SSL Expiry
This page explains how go-web-monitor gets the days remaining on a site's SSL certificate and the color thresholds in the table.
How It Works
util.CheckExpire() (internal/util/ssl.go:11) runs after the HTTP request gets a response:
- Strips the
https://prefix from the URL and takes the text before the first/as the hostname. - Dials
<host>:443withtls.Dial, using the system's default certificate verification. - Reads
NotAfterfrom the first certificate the server sends (the leaf certificate). - Days remaining = hours until
NotAfter÷ 24, truncated to an integer.
Any failed step returns 0, and the table shows N/A.
Color Thresholds
| Days remaining | Table text | Color |
|---|---|---|
| > 30 | N Days |
Green |
| 8–30 | N Days |
Yellow |
| 1–7 | N Days |
Red |
| 0 or unavailable | N/A |
Red |
Days remaining appear only in the table and never trigger an email; alerts cover offline sites only (see Alert Rules).
When the Certificate Is Unavailable
| Case | Cause |
|---|---|
Sites monitored over http:// |
The http:// prefix is not stripped, so the hostname resolves to http: and the dial fails |
URLs with a custom port (e.g. https://example.com:8443) |
The hostname keeps the port, so appending :443 produces an invalid address; certificates are read from port 443 only |
| Certificate verification fails (self-signed, expired, hostname mismatch) | tls.Dial uses default verification and returns an error on failure |
| The HTTP request itself fails | The SSL check does not run |