# It there a command to show how many days certificate you have?

**URL:** <https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351>\
**Category:** Server\
**Created:** [February 22, 2016, 8:53pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351 "2016-02-22T20:53:05Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ray/32/1500_2.png) [@Ray](https://community.letsencrypt.org/u/Ray)\
**Post date:** [February 22, 2016, 8:53pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/1 "2016-02-22T20:53:05Z")

</div>

Just tell the command to show how many days have left before you have to renew?

I don’t know if. I hope some one knows and will reply to this post.

-Raymond Day

---

<div class="post-metadata">

**Author:** ![redo\_fr](https://avatars.discourse-cdn.com/v4/letter/r/9fc29f/32.png) [@redo\_fr](https://community.letsencrypt.org/u/redo_fr)\
**Post date:** [February 22, 2016, 9:15pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/2 "2016-02-22T21:15:42Z")

</div>

Hi.  
Try with:

> echo | openssl s\_client -connect \<you server here\>:443 2\>/dev/null | openssl x509 -noout -dates

Reply example:

> notBefore=Feb 22 08:56:00 2016 GMT  
> notAfter=May 22 08:56:00 2016 GMT

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [February 22, 2016, 11:07pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/3 "2016-02-22T23:07:36Z")

</div>

@Ray, just a little comment to @redo_fr post. If you are using [SNI](https://en.wikipedia.org/wiki/Server_Name_Indication) in your web server, add `-servername yourdomain.tld` parameter to openssl command or you could only get the default cert in your web server.

Something like this:  
`echo | openssl s_client -connect yourdomain.tld:443 -servername yourdomain.tld 2>/dev/null | openssl x509 -noout -dates`

You can also check the cert file directly:  
`openssl x509 -noout -dates -in /etc/letsencrypt/live/yourdomain.tld/cert.pem`

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![Ray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ray/32/1500_2.png) [@Ray](https://community.letsencrypt.org/u/Ray)\
**Post date:** [February 23, 2016, 2:24am UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/4 "2016-02-23T02:24:44Z")

</div>

Very good looks like that worked.

> root@XXX:~/letsencrypt# echo | openssl s\_client -connect XXX.XXX:443 2\>/dev/null | openssl x509 -noout -dates  
> notBefore=Feb 19 10:09:00 2016 GMT  
> notAfter=May 19 10:09:00 2016 GMT  
> root@XXX:~/letsencrypt#

So it will last till 5/19/2016 super good to know.

Thank you.

-Raymond Day

---

<div class="post-metadata">

**Author:** ![Nit](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nit/32/3699_2.png) [@Nit](https://community.letsencrypt.org/u/Nit)\
**Post date:** [February 23, 2016, 11:32am UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/5 "2016-02-23T11:32:05Z")

</div>

I use [ssl-cert-check](https://tracker.debian.org/pkg/ssl-cert-check) which is packaged on debian like systems and I find it very handy.

```
root@XXX# ssl-cert-check -c cert.pem 

Host Status Expires Days
------------------------------------------- ------------ ------------ ----
FILE:cert.pem Valid May 10 2016 77                                 

```

–

```
root@XXX# ssl-cert-check -h
Usage: /usr/bin/ssl-cert-check [-e email address] [-x days] [-q] [-a] [-b] [-h] [-i] [-n] [-v]
       { [-s common_name] && [-p port] } || { [-f cert_file] } || { [-c certificate file] }

  -a : Send a warning message through E-mail
  -b : Will not print header
  -c cert file : Print the expiration date for the PEM or PKCS12 formatted certificate in cert file
  -e E-mail address : E-mail address to send expiration notices
  -f cert file : File with a list of FQDNs and ports
  -h : Print this screen
  -i : Print the issuer of the certificate
  -k password : PKCS12 file password
  -n : Run as a Nagios plugin
  -p port : Port to connect to (interactive mode)
  -s commmon name : Server to connect to (interactive mode)
  -t type : Specify the certificate type
  -q : Don't print anything on the console
  -v : Specify a specific protocol version to use (tls, ssl2, ssl3)
  -V : Only print validation data
  -x days : Certificate expiration interval (eg. if cert_date < days)

```

The script is also available at [http://prefetch.net/code/ssl-cert-check](http://prefetch.net/code/ssl-cert-check)

---

<div class="post-metadata">

**Author:** ![Ray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ray/32/1500_2.png) [@Ray](https://community.letsencrypt.org/u/Ray)\
**Post date:** [February 23, 2016, 4:22pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/6 "2016-02-23T16:22:00Z")

</div>

Thank you looks like a good one. Can install it with the apt-get command it said it like this:

> The program 'ssl-cert-check' is currently not installed. You can install it by typing:  
> apt-get install ssl-cert-check

But I guess I have to type something else because I get this error:

root@XXX:~/letsencrypt# ssl-cert-check -c cert.pem

Host Status Expires Days

* * *

ERROR: The file named cert.pem is unreadable or doesn't exist  
ERROR: Please check to make sure the certificate for FILE:cert.pem is valid  
root@XXX:~/letsencrypt#

Is there another name for the cert.pem?

