↑ ↓ select, Enter open, Esc close

Check whether a certificate expires within the next days

Adjust the values, the command updates live
root@server
openssl x509 -in /etc/letsencrypt/live/example.com/cert.pem -noout -checkend $(( 30 * 86400 )) && echo "noch gültig" || echo "läuft bald ab"

The -checkend option expects seconds and returns exit code 0 if the certificate is still valid after that time, otherwise 1. The $(( ... )) arithmetic converts days into seconds. This makes it easy to trigger a warning in scripts or cron jobs before visitors see an error message.

Note: Root is only needed for protected paths like /etc/letsencrypt/.

Also searched as

  • check if certificate expires in 30 days
  • monitor ssl expiry with cron
  • openssl checkend script
  • certificate expiration warning script

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.