StatOSS

SSL certificate monitoring

A TLS handshake with your host every hour, and an alert when the certificate is wrong for the name, expired, or about to expire.

northwind.statoss.comPublic page

Northwind is up.

The monitor is responding.

Certificate for northwind.example

Up for 23 h 58 min100% passed

1,438 checks, median 48 ms, all passed

95% under 68 ms

A certificate monitor, checked once an hour, with made-up data. The bar height is the time of the TLS handshake; a certificate inside its warning window turns the whole strip red until it is renewed.

How the check works

A certificate monitor opens a TLS connection to the host and port you name and looks at the certificate it is handed. It fails when the certificate is not valid for the name, has expired, or expires within the number of days you set, 14 unless changed. The check runs once an hour rather than every minute, since a certificate does not change between checks and the warning window is measured in days. It works for any host that speaks TLS, not only websites: a mail server, a database with TLS, an internal API on a public name.

Why a separate check

An ordinary website monitor catches an expired certificate, because the TLS handshake fails and the check does with it. By then the site is already down. The certificate monitor fails inside the warning window, so the renewal that did not run, or the automation that quietly broke months ago, gets fixed while the old certificate still has days left. A domain expiry monitor covers the other renewal.

When it counts as down

A certificate monitor counts as down after two failed checks in a row and as back after one success. Before a failure counts, it is checked again in the same region; only a failure both checks see goes on the record. On Hobby and Pro every other region checks at the same moment, so the page can say down from North America instead of down. A single failed check still appears on the strip with its time and reason, it just does not change the state or send an alert.

Alerts

Each change of state sends one alert: down, and back, with how long it was out. Email is on every plan. Hobby and Pro add Slack, Discord, Microsoft Teams, Telegram, PagerDuty, Opsgenie, Pushover, ntfy and a signed webhook, plus a repeat notice every so many minutes while an outage lasts. Nothing is sent during a maintenance window.

What the status page shows

Every certificate monitor gets a strip on the public page. Each bar is one check, its height the response time; amber marks a timeout and red any other failure. Consecutive failures are grouped into one entry with the time and the reason, and the mark stays there for the whole range. A certificate monitor going down opens an incident on the page by itself and resolves it on recovery.