What it is
A TLS certificate near expiry with no automated renewal path in place is an outage waiting to happen. When the certificate expires, browsers surface a full-page warning and refuse to load the site by default, mail servers fail to negotiate TLS for STARTTLS on port 25, and API integrations break.
Why it matters
Directly, they don't need to. Indirectly, an expired certificate creates the exact user-training condition attackers benefit from: users learn to click through browser warnings, which primes them to click through the warnings that actually protect against phishing sites and man-in-the-middle attacks.
How anyone can check it
echo | openssl s_client -connect yourfirm.ca:443 2>/dev/null | openssl x509 -noout -enddateShows the date the certificate expires.
Remediation direction
Every internet-facing TLS certificate on ACME auto-renewal (Let's Encrypt, ZeroSSL) with monitoring on the renewal cron. For appliances that can't use ACME, calendar reminders 60 and 30 days before expiry plus a renewal-owner named in the reminder. Review the whole cert inventory quarterly, not just the ones the ops team remembers.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.