Skip to content

ReferenceThe 22 checks

SSL certificates

Health checkcertificates

What it reads

The certificates in /etc/letsencrypt/live, Caddy's certificate folders, and the certificate files named in nginx and Apache settings.

Does it need root?

It needs root for part of what it reads. Certificate folders such as /etc/letsencrypt/live can be read only by root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • count certificates, none expiring within limit days
  • No certificates found on this server

What it can find

Critical

SSL certificate for host expired days days ago

Browsers and apps are refusing to connect to host now.

Fix
sudo certbot renew --force-renewal

The fix changes with how the server is set up:

If Caddy serves the site
Caddy renews by itself, so find out why it has not: sudo journalctl -u caddy --since -24h | grep -i error
If another issuer made the certificate
Renew the certificate at path with whoever issued it, then reload the web server
Warning

SSL certificate for host expires in days days

When it expires, browsers and apps will refuse to connect.

Fix
sudo certbot renew

The fix changes with how the server is set up:

If Caddy serves the site
Caddy renews by itself, so find out why it has not: sudo journalctl -u caddy --since -24h | grep -i error
If another issuer made the certificate
Renew the certificate at path with whoever issued it, then reload the web server