Example 1
- expiry 2024-04-01
- threshold 30
91
How many days at 2024-04-01 vs 2024-01-01? 91. Typed dates, not a live CA.
Type an expiry date. 2024-04-01 vs frozen 2024-01-01 gives 91. 2024-01-31 gives 30. 2025-01-01 gives 366. Typed dates, not a live CA.
Local-midnight difference versus frozen 2024-01-01 from the JSON. Not a CA handshake. The notBefore span sits on SSL Certificate Validity.
Enter data and click Calculate.
SSL Certificate Expiry in this calculator counts days from the typed date. 2024-04-01 versus frozen 2024-01-01 gives 91. 2024-01-31 gives 30. 2025-01-01 gives 366. Extras keep those dates, not the browser clock and not a live CA.
Field ssl-certyfikat-dni-date is the date. Field ssl-certyfikat-dni-warn-days in the examples is 30, 14, and 30, but primary stays the day count. 2024-04-01 minus 2024-01-01 = 91. 31 January is 30. 2025-01-01 in a leap year is 366.
91 does not come from openssl s_client. 30 is not NotAfter from Let's Encrypt. 366 is not a CA probe. You type the date. The calculator does not call a CA.
SSL Certificate Validity next door counts the span of two dates. Timezone converts an hour. Here 2024-04-01 stays 91, days from the typed date.
Type 2024-04-01 and threshold 30, then Calculate. The extras result is 91 versus 2024-01-01. This is not a live certificate.
2024-04-01 gives 91. 2024-01-31 gives 30. 2025-01-01 gives 366. Another date changes 91. There is no live CA.
days = round((expiry - reference_day) / 86400000). Extras vs 2024-01-01. Typed dates, not a live CA.
Typed dates, not a live CA. 2024-04-01 gives 91. 2024-01-31 gives 30.
91
How many days at 2024-04-01 vs 2024-01-01? 91. Typed dates, not a live CA.
30
What about 2024-01-31? 30.
366
What about 2025-01-01? 366. A leap year.
91. Typed dates, not a live CA.
30. From 1 to 31 January.
366. 2024 is a leap year.
No. Typed date minus a reference day. No handshake.
The JSON scan froze that day. The live card counts from today; extras do not.
A warning in ssl-certyfikat-dni-warn-days. The result stays the day count.
No. Local midnight minus the reference midnight. Not a PEM stamp.
On SSL Certificate Validity. Here 91 from 2024-04-01 stays.
No. Without a date the calculator stops. This is not a live certificate.
The calculator counts bits, bytes or throughput from your numbers. Below are SI and bit definitions (NIST).
Page updated in 2026.
This calculator answers: how many days until expiry β from today to notAfter. It is a countdown, not the certificateβs full lifetime. Certificate expiry β domain registration expiry.
| Issuer / type | Typical validity | Notes |
|---|---|---|
| Let's Encrypt / ACME | 90 days | Designed for automated renewal (certbot and similar). |
| Commercial CA (DV/OV) | Up to 398 days | Maximum under CA/Browser Forum requirements since 2020. |
| Legacy EV certificates | Up to 2 years (historically) | New issuances now follow the same limits as DV/OV. |
| Internal CA / self-signed | Whatever the organization sets | Not bound by public CA/B Forum limits, but similar discipline still pays off. |
Once notAfter passes, browsers (Chrome, Firefox, Safari) block the connection with a warning like "Your connection is not private." Mobile apps and server-to-server clients (curl, HTTP libraries) fail certificate verification and abort the request β often with no user-facing message at all, just an error in a backend log.
notAfter β enough time to issue, validate the domain, and deploy.