Skip to content
Hivex tools · WebsiteFree · No account

SSL certificate of www.wikipedia.org.

See whether browsers trust a site's certificate, when it runs out, the chain its server sends, and which TLS versions it still accepts.

Looking up…

What the checker does.

  • It opens the site over HTTPS the way a browser does. If that connection refuses the certificate, browsers will refuse it too.
  • It then makes four short connections to port 443, each offering a single TLS version (1.3, 1.2, 1.1 and 1.0), and notes which ones the server accepts and the cipher it picks.
  • Offered TLS 1.2, a server sends its certificates before anything is encrypted. Hivex reads them (names, dates, issuer, key and signature) and hangs up before the handshake completes, so no page is ever requested that way.

What good looks like.

  • Trusted, with more than two weeks left, and renewed automatically.
  • The chain starts with the site's own certificate, then each intermediate, each issued by the next one; the root is left out.
  • TLS 1.3 and 1.2 accepted, 1.1 and 1.0 refused.
  • An RSA key of at least 2048 bits or an EC key (P-256 or P-384), signed with SHA-256 or stronger.

Fixing what it finds.

  • Expired or close to it: renew, then check that the renewal job (certbot, your host's panel) runs on its own and reloads the web server.
  • Name not covered: get a certificate that lists every name people type, both example.com and www.example.com.
  • Missing intermediate: point the server at the full chain (fullchain.pem with certbot), not the site's certificate alone.
  • Old TLS versions: in nginx, ssl_protocols TLSv1.2 TLSv1.3; in Apache, SSLProtocol -all +TLSv1.2 +TLSv1.3.

Questions people ask.

How long can an SSL certificate last?

Publicly trusted certificates issued since 15 March 2026 may last at most 200 days. The limit drops to 100 days from 15 March 2027 and to 47 days from 15 March 2029 (CA/Browser Forum ballot SC-081v3), so automatic renewal is the only practical way.

Is SSL the same as TLS?

SSL is the old name. SSL 2.0 and 3.0 are banned, and TLS 1.0 and 1.1 have been deprecated since 2021 (RFC 8996). A site should offer TLS 1.2 and 1.3 only; the certificate is the same whatever the name.

What is a certificate chain?

The site's own certificate plus the intermediate certificates that link it to a root your device already trusts. The server should send its certificate first and then the intermediates; the root itself is not needed.

Why do browsers say 'Your connection is not private'?

Usually the certificate has expired, does not list the exact name in the address bar, is self-signed, or the server leaves out an intermediate. A wrong clock on the visitor's device causes it too.

Does the name have to be in the certificate's Common Name?

No: browsers only read the Subject Alternative Names list. A wildcard such as *.example.com covers www.example.com but neither example.com nor a.b.example.com.

Can it check a site behind Cloudflare?

It checks that the certificate visitors get is trusted and flags Cloudflare's 525 and 526 errors. The chain and TLS versions are not read, because Hivex runs on Cloudflare Workers, which cannot open raw connections to Cloudflare's own addresses.

Hivex index

Short names, still free to register.

Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.

Browse free names

From code, or an AI assistant.

Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.

The API guideThe MCP serverOpenAPI schema

Sources

  1. RFC 8446: TLS 1.3
  2. RFC 5246: TLS 1.2
  3. RFC 8996: Deprecating TLS 1.0 and TLS 1.1
  4. RFC 9525: Service identity in TLS (which names a certificate covers)
  5. RFC 5280: X.509 certificates
  6. CA/Browser Forum ballot SC-081v3: shorter certificate lifetimes
  7. Cloudflare: TCP sockets in Workers

By Hivex. Updated 10 October 2026. Each check makes one HTTPS request and four short TLS handshakes from Cloudflare that stop once the server has answered; no page is read and nothing is stored.