Certificates: which end soon, and where they're used
A DigitalOcean certificate secures HTTPS on a load balancer or a Spaces CDN custom domain; Let's Encrypt ones renew automatically, while custom ones must be replaced by hand. Duskwatch is an independent iPhone app for DigitalOcean, in development; it lists every certificate in your team with its expiry, renewal type and the load balancers or CDN endpoints that use it, and flags the ones that end within 14 days.
Updated
What ends soon, in days
Each certificate shows its state in words: Valid, Expires in 9 d, Expired, Pending or Failed. Within 14 days of its end date, a certificate gets a finding, and an expired one gets a louder one. For a Let's Encrypt certificate, ending that close means automatic renewal is probably failing, so the finding says that instead of asking you to renew it.
| Finding | What it means | Next step the app suggests |
|---|---|---|
| Certificate expires in 9 d · Custom certificate | A certificate you uploaded is close to its end date | Upload a renewed certificate before then |
| Certificate expires in 9 d · Automatic renewal seems to be failing | A Let's Encrypt certificate should have renewed by now | Check that the domain's DNS still points at DigitalOcean so it can renew |
| Certificate expired · Expired 2 d ago | Browsers reject the sites that use it | Upload a renewed certificate, or fix the DNS for a Let's Encrypt one |
| Let's Encrypt couldn't issue it | The certificate is in an error state | Check that the domain's DNS is managed by DigitalOcean |
| Certificate is stuck pending | It has been pending for more than an hour | Check that the domain's DNS points at DigitalOcean |
Automatic or manual renewal
The certificate screen states the renewal type plainly: "Automatic (DigitalOcean)" for Let's Encrypt, "Manual upload" for a custom certificate. That one line tells you whether an expiry is your job or a symptom. It also lists the domains the certificate covers, when it was created, when it ends and its SHA-1 fingerprint. The private key is never part of what DigitalOcean returns, so it never reaches the app.
DigitalOcean creates and automatically renews Let's Encrypt certificates, which requires managing the domain with DigitalOcean DNS. For a custom certificate, you are responsible for updating it manually when it expires.
DigitalOcean docs: manage SSL certificates (external link), verified
Where it's used
An expiring certificate matters only through what serves it. The "Used by" section lists the load balancers and Spaces CDN endpoints in the team that use it, for example lb-web or the CDN for static.example.com, and the finding repeats it in its evidence. A certificate that nothing uses shows "Not in use": it can wait, or go, when you next tidy up in DigitalOcean.
static-example · Custom · Manual upload
Certificate expires in 9 d · Used by lb-web, the CDN for static.example.com
Certificates in