SSL certificate expiry alerts: from spreadsheet to alerts someone acts on

The spreadsheet and shared calendar worked when one team owned a dozen hostnames and certificates lasted a year. It fails quietly at scale. Ownership churn leaves rows with ex-employees still listed as contacts. New certificates never get a row because issuance happened in a cloud console, not through the process that fed the sheet. Renewal in a vault is not deployment to the listener — and nobody updates the calendar when the VIP still serves the old serial.

Monitoring-only tools can email you that not_after approaches while leaving renewal and rollout manual. Alerting is the floor; automation is the fix. But bad alerts are worse than no alerts — they train on-call to ignore the channel. Design alerts people act on.

Alert on remaining validity, not anniversaries

Alert on remaining validity thresholds — 30, 14, and 7 days before expiry — not on issue dates or anniversary reminders. Issue-date alerts drift the moment a CA re-issues early or a hotfix shortens the lifetime. Thresholds tied to not_after match what breaks in production. Shorter lifetimes under CA/Browser Forum SC-081 make 14-day-only alerting a late surprise; layer thresholds so the first signal still leaves time for DNS validation and deployment.

Route to owners and escalate

Route alerts to the owning team, not a shared inbox that becomes someone else's problem. Map discovery data — hostname, cloud resource, agent tag — to a service catalog or team channel. Escalate unacknowledged alerts: if nobody acknowledges within a defined window, page the platform on-call or the security duty roster. Shared mailboxes without escalation are where certificates go to expire politely.

Failed renewal is the leading indicator

Alert on failed renewal immediately, not only when expiry is near. A stalled ACME validation 30 days out is fixable; the same failure discovered at 24 hours is an outage. Challenge failures, CAA denials, and rate limits belong in the same severity class as imminent expiry — they are the leading indicator. The Key Vault cert that expired without an alert is the storage-without-lifecycle pattern: the cert looked managed until it was not.

Verify the deployed certificate

Verify the deployed certificate, not just the issued one. Compare serial number or SHA-256 fingerprint on the live TLS endpoint against what your CA or vault shows as current. Issuance succeeded and deployment never ran is the most common false green in dashboards. This check catches load balancers still pinned to last month's PEM while Key Vault already holds the replacement. Schedule fingerprint checks after every renewal job, not only on the weekly scan — deployment lag is measured in hours, not weeks.

Keep the channel trustworthy

Noise control keeps channels trustworthy. Suppress repeat alerts for the same cert once acknowledged, but reopen if fingerprint checks still fail or not_after crosses the next threshold. Document runbook links in the alert body — which DNS zone, which listener, which vault secret — so the recipient does not start from a search. Alerts that require archaeology get muted; alerts that name the fix get acted on.

Watch the watchers. The monitoring stack, webhook endpoints, and bastion hosts that receive alerts all use TLS too. When the observer's own cert expires, you lose visibility precisely when you need it — see the monitoring tool whose cert expired. Include those endpoints in the same inventory and threshold policy as customer-facing services.

Incidents still happen when alerts were theoretically configured. The operational cost — downtime, war rooms, audit findings — is why teams move from calendar to inventory-backed alerting. Read certificate expiry incident cost for why finance should treat missed alerts as a reliability risk, not an IT hygiene item.

Automate Certificates discovers certificates continuously, alerts on remaining validity and renewal failures, and automates renewal through ACME and Key Vault integration — so the alert and the fix live in the same place. It is not a certificate authority; it is the control plane that makes alerts actionable. See features for discovery, alerting, and renewal automation.