Monitoring
SSL Monitoring
Get notified before certificates expire or become invalid.
SSL monitors open a TLS connection to your target, read certificate metadata, and track expiration windows. They alert before expiry and when certificate validation fails.
Frequency
SSL monitors do not run on minute-level intervals — there is no interval setting to configure. Healthy certificates are checked
about once a day; monitors in a warning or failed state re-check roughly hourly so a renewed certificate recovers quickly.
Configuration Fields
- Target: hostname or URL
- Port: default 443
- Warning days: threshold for expiring state (default 14)
- Timeout: TLS connect timeout
Status Mapping
| Condition | Check Status | Event |
|---|---|---|
| Certificate healthy and beyond warning window | up | ssl_ok on recovery transitions |
| Expires within warning days | late (Warning) | ssl_expiring — once, on transition |
| Certificate expired, not yet valid, hostname mismatch, self-signed, or untrusted chain | down (definitive — the certificate was retrieved and inspected) | ssl_expired |
| Host unreachable / timeout / handshake failure | Confirming… first; down only after consecutive confirmed failures | ssl_expired after confirmation |
Warning is not downtime
An expiring certificate shows as a Warning — it does not mark the monitor down, does not
reduce uptime, and appears as Degraded (not an outage) on status pages. A network blip is
never reported as a certificate problem: PulseBeacon confirms connectivity failures with follow-up probes and only classifies
a certificate as expired or invalid when the certificate itself was actually retrieved and inspected.
Example Configurations
Standard HTTPS Site
Target: https://app.example.com
Port: 443
Warning days: 14
Timeout: 10
Custom TLS Port
Target: internal-gateway.example.net
Port: 8443
Warning days: 30
Timeout: 10
Troubleshooting
ssl_unreachable/ssl_connect_failed: DNS, network path, firewall, or port issue (confirmed before any Down).ssl_handshake_failed: TLS negotiation failed (confirmed before any Down).ssl_expired/ssl_not_yet_valid: certificate validity window problem (definitive).ssl_hostname_mismatch: certificate does not cover the monitored hostname (definitive).ssl_self_signed/ssl_chain_invalid: certificate is not signed by a trusted authority (definitive).ssl_cert_missing/ssl_parse_failed: endpoint did not return a usable certificate.- The monitor details page shows the error category, exact reason text, and days remaining.