Checking SSL Certificate Status

How Plenix probes and grades your clients’ certificates from A+ to F, discovers them automatically, and warns you before one expires or fails.

Overview

Plenix doesn't just read a certificate's expiry date β€” it makes a live TLS connection to each domain, checks the whole chain, and grades what it finds the way a browser would judge it.

  1. Go to Monitoring β†’ SSL Certificates.
  2. The table shows each domain, its grade, expiry date, and days remaining.
  3. Certificates known from a monitored device or company are picked up automatically β€” look for the Auto-discovered tag and its source.
  4. To add one yourself, click Add Certificate and it's checked immediately (Add & check now).
  5. Click a row to see full certificate details (issuer, SANs, chain, TLS version, key strength), or click Re-check now to probe it again on demand.

How grading works

Every certificate is scored A+ down to F, deliberately harsh at the bottom: anything that would interrupt a visitor in their browser is an F, no matter how modern the rest of the setup is.

GradeWhen it's given
FUnreachable, expired, self-signed, an invalid chain, a SHA-1/MD5 signature, or an RSA key under 2048 bits
DStill on TLS 1.0, 1.1, or plain SSL
C7 days or fewer until expiry
B30 days or fewer until expiry, or a sound cert not yet on TLS 1.3
ATLS 1.2, healthy chain, expiry not imminent
A+TLS 1.3, healthy chain, expiry not imminent

An automatic sweep re-probes every certificate nightly, so a grade or an expiry countdown never goes stale between visits to the page.

Alerts

Certificates expiring within 30 days show an amber warning; within 7 days show red. Configure expiry alerts under an alert template using the ssl_days_remaining metric to receive email warnings ahead of either threshold.

Where to go next

Was this article helpful?

Checking SSL Certificate Status β€” Device Monitoring | Plenix Docs | Plenix Docs