TLS and certificates
Certificate checker
Read the certificate a website presents over HTTPS, often called its SSL certificate: who it was issued to and by, which hostnames it covers, when it is valid and whether the chain the server sends leads to a trusted root.
What this checks
- The site's own (leaf) certificate, served on port 443 for the domain and for its
www.name, or for the one subdomain entered. - Trust: whether the certificates sent chain to a root in Mozilla's root store, the list of authorities Firefox ships with and many other systems reuse.
- Hostname coverage: whether the name is among the certificate's subject alternative names, directly or through a wildcard such as
*.example.org. - Validity: the not-before and not-after dates, compared with the current time.
- Details for the record: subject, issuer, signature algorithm, how many certificates the server sent, and the serial number.
What the result means
A certificate binds a public key to one or more hostnames, and a certificate authority's signature vouches for that binding. Browsers accept it only when three things hold: the chain leads to a root they trust, the name being visited is listed in the certificate, and today's date falls inside its validity period.
Each of those has its own finding. Untrusted usually means a self-signed certificate, one from a private CA, or a server that leaves out the intermediate certificate. A name mismatch often shows on just one host: the www. name, or the bare domain when the certificate was issued only for www..
Use the details to compare what is served with what you expect: the issuer you chose, every name you serve, and a chain made of your certificate plus its intermediates. A chain of one usually means the intermediate is missing.
How to fix common issues
Certificate is not trusted
Install a certificate from a public certificate authority, and configure the server to send the full chain (your certificate plus intermediates).
Certificate does not cover this hostname
Issue a certificate whose subject alternative names include this hostname, or a wildcard that covers it, and install it.
Certificate has expired
Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.
Certificate is not yet valid
Check the server's clock and the certificate's validity dates, and install a certificate that is valid now.
Cyber Essentials and ISO 27001
Certificates are part of cryptographic key management, which ISO/IEC 27001:2022 places under Annex A 8.24, use of cryptography. A trusted, correctly named certificate is technical evidence for that control on one public service. The rules behind it are for the organisation to set: which authorities may issue for its domains, how private keys are protected and who approves a new certificate.
Knowing which certificates exist and who is responsible for each one belongs with the asset inventory (5.9, inventory of information and other associated assets). Cyber Essentials does not address certificates directly.
Scope and limitations
- Revocation is not checked, so a certificate its authority has revoked can still show as trusted here.
- Trust is judged against Mozilla's root store. Other platforms keep their own lists, which largely but not exactly match it, and a certificate from a private CA trusted inside your organisation will show as untrusted.
- The certificate is read from a TLS 1.2 or 1.3 handshake. A server that cannot complete one gets an HTTPS finding instead, and its certificate is not read.
- Certificates for other names, such as mail or API hosts, need their own run, one subdomain at a time.
Related guides
Questions
- What is an SSL certificate?
- The certificate a server presents during a TLS handshake. It lists the hostnames it is valid for and carries a public key, signed by a certificate authority. The SSL in the name is historical; the protocol in use is TLS.
- Why does my certificate work in a browser but fail elsewhere?
- Often because the server does not send its intermediate certificate. Some browsers fill the gap from their own cache, while command-line tools, apps and other servers cannot. Configure the server to send the full chain.
- Does a wildcard certificate cover the bare domain?
- No. A wildcard such as *.example.org covers names one level below, like www.example.org, but not example.org itself or a.b.example.org. Most certificates list the bare domain as a second name alongside the wildcard.
Related security tools
- Certificate expiry checker - See when a site's TLS certificate expires and how many days are left.
- CAA checker - See which certificate authorities a domain allows to issue its certificates.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.

