Work out certificate expiry days instantly with clear inputs, formula shown and shareable results.
TLS certificate lifetimes have shortened steadily — public certificates are now capped near 398 days and ACME issuers default to 90 — which makes automated renewal essential rather than optional. Renewal should start well before expiry so there is time for retries, DNS propagation and validation failures; ACME clients conventionally renew at one third of remaining lifetime.
Expiry tracking
days remaining = validity - days elapsed; renewal due = days remaining - renewal threshold
Short lifetimes limit the damage from an undetected key compromise and reduce reliance on revocation, which has never worked reliably at internet scale.
At least one third of the validity period, and never less than about a week. That leaves room for a failed validation to be retried without an outage.