SSL certificates secure your website with HTTPS. It’s important to check your certificate’s validity and expiry date regularly. You can do this using OpenSSL on macOS, Linux, Windows, via local SSH terminal, directly through the Terminal tool inside cPanel, or using the cPanel SSL/TLS interface.
1. Check SSL Certificate Validity Dates (General Command)
Use this command, replacing example.com with your domain:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates
Example Output:
notBefore=Aug 15 00:00:00 2024 GMT notAfter=Nov 13 23:59:59 2025 GMT
- notBefore → when the certificate became valid
- notAfter → when the certificate expires
2. macOS
- Open Terminal.
- Run the command above.
3. Linux
- Open a terminal.
- Run the same command.
If OpenSSL isn’t installed:
- Ubuntu/Debian:
sudo apt update && sudo apt install openssl -y
- CentOS/RHEL/Fedora:
sudo yum install openssl -y
4. Windows (Local Machine)
Option A: Use WSL (Windows Subsystem for Linux)
- Install WSL.
- Open Ubuntu (or another Linux distro).
- Run the command.
Option B: Install OpenSSL for Windows
- Download Win32 OpenSSL.
- Add it to your PATH.
- Open Command Prompt or PowerShell, then run:
echo | openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -dates
5. Using a Local SSH Terminal (Mac, Linux, or Windows with PuTTY/WSL)
You can connect to your Ecenica Hosting account via SSH and check the SSL certificate directly from the server.
- Open your terminal (Mac/Linux) or PuTTY/WSL (Windows).
- Connect to your hosting account using SSH:
ssh yourusername@yourdomain.com -p 22
- Replace
yourusernamewith your cPanel username. - Replace
yourdomain.comwith your domain name.
- Replace
- Enter your cPanel password when prompted.
- Once logged in, run the OpenSSL command:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates
- You’ll see the certificate validity dates.
6. Using the Terminal Tool in cPanel (Easiest for Windows Users)
If you don’t want to install OpenSSL locally, you can run the check directly from cPanel’s Terminal tool:
- Log in to your Ecenica cPanel.
- In the Advanced section, click Terminal.
- You’ll get a warning about advanced use — click I understand and want to proceed.
- A command-line window will open inside cPanel (this is SSH access in your browser).
- Run the same OpenSSL command:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates
- You’ll see output like:
notBefore=Aug 15 00:00:00 2024 GMT notAfter=Nov 13 23:59:59 2025 GMT
That’s your certificate’s valid from and expiry date.
7. Using cPanel’s Built-in SSL Tools (No Commands Needed)
cPanel also provides a GUI for checking SSL/TLS certificates without using the terminal.
SSL/TLS Status
- Log in to cPanel.
- Go to Security → SSL/TLS Status.
- Find your domain in the list:
- Green lock / AutoSSL Domain Validated → certificate is active and valid.
- Red X / No Certificate → certificate missing or invalid.
- Expiry dates are shown here, and you can also re-run AutoSSL.
SSL/TLS Manager
- In cPanel → Security → SSL/TLS, you can:
- View installed certificates.
- Upload or delete certificates.
- Manage private keys and CSRs.
AutoSSL
- AutoSSL automatically issues and renews SSL certificates for your domains.
- You can manually re-run AutoSSL if you recently added or updated a domain.
8. Extra Checks
-
Expiry only:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -enddate
-
Full details (issuer, subject, SANs, etc.):
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -text