# SSL Expiry

This page explains how go-web-monitor gets the days remaining on a site's SSL certificate and the color thresholds in the table.

## How It Works

`util.CheckExpire()` (`internal/util/ssl.go:11`) runs after the HTTP request gets a response:

1. Strips the `https://` prefix from the URL and takes the text before the first `/` as the hostname.
2. Dials `<host>:443` with `tls.Dial`, using the system's default certificate verification.
3. Reads `NotAfter` from the first certificate the server sends (the leaf certificate).
4. Days remaining = hours until `NotAfter` ÷ 24, truncated to an integer.

Any failed step returns `0`, and the table shows `N/A`.

## Color Thresholds

| Days remaining | Table text | Color |
|----------------|------------|-------|
| > 30 | `N Days` | Green |
| 8–30 | `N Days` | Yellow |
| 1–7 | `N Days` | Red |
| 0 or unavailable | `N/A` | Red |

Days remaining appear only in the table and never trigger an email; alerts cover offline sites only (see [Alert Rules](/alerting)).

## When the Certificate Is Unavailable

| Case | Cause |
|------|-------|
| Sites monitored over `http://` | The `http://` prefix is not stripped, so the hostname resolves to `http:` and the dial fails |
| URLs with a custom port (e.g. `https://example.com:8443`) | The hostname keeps the port, so appending `:443` produces an invalid address; certificates are read from port 443 only |
| Certificate verification fails (self-signed, expired, hostname mismatch) | `tls.Dial` uses default verification and returns an error on failure |
| The HTTP request itself fails | The SSL check does not run |
