Skip to content

Certificates: which end soon, and where they're used

A DigitalOcean certificate secures HTTPS on a load balancer or a Spaces CDN custom domain; Let's Encrypt ones renew automatically, while custom ones must be replaced by hand. Duskwatch is an independent iPhone app for DigitalOcean, in development; it lists every certificate in your team with its expiry, renewal type and the load balancers or CDN endpoints that use it, and flags the ones that end within 14 days.

Updated

What ends soon, in days

Each certificate shows its state in words: Valid, Expires in 9 d, Expired, Pending or Failed. Within 14 days of its end date, a certificate gets a finding, and an expired one gets a louder one. For a Let's Encrypt certificate, ending that close means automatic renewal is probably failing, so the finding says that instead of asking you to renew it.

Certificate findings, what they mean and what the app suggests
FindingWhat it meansNext step the app suggests
Certificate expires in 9 d · Custom certificateA certificate you uploaded is close to its end dateUpload a renewed certificate before then
Certificate expires in 9 d · Automatic renewal seems to be failingA Let's Encrypt certificate should have renewed by nowCheck that the domain's DNS still points at DigitalOcean so it can renew
Certificate expired · Expired 2 d agoBrowsers reject the sites that use itUpload a renewed certificate, or fix the DNS for a Let's Encrypt one
Let's Encrypt couldn't issue itThe certificate is in an error stateCheck that the domain's DNS is managed by DigitalOcean
Certificate is stuck pendingIt has been pending for more than an hourCheck that the domain's DNS points at DigitalOcean

Automatic or manual renewal

The certificate screen states the renewal type plainly: "Automatic (DigitalOcean)" for Let's Encrypt, "Manual upload" for a custom certificate. That one line tells you whether an expiry is your job or a symptom. It also lists the domains the certificate covers, when it was created, when it ends and its SHA-1 fingerprint. The private key is never part of what DigitalOcean returns, so it never reaches the app.

  • DigitalOcean creates and automatically renews Let's Encrypt certificates, which requires managing the domain with DigitalOcean DNS. For a custom certificate, you are responsible for updating it manually when it expires.

    DigitalOcean docs: manage SSL certificates (external link), verified

Where it's used

An expiring certificate matters only through what serves it. The "Used by" section lists the load balancers and Spaces CDN endpoints in the team that use it, for example lb-web or the CDN for static.example.com, and the finding repeats it in its evidence. A certificate that nothing uses shows "Not in use": it can wait, or go, when you next tidy up in DigitalOcean.

A certificate and its finding, with synthetic names

static-example · Custom · Manual upload

Certificate expires in 9 d · Used by lb-web, the CDN for static.example.com

Expiry reminders after Let's Encrypt's emails stopped

Let's Encrypt no longer emails anyone before a certificate expires, and DigitalOcean's docs describe no expiry email for the certificates it manages. DigitalOcean renews its Let's Encrypt certificates only while it manages the domain's DNS, and custom certificates are yours to replace by hand. The app checks every certificate in the team the same way, whoever issued it.

What Duskwatch doesn't do here

  • No push for certificates: an expiring certificate is a finding in the app.
  • No uploading, renewing or deleting certificates.
  • No private keys, ever.
  • No checking certificates on servers outside DigitalOcean, such as one installed on a droplet with Certbot.

Questions

  • Does DigitalOcean renew my certificate?

    Let's Encrypt certificates, yes, automatically, as long as the domain's DNS is managed by DigitalOcean. Custom certificates you uploaded must be replaced by hand.

  • Will anyone remind me before a certificate expires?

    Let's Encrypt stopped its expiry emails on 4 June 2025. Duskwatch flags every certificate in your team that ends within 14 days, as a finding in the app rather than a push.

  • Where is a certificate used?

    The certificate screen lists the load balancers and Spaces CDN endpoints in your team that use it. If none do, it says "Not in use".

  • Why does a Let's Encrypt certificate show as expiring?

    Automatic renewal should happen well before the end date, so one that is this close usually means renewal is failing. Check that the domain's DNS is still managed by DigitalOcean.

Duskwatch is in development. Join the waitlist to hear when it's on the App Store.

We'll email you once when Duskwatch is on the App Store. One-click unsubscribe. How we handle your data

Basic monitoring is free; alerts, most actions and advanced features are part of Duskwatch Pro.