To check a website’s SSL/TLS certificate, inspect its validity dates and confirm that it covers the exact hostname in your browser’s address bar. If the dates look valid but the browser still warns you, check the certificate chain and trust configuration. You can inspect what your browser received, use OpenSSL to test a specific host and port, or run Qualys SSL Labs’ test against a publicly reachable server.
What to check on a website certificate
A browser warning does not necessarily mean the certificate has expired. Certificate verification checks several things, including the certificate’s validity period, whether it covers the requested hostname, and whether the client can build a trusted chain from the server certificate to a trusted root.
- Validity: Compare the certificate’s “Valid to” or “Not After” date and time with the current date and time. If the end time has passed, the certificate is expired. A future end date does not prove the rest of the configuration is correct.
- Hostname: Check that the certificate covers the exact name in the address bar. A certificate for example.com may not cover www.example.com unless both names are included or covered by an applicable wildcard.
- Certificate chain: The server typically needs to provide intermediate certificates that let the client connect its certificate to a trusted root. A missing intermediate or an issuer the client does not trust can cause verification to fail even when the visible server certificate has not expired.
Check the certificate in Firefox
Firefox can show the certificates presented during that browser’s connection. Labels and navigation can vary by release, so follow the current wording in your installed version.
- Open the site and select the site-information control beside the address bar.
- Open the connection details and more site information, then select View Certificate.
- Review the server certificate’s validity period, issuer, and names. In particular, check that a Subject Alternative Name entry covers the hostname currently shown in the address bar.
- If Firefox displays a warning page, open the certificate details from that page and inspect the same information.
Mozilla’s certificate viewer describes separate tabs for the TLS server certificate, intermediate certificate, and root certificate. The browser view tells you what Firefox received for that connection; it does not automatically establish what another device, browser, or endpoint will receive. Mozilla Support: Secure website certificate
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Inspect the server with OpenSSL
OpenSSL’s s_client utility can connect to a particular HTTPS hostname and display the certificate chain and verification result. From a terminal, run:
openssl s_client -connect example.com:443 -servername example.com -showcerts -verify_return_error
Replace example.com with the exact hostname you want to test. The command uses port 443, the standard HTTPS port; change it if the service listens on another port.
Rank #2
-servernamesends the hostname through SNI (Server Name Indication). This matters when several HTTPS sites share an IP address and the server selects a certificate based on the requested name.-showcertsdisplays the certificates sent by the server.-verify_return_errormakes verification errors abort the handshake. Without it,s_clientis designed to continue after certificate verification errors.
OpenSSL’s TLS guide shows Verification: OK as a successful trust check in its example. An error such as unable to get local issuer certificate means the client could not find an issuer in its trust store. Possible causes include a server that did not send a needed intermediate certificate, a local trust-store problem, or an issuer that store does not recognize. Output depends on the OpenSSL version, the trust store in use, and the server’s response. Check openssl s_client -help for options supported by your installed version; this diagnostic command is not a reason to disable certificate verification in normal applications. See the OpenSSL s_client documentation and the OpenSSL TLS guide to certificate verification failures.
Run an online test of a public server
Qualys SSL Labs’ SSL Server Test performs a deeper analysis of a web server configuration reachable on the public Internet. Enter the hostname and review its certificate and configuration findings: Qualys SSL Labs SSL Server Test.
Recommended Free Tools
Rank #3
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
This test is for a public server. It may not reflect a private service, a different port or endpoint, or the trust environment of the particular client where the warning occurred.
Understand common certificate problems
Expired certificate
The server certificate’s validity end time has passed. A site owner should renew or replace it and ensure the intended certificate is deployed on every relevant serving endpoint. Recheck the live endpoint after deployment.
Rank #4
Hostname mismatch
The certificate does not cover the hostname requested by the browser. Confirm that you are testing the intended www or non-www address, then check which certificate the server selects for that hostname.
Missing intermediate certificate
The server may be sending its own certificate without an intermediate needed to build a chain to a trusted root. The site owner should install and serve the complete intended chain, then test again with a fresh client.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesUntrusted issuer or local trust-store problem
A client may be unable to build a trusted path because the server chain is incomplete, the issuer is not recognized, or the affected device’s trust store has a problem. Compare results from another client and inspect the chain before changing the server or device configuration.
Different results across devices or tests
First compare the exact hostname, port, and endpoint. A browser, an OpenSSL command, and a remote scanner can reach different server instances or use different trust contexts. Cloudflare also identifies SNI compatibility as a possible source of errors for some older clients; treat the browser’s exact error message as a clue, then verify the certificate and chain rather than diagnosing by message alone. See Cloudflare’s general SSL errors guide (updated April 16, 2026).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose the right check
| Method | Best for | Main limitation |
|---|---|---|
| Browser certificate viewer | A quick look at certificate details received by that browser. | Navigation is browser-specific, and the result reflects that browser’s connection context. Mozilla Support |
OpenSSL s_client |
Inspecting certificates sent by an endpoint and checking verification output. | Options and output depend on version and trust store; by default the test utility can continue after verification errors. OpenSSL s_client documentation OpenSSL TLS guide |
| Qualys SSL Labs SSL Server Test | A remote configuration assessment of a publicly reachable web server. | It may not reproduce a private endpoint or an individual client’s environment. Qualys SSL Labs |
What to do when a browser shows a certificate warning
If you operate the website, use the findings to correct the renewal, hostname, certificate deployment, or chain configuration, then retest the same hostname and port. If you are an ordinary visitor, do not bypass the warning for sign-ins, payments, or other sensitive activity. The warning means the browser could not establish the expected secure connection; ask the site owner or try again once the issue has been resolved. Cloudflare’s SSL troubleshooting guide maps several browser error strings to possible SSL/TLS problems, but the precise cause still needs to be verified.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

