ip
ipku.in

SSL Certificate Checker

Check a domain's SSL certificate the way a browser sees it: when it expires, which names it covers, who issued it, whether the chain is complete, and which TLS versions the server still accepts.

Result
Certificate has problems
expired 4189 days agovalid until Apr 12, 2015
1 pass1 warning2 fail

COMODO RSA Domain Validation Secure Server CA · COMODO CA Limited

DNS for this domain →Look up the server IP →Full analysis of this domain →json ↗

Checked directly from the ipku.in server: one TLS connection for the certificate, plus one per TLS version. The chain is judged against Mozilla's root CA list. A warning shows 14 days before expiry.

Checks
  • ×
    ValidityExpired 4189 days ago. Browsers show visitors a warning; install a new certificate.
  • ✓
    Domain nameThe certificate covers expired.badssl.com.
  • ×
    Certificate chainA certificate in the chain has expired.
  • !
    TLS versionsAccepts TLS 1.2, TLS 1.1, TLS 1.0. TLS 1.0 and 1.1 are obsolete and refused by modern browsers, so they should be turned off.
CertificateRSA 2048
name
*.badssl.com
SAN (2)
*.badssl.combadssl.com
issuer
COMODO RSA Domain Validation Secure Server CA · COMODO CA Limited
valid from
Apr 9, 2015
valid until
Apr 12, 2015
serial
4AE79549FA9ABE3F100F17A478E16909
sha-256
BA:10:5C:E0:2B:AC:76:88:8E:CE:E4:7C:D4:EB:79:41:65:3E:9A:C9:93:B6:1B:2E:B3:DC:C8:20:14:D2:1B:4F
Chain3
  1. ●
    *.badssl.comcertificate · valid until Apr 12, 2015
  2. └
    COMODO RSA Domain Validation Secure Server CAintermediate · valid until Feb 11, 2029
  3. └
    COMODO RSA Certification Authorityintermediate · valid until May 30, 2020
Connection:443
protocol
TLS 1.2
cipher
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
alpn
http/1.1
  • TLS 1.3refused
  • TLS 1.2accepted
  • TLS 1.1accepted
  • TLS 1.0accepted
01 / faq

SSL certificates, briefly.

What is an SSL certificate?

▼

An SSL (strictly, TLS) certificate proves that the server really belongs to the domain and encrypts the connection between browser and server. Without a valid one, browsers show a "Not secure" warning and visitors may leave.

Why does the browser say "not secure" when SSL is installed?

▼

The usual causes: the certificate has expired, it doesn't cover the name being opened (say, example.com but not www.example.com), the intermediate chain isn't installed, or the page loads images and scripts over http:// (mixed content). The first three show up in this check.

What does an incomplete chain mean?

▼

CAs issue certificates through an intermediate certificate, and the server has to send that intermediate along with the domain certificate. Desktop browsers can sometimes fill the gap themselves, but Android, curl, and many apps cannot, and refuse the connection. The fix is to install the CA bundle from the issuer together with the certificate.

How long is a Let’s Encrypt certificate valid?

▼

Let's Encrypt certificates are valid for 90 days and usually renew automatically about 30 days before they run out. If this check shows 14 days or fewer left, automatic renewal has probably failed, for example because the domain's DNS no longer points at the server.

Can I check ports other than 443?

▼

Yes. Pick the port next to the domain field: 465 (SMTPS), 993 (IMAPS), and 995 (POP3S) for mail servers, or 2083, 2087, and 2096 for cPanel, WHM, and webmail. Ports that use STARTTLS, like 25 and 587, are not supported yet.

Can I use it from a terminal?

▼

Yes. curl 'ipku.in/en/tools/ssl-check?q=example.com' returns the check as plain text, and /api/ssl/example.com returns JSON. Add &port=993 or ?port=993 for another port.