The result shows the expiry date for the certificate visitors can receive.
Renewal runway
Turn the expiry date into a renewal plan.
Use this when the question is no longer just when does it expire, but who needs to act, when warnings should start, and what evidence proves the renewed certificate reached customers.
Issuer, expiry, fingerprint, SANs, chain depth, and page-specific evidence load in a dedicated result section below the hero.
Compare remaining time with renewal, review, deployment, and edge propagation.
Use hostname, deadline, issuer, serial, and fingerprint in the renewal ticket.
Move important hostnames into scheduled expiry monitoring.
Runway intent
Use this when the deadline needs an owner and a schedule.
The renewal runway planner narrows the live checker result to renewal operations: deadline pressure, warning windows, proof fields, and when a one-time check should become monitoring.
Start from the customer-facing deadline
The planner reads the certificate currently served by the public hostname, then turns the not-after date into renewal pressure instead of leaving the team with a date alone.
- Use the live not-after date as the deadline customers will hit.
- Compare remaining days with renewal, review, deployment, and edge propagation time.
- Capture issuer, serial number, and fingerprint when the renewed certificate should already be live.
Use staged warning windows
The result proposes 30, 14, 7, 3, and 1 day warning windows so teams can decide whether a hostname belongs in scheduled monitoring or a one-time follow-up ticket.
- Use 30 days for normal owner follow-up.
- Use 14 and 7 days for deployment verification.
- Use 3 and 1 days as emergency windows for customer-facing endpoints.
Write a handoff that can be acted on
A renewal task is easier to route when it includes the hostname, port, deadline, validation state, issuer, serial number, and fingerprint. The runway result groups those fields beside the alert schedule.
- Send the handoff to the certificate owner or platform team.
- Re-run the check after renewal to prove the public endpoint changed.
- Move recurring production deadlines into monitoring instead of relying on manual date checks.
If this runway matters after today, monitor the expiry window.
The planner turns one deadline into a renewal schedule. Monitoring repeats the check and warns before the window becomes urgent.
What is renewal runway?
Renewal runway is the time between the live certificate deadline and the work needed to renew, deploy, reload, and verify the certificate on the public endpoint.
Why can the runway differ from my renewal system?
Renewal systems can issue a new certificate before the public endpoint serves it. DNS, CDN, load balancer, or service reload issues can leave the old certificate in place, so the planner uses the certificate customers can receive now.
When should this become monitoring?
Monitor app, API, checkout, identity, CDN, and client hostnames where a missed 30, 14, 7, 3, or 1 day warning would create customer or operational risk.