Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Infrastructure
Reference · Pattern

Public TLS certificate approaching expiry without automated renewal

Severity MediumKind InfrastructureEffort to fix TrivialUpdated 5 Aug 2026By LeakTrace
Definition

A production-facing TLS certificate is within the browser warning window and shows no evidence of ACME/auto-renewal, risking a hard outage and browser trust warnings.

What it is

A TLS certificate near expiry with no automated renewal path in place is an outage waiting to happen. When the certificate expires, browsers surface a full-page warning and refuse to load the site by default, mail servers fail to negotiate TLS for STARTTLS on port 25, and API integrations break.

Why it matters

Directly, they don't need to. Indirectly, an expired certificate creates the exact user-training condition attackers benefit from: users learn to click through browser warnings, which primes them to click through the warnings that actually protect against phishing sites and man-in-the-middle attacks.

How anyone can check it

echo | openssl s_client -connect yourfirm.ca:443 2>/dev/null | openssl x509 -noout -enddate

Shows the date the certificate expires.

Remediation direction

Every internet-facing TLS certificate on ACME auto-renewal (Let's Encrypt, ZeroSSL) with monitoring on the renewal cron. For appliances that can't use ACME, calendar reminders 60 and 30 days before expiry plus a renewal-owner named in the reminder. Review the whole cert inventory quarterly, not just the ones the ops team remembers.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →