SSL/TLS Checker
SSL/TLS Checker helps you analyze ssl/tls certificate and configuration, for certificate inspection, HTTPS validation, and TLS troubleshooting.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
SSL/TLS Checker analyzes your website's SSL/TLS certificate and connection security, verifying encryption strength, certificate validity, expiration dates, and configuration issues.

Why It Matters
- →Security: Encrypts data between users and your server
- →Trust: Browsers show warnings for invalid or expired certificates
- →SEO: Google penalizes sites without HTTPS
- →Compliance: Required for PCI-DSS and many privacy regulations
How to Read Results
- Certificate Validity: Check "Valid From" and "Valid To" dates
- Common Name: Should match your domain name
- Issuer: Certificate Authority that signed the certificate
- Protocol Version: TLS 1.2 or 1.3 recommended (avoid TLS 1.0/1.1)
Technical Background
TLS (Transport Layer Security, RFC 8446) establishes encrypted communication channels using a multi-step handshake: (1) Client Hello — client sends supported TLS versions and cipher suites; (2) Server Hello — server selects version and cipher, sends certificate; (3) Certificate verification — client validates the certificate chain against trusted CAs; (4) Key Exchange — ECDHE or DHE generates a shared secret; (5) Session keys derived; (6) Encrypted data transfer begins. X.509 certificates (RFC 5280) contain the Subject, Issuer (CA), validity period, public key, Subject Alternative Names (SANs), and digital signature. Certificate chains must be complete: leaf certificate → intermediate CA(s) → root CA. Incomplete chains cause "unable to verify certificate chain" errors.
TLS versions: TLS 1.0 and 1.1 are deprecated (RFC 8996) — browsers removed support in 2020. TLS 1.2 remains widely supported but TLS 1.3 is preferred for performance (1-RTT handshake vs 2-RTT in 1.2) and forward secrecy (all cipher suites use ephemeral keys). Certificate types: Domain Validated (DV) — automated domain ownership check only; Organization Validated (OV) — vets company identity; Extended Validation (EV) — rigorous vetting for financial/legal entities. Free DV certificates from Let's Encrypt, ZeroSSL, and Google Trust Services have made HTTPS universal.
Common SSL/TLS vulnerabilities include: expired or soon-to-expire certificates (monitor expiry < 30 days), self-signed certificates not trusted by browsers, certificate/domain name mismatch (CN or SAN doesn't match the URL), weak cipher suites (RC4, 3DES, NULL, EXPORT ciphers), and outdated protocols. Security headers like HSTS (HTTP Strict Transport Security, RFC 6797) enforce HTTPS at the browser level. Certificate Transparency (RFC 9162) logs all issued certificates publicly, enabling detection of unauthorized certificate issuance for your domain.
Security professionals use automated certificate monitoring to prevent unexpected expirations. Lets Encrypt certificates expire every 90 days and require automated renewal via ACME protocol clients like Certbot or acme.sh. Commercial CAs issue 1-year certificates (2-year was deprecated by browsers in 2020). OCSP (Online Certificate Status Protocol, RFC 6960) allows real-time revocation checking without downloading full CRLs. OCSP Stapling improves performance by having the server pre-fetch and cache the OCSP response. Organizations managing many certificates should use a certificate lifecycle management (CLM) platform to track expiry dates, automate renewals, and ensure consistent security configurations across all endpoints.
Administrators should routinely test SSL/TLS configuration using tools like SSL Labs (ssllabs.com/ssltest), testssl.sh, or nmap with ssl-enum-ciphers script. These tools evaluate cipher strength, protocol versions, certificate chain completeness, HSTS policy, and known vulnerability exposure (POODLE, BEAST, HEARTBLEED, ROBOT). A strong SSL/TLS configuration scores A or A+ on SSL Labs. Key improvements include: enabling only TLS 1.2 and 1.3, using strong ECDHE cipher suites, enabling HSTS with minimum 1-year max-age, adding HSTS preload for browser list inclusion, and configuring OCSP stapling to reduce certificate validation latency for users.
Common Errors and How to Fix Them
- ProblemThe server sends only the leaf certificate without the intermediate, so desktop browsers work but curl, Java clients, older Android devices and API integrations report 'unable to get local issuer certificate'.
- FixConfigure the full chain: in nginx point ssl_certificate at fullchain.pem rather than cert.pem; in Apache 2.4.8+ include the intermediates in the SSLCertificateFile. Desktop browsers often hide the problem by fetching missing intermediates themselves.
- ProblemThe certificate covers www.example.com but visitors typing example.com get a name mismatch error.
- FixBrowsers validate only the Subject Alternative Name list, not the Common Name. Reissue the certificate with both names in the SAN, or a wildcard plus the apex, since *.example.com does not cover example.com itself.
- ProblemA free automated certificate expired because renewal silently failed after a firewall change blocked port 80 for the HTTP-01 challenge.
- FixKeep port 80 reachable for validation or switch to DNS-01, run 'certbot renew --dry-run' after infrastructure changes, and alert on certificates with fewer than 14 days remaining.
- ProblemThe certificate was renewed on disk but the site keeps serving the old one.
- FixWeb servers load certificates at start-up. Add a deploy hook that runs 'systemctl reload nginx' (or the equivalent) after each renewal and confirm here that the new expiry date is live.
- ProblemTLS 1.0 and 1.1 are still enabled for compatibility with an old client.
- FixBoth versions were formally deprecated by RFC 8996 and are rejected by current browsers. Restrict the server to TLS 1.2 and 1.3, for example 'ssl_protocols TLSv1.2 TLSv1.3;' in nginx.
- ProblemIssuance or renewal fails with a CAA error after switching certificate authorities.
- FixA CAA record (RFC 8659) lists which CAs may issue for the domain. Add the new CA, for example 'example.com. CAA 0 issue "letsencrypt.org"', before requesting the certificate.
Frequently Asked Questions
How long can a TLS certificate be valid today?
Under CA/Browser Forum ballot SC-081, the maximum lifetime of publicly trusted certificates dropped from 398 days to 200 days in March 2026, and is scheduled to fall to 100 days in March 2027 and 47 days in March 2029. Shorter lifetimes make automated renewal through ACME practically mandatory, so treat manual installation as a legacy process to phase out.
Why does my browser show a padlock while this checker reports a chain problem?
Desktop browsers cache intermediate certificates from earlier visits and can download missing ones using the Authority Information Access URL in the certificate. Command-line tools, payment gateways, webhooks and many mobile apps do not, so they fail on the same server. Serving the complete chain fixes every client instead of relying on browser workarounds.
Does it matter whether I use a DV, OV or EV certificate?
The encryption is identical; only the vetting differs. Domain Validated certificates prove control of the domain, while OV and EV add checks on the organization. Major browsers removed the special EV address-bar indicator years ago, so for most websites a DV certificate with reliable automation is the practical choice.
Can one certificate protect several domains?
Yes. A multi-domain certificate lists every hostname in its Subject Alternative Name extension, and a wildcard such as *.example.com covers any single-level subdomain like shop.example.com, but neither the apex nor deeper names like a.b.example.com. Wildcards require DNS-01 validation with ACME and spread risk: one leaked key exposes every covered host.
Is SSL the same thing as TLS?
TLS is the successor to SSL. SSL 2.0 and 3.0 are prohibited by RFC 6176 and RFC 7568, and TLS 1.0 and 1.1 are deprecated by RFC 8996. Modern servers should offer TLS 1.3 (RFC 8446) and TLS 1.2. The term 'SSL certificate' survives as marketing; the same X.509 certificate works with any protocol version.
Academic Documentation
Protocol context and primary references
Let's Encrypt
Free, automated SSL/TLS certificates
Open source →
SSL Labs
SSL/TLS testing and research by Qualys
Open source →
IETF
Internet Engineering Task Force
Open source →
RFC Editor
Official RFC documentation
Open source →
IANA
Internet Assigned Numbers Authority
Open source →
CAB Forum
Browser trust and certificate issuance baseline requirements.
Open source →
REST API Documentation
v1.0GET /api/tools/ssl-check
curl -X POST https://epcybertools.com/api/tools/ssl-check \
-H "Content-Type: application/json" \
-d '{"domain":"google.com","port":443}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# Check SSL certificate details
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -text
# Check expiry date
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -dates
# Verify certificate chain
openssl s_client -connect example.com:443 -showcerts