Skip to content

TLS and certificates

Certificate checker

Read the certificate a website presents over HTTPS, often called its SSL certificate: who it was issued to and by, which hostnames it covers, when it is valid and whether the chain the server sends leads to a trusted root.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

A certificate binds a public key to one or more hostnames, and a certificate authority's signature vouches for that binding. Browsers accept it only when three things hold: the chain leads to a root they trust, the name being visited is listed in the certificate, and today's date falls inside its validity period.

Each of those has its own finding. Untrusted usually means a self-signed certificate, one from a private CA, or a server that leaves out the intermediate certificate. A name mismatch often shows on just one host: the www. name, or the bare domain when the certificate was issued only for www..

Use the details to compare what is served with what you expect: the issuer you chose, every name you serve, and a chain made of your certificate plus its intermediates. A chain of one usually means the intermediate is missing.

How to fix common issues

Certificate is not trusted

Install a certificate from a public certificate authority, and configure the server to send the full chain (your certificate plus intermediates).

More in the Certificate validity check reference

Certificate does not cover this hostname

Issue a certificate whose subject alternative names include this hostname, or a wildcard that covers it, and install it.

More in the Certificate validity check reference

Certificate has expired

Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.

More in the Certificate validity check reference

Certificate is not yet valid

Check the server's clock and the certificate's validity dates, and install a certificate that is valid now.

More in the Certificate validity check reference

Cyber Essentials and ISO 27001

Certificates are part of cryptographic key management, which ISO/IEC 27001:2022 places under Annex A 8.24, use of cryptography. A trusted, correctly named certificate is technical evidence for that control on one public service. The rules behind it are for the organisation to set: which authorities may issue for its domains, how private keys are protected and who approves a new certificate.

Knowing which certificates exist and who is responsible for each one belongs with the asset inventory (5.9, inventory of information and other associated assets). Cyber Essentials does not address certificates directly.

Scope and limitations

Related guides

Questions

What is an SSL certificate?
The certificate a server presents during a TLS handshake. It lists the hostnames it is valid for and carries a public key, signed by a certificate authority. The SSL in the name is historical; the protocol in use is TLS.
Why does my certificate work in a browser but fail elsewhere?
Often because the server does not send its intermediate certificate. Some browsers fill the gap from their own cache, while command-line tools, apps and other servers cannot. Configure the server to send the full chain.
Does a wildcard certificate cover the bare domain?
No. A wildcard such as *.example.org covers names one level below, like www.example.org, but not example.org itself or a.b.example.org. Most certificates list the bare domain as a second name alongside the wildcard.

Related security tools