Home / Docs / SSL Monitoring

Monitoring

SSL Monitoring

Get notified before certificates expire or become invalid.

SSL monitors open a TLS connection to your target, read certificate metadata, and track expiration windows. They alert before expiry and when certificate validation fails.

Frequency

SSL monitors do not run on minute-level intervals — there is no interval setting to configure. Healthy certificates are checked about once a day; monitors in a warning or failed state re-check roughly hourly so a renewed certificate recovers quickly.

Configuration Fields

  • Target: hostname or URL
  • Port: default 443
  • Warning days: threshold for expiring state (default 14)
  • Timeout: TLS connect timeout

Status Mapping

Condition Check Status Event
Certificate healthy and beyond warning windowupssl_ok on recovery transitions
Expires within warning dayslate (Warning)ssl_expiring — once, on transition
Certificate expired, not yet valid, hostname mismatch, self-signed, or untrusted chaindown (definitive — the certificate was retrieved and inspected)ssl_expired
Host unreachable / timeout / handshake failureConfirming… first; down only after consecutive confirmed failuresssl_expired after confirmation

Warning is not downtime

An expiring certificate shows as a Warning — it does not mark the monitor down, does not reduce uptime, and appears as Degraded (not an outage) on status pages. A network blip is never reported as a certificate problem: PulseBeacon confirms connectivity failures with follow-up probes and only classifies a certificate as expired or invalid when the certificate itself was actually retrieved and inspected.

Example Configurations

Standard HTTPS Site
Target: https://app.example.com
Port: 443
Warning days: 14
Timeout: 10
Custom TLS Port
Target: internal-gateway.example.net
Port: 8443
Warning days: 30
Timeout: 10

Troubleshooting

  • ssl_unreachable / ssl_connect_failed: DNS, network path, firewall, or port issue (confirmed before any Down).
  • ssl_handshake_failed: TLS negotiation failed (confirmed before any Down).
  • ssl_expired / ssl_not_yet_valid: certificate validity window problem (definitive).
  • ssl_hostname_mismatch: certificate does not cover the monitored hostname (definitive).
  • ssl_self_signed / ssl_chain_invalid: certificate is not signed by a trusted authority (definitive).
  • ssl_cert_missing / ssl_parse_failed: endpoint did not return a usable certificate.
  • The monitor details page shows the error category, exact reason text, and days remaining.