-Raymond Day

---

<div class="post-metadata">

**Author:** ![Ray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ray/32/1500_2.png) [@Ray](https://community.letsencrypt.org/u/Ray)\
**Post date:** [February 23, 2016, 4:34pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/7 "2016-02-23T16:34:04Z")

</div>

Looks like I have to tell it were the cert.pem file is:

> root@XXX:~# ssl-cert-check -c /etc/letsencrypt/live/XXX.XXX/cert.pem

> Host Status Expires Days
> 
> * * *
> 
> FILE:/etc/letsencrypt/live/XXX.XXX/cert.pem Valid May 22 2016 89  
> root@XXX:~#

Is something wrong because I have to tell it the full path?

**Thank you for showing this command!** Looks like a very good one to show when it will expire. Looks like I have 89 days left.

-Raymond Day

---

<div class="post-metadata">

**Author:** ![Nit](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nit/32/3699_2.png) [@Nit](https://community.letsencrypt.org/u/Nit)\
**Post date:** [February 23, 2016, 5:00pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/8 "2016-02-23T17:00:05Z")

</div>

I was in the /etc/letsencrypt/live/XXX.XXX/ directory when I issue my command “ssl-cert-check -c cert.pem”. If you are not in a directory with a cert.pem file in it, It is normal to get an error saying the file do not exist as every path no beginning with a ‘/’ are assume to be relative to the current directory.

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [February 23, 2016, 5:02pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/9 "2016-02-23T17:02:22Z")

</div>

You can also use [https://github.com/srvrco/checkssl](https://github.com/srvrco/checkssl) if you want to ( it was written specifically to inform, or run a specific job when renewal was close). On the other hand, not that the LE script auto renews the certificate when it’s within 30 days of renewal there is less need for checking.

---

<div class="post-metadata">

**Author:** ![Ray](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ray/32/1500_2.png) [@Ray](https://community.letsencrypt.org/u/Ray)\
**Post date:** [February 23, 2016, 5:49pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/10 "2016-02-23T17:49:32Z")

</div>

I think it’s good to have to renew it so they know you still are there.

The checkssl is not a apt-get so I don’t want to install it. Thanks for showing it.

-Raymond Day

---

<div class="post-metadata">

**Author:** ![RapaciousBodhisattva](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rapaciousbodhisattva/32/6651_2.png) [@RapaciousBodhisattva](https://community.letsencrypt.org/u/RapaciousBodhisattva)\
**Post date:** [December 21, 2016, 1:18am UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/12 "2016-12-21T01:18:24Z")

</div>

ubuntu 16.04

```auto
sudo apt-get install ssl-cert-check 

ssl-cert-check is already the newest version (3.27-2).

```

---

<div class="post-metadata">

**Author:** ![ThomasG77](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/thomasg77/32/15322_2.png) [@ThomasG77](https://community.letsencrypt.org/u/ThomasG77)\
**Post date:** [August 2, 2017, 6:12pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/13 "2017-08-02T18:12:25Z")

</div>

If you use certbot ([https://certbot.eff.org/](https://certbot.eff.org/)), it’s simply a matter of using

```
certbot certificates

```

If you need to filter for a particular domain the result, do

```
certbot certonly --cert-name example.com

```

This answer has been clearly borrowed from the official certbot documentation at [https://certbot.eff.org/docs/using.html#where-are-my-certificates](https://certbot.eff.org/docs/using.html#where-are-my-certificates)

---

<div class="post-metadata">

**Author:** ![webowner](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/webowner/32/17464_2.png) [@webowner](https://community.letsencrypt.org/u/webowner)\
**Post date:** [February 22, 2018, 3:24pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/14 "2018-02-22T15:24:37Z")

</div>

You can set that command up on your cronjob to check the expiration dates quite regularly and send you an e-mail notification or something whenever they are about to expire. I personally prefer using **[SSL Checker](https://itunes.apple.com/us/app/ssl-checker/id1347743213?mt=8)** app for iPhone for this purpose. I can monitor any host there and it sends me a notification whenever any of my SSL certificates is about to expire.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [April 25, 2018, 6:46pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/15 "2018-04-25T18:46:19Z")

</div>

A post was split to a new topic: [Certbot: “Certificates” command shows different expiry dates than OpenSSL](https://community.letsencrypt.org/t/certbot-certificates-command-shows-different-expiry-dates-than-openssl/60446)

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [May 28, 2018, 8:23pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/16 "2018-05-28T20:23:33Z")

</div>

A post was split to a new topic: [Openssl and browsers show different expiration dates](https://community.letsencrypt.org/t/openssl-and-browsers-show-different-expiration-dates/63047)

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [May 28, 2018, 8:29pm UTC](https://community.letsencrypt.org/t/it-there-a-command-to-show-how-many-days-certificate-you-have/11351/17 "2018-05-28T20:29:25Z")

</div>


