What it checks
Whether the certificate the server presents is in date, chains to a publicly trusted certificate authority and covers the hostname that was requested.
A pass means: The certificate is trusted, in date and covers the hostname.
Possible findings
Certificate has expired
Severity: HighConfidence: ConfirmedKind: Security issue
What we found
The certificate presented has passed its expiry date.
Why it matters
Browsers show a full-page warning and most visitors leave. Automated clients refuse to connect.
How to fix it
Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.
Certificate is not yet valid
Severity: HighConfidence: ConfirmedKind: Security issue
What we found
The certificate presented has a start date in the future.
Why it matters
Browsers reject the certificate until its start date, so visitors see a warning.
How to fix it
Check the server's clock and the certificate's validity dates, and install a certificate that is valid now.
Certificate is not trusted
Severity: HighConfidence: ConfirmedKind: Security issue
What we found
The certificate chain does not lead to a publicly trusted certificate authority.
Why it matters
Browsers show a warning, and visitors cannot tell your site from an impostor. A common cause is a self-signed certificate or a missing intermediate certificate.
How to fix it
Install a certificate from a public certificate authority, and configure the server to send the full chain (your certificate plus intermediates).
Certificate does not cover this hostname
Severity: HighConfidence: ConfirmedKind: Security issue
What we found
The certificate presented is not valid for the hostname that was requested.
Why it matters
Browsers show a warning because the certificate was issued for a different name.
How to fix it
Issue a certificate whose subject alternative names include this hostname, or a wildcard that covers it, and install it.

