read the certificate chain and try each TLS version.
- 3Read the verdict
Failures come first, each with a line on how to fix it.
- 4Check the details
Issuer, covered names, fingerprint and the chain table sit below the checks.
Why use Cubfile for this
- Expiry countdown
Days left, with a warning at 30 days and a failure at 7.
- Chain and trust
Spots a missing intermediate and checks trust against the Mozilla root store.
- Name matching
Compares the host with the covered names (SAN), wildcards included.
- TLS versions
Shows which of TLS 1.0, 1.1, 1.2 and 1.3 the server accepts.