SSL Certificate Expiry

Type an expiry date. 2024-04-01 vs frozen 2024-01-01 gives 91. 2024-01-31 gives 30. 2025-01-01 gives 366. Typed dates, not a live CA.

Local-midnight difference versus frozen 2024-01-01 from the JSON. Not a CA handshake. The notBefore span sits on SSL Certificate Validity.

Input data

Results

Enter data and click Calculate.

How it works

SSL Certificate Expiry in this calculator counts days from the typed date. 2024-04-01 versus frozen 2024-01-01 gives 91. 2024-01-31 gives 30. 2025-01-01 gives 366. Extras keep those dates, not the browser clock and not a live CA.

Field ssl-certyfikat-dni-date is the date. Field ssl-certyfikat-dni-warn-days in the examples is 30, 14, and 30, but primary stays the day count. 2024-04-01 minus 2024-01-01 = 91. 31 January is 30. 2025-01-01 in a leap year is 366.

91 does not come from openssl s_client. 30 is not NotAfter from Let's Encrypt. 366 is not a CA probe. You type the date. The calculator does not call a CA.

SSL Certificate Validity next door counts the span of two dates. Timezone converts an hour. Here 2024-04-01 stays 91, days from the typed date.

Type 2024-04-01 and threshold 30, then Calculate. The extras result is 91 versus 2024-01-01. This is not a live certificate.

2024-04-01 gives 91. 2024-01-31 gives 30. 2025-01-01 gives 366. Another date changes 91. There is no live CA.

Formula

days = round((expiry - reference_day) / 86400000). Extras vs 2024-01-01. Typed dates, not a live CA.

How to use

  1. Type date 2024-04-01 and threshold 30.
  2. Click Calculate. Extras vs 2024-01-01 give 91.
  3. 2024-01-31 gives 30. 2025-01-01 gives 366.
  4. Typed dates, not a live CA.
  5. A notBefore span sits on SSL Certificate Validity.

2024-04-01 vs 2024-01-01 = 91

Typed dates, not a live CA. 2024-04-01 gives 91. 2024-01-31 gives 30.

SSL
A typed date, not a handshake. 91 does not come from a CA.
Certificate
The expiry field. 2024-01-31 gives 30. 2025-01-01 gives 366.
Expiry
The result. 2024-04-01 leaves 91. Not openssl.

Examples

Example 1

  • expiry 2024-04-01
  • threshold 30

91

How many days at 2024-04-01 vs 2024-01-01? 91. Typed dates, not a live CA.

Example 2

  • expiry 2024-01-31
  • threshold 14

30

What about 2024-01-31? 30.

Example 3

  • expiry 2025-01-01
  • threshold 30

366

What about 2025-01-01? 366. A leap year.

Related calculators

Common questions

How many days at 2024-04-01 vs 2024-01-01?

91. Typed dates, not a live CA.

What about 2024-01-31?

30. From 1 to 31 January.

What about 2025-01-01?

366. 2024 is a leap year.

Does the calculator call a CA or openssl?

No. Typed date minus a reference day. No handshake.

Why 2024-01-01 in the extras?

The JSON scan froze that day. The live card counts from today; extras do not.

Why threshold 30?

A warning in ssl-certyfikat-dni-warn-days. The result stays the day count.

Is 91 a UTC NotAfter?

No. Local midnight minus the reference midnight. Not a PEM stamp.

Where do I time a notBefore window?

On SSL Certificate Validity. Here 91 from 2024-04-01 stays.

Does a blank date count?

No. Without a date the calculator stops. This is not a live certificate.

Knowledge sources

The calculator counts bits, bytes or throughput from your numbers. Below are SI and bit definitions (NIST).

Page updated in 2026.

What certificate expiry means

This calculator answers: how many days until expiry β€” from today to notAfter. It is a countdown, not the certificate’s full lifetime. Certificate expiry β‰  domain registration expiry.

Why renewal planning matters

  • An expired certificate blocks traffic β€” browsers show a full-page warning, not a minor notice.
  • APIs and integrations (webhooks, mobile apps with certificate pinning) can start failing TLS handshakes with no visible UI warning at all.
  • Manual renewal is easy to miss β€” which is why the industry keeps moving toward shorter lifetimes and automation (ACME).

Typical certificate validity periods

Issuer / typeTypical validityNotes
Let's Encrypt / ACME90 daysDesigned for automated renewal (certbot and similar).
Commercial CA (DV/OV)Up to 398 daysMaximum under CA/Browser Forum requirements since 2020.
Legacy EV certificatesUp to 2 years (historically)New issuances now follow the same limits as DV/OV.
Internal CA / self-signedWhatever the organization setsNot bound by public CA/B Forum limits, but similar discipline still pays off.

What happens when it expires

Once notAfter passes, browsers (Chrome, Firefox, Safari) block the connection with a warning like "Your connection is not private." Mobile apps and server-to-server clients (curl, HTTP libraries) fail certificate verification and abort the request β€” often with no user-facing message at all, just an error in a backend log.

When to renew β€” the ~30-day window

  • For 90-day certificates (Let's Encrypt), automation typically renews around 60 days in (about 1/3 of the remaining lifetime).
  • For yearly certificates, a common reminder is 30 days before notAfter β€” enough time to issue, validate the domain, and deploy.
  • The calculator shows a recommended renewal window once 60 days or fewer remain.

Examples

  • Expires in 45 days, threshold 30 β€” status "Valid", no renewal window yet.
  • Expires in 12 days, threshold 30 β€” status "Expiring soon", renewal window shown.
  • Expired 5 days ago β€” status "Expired", immediate action required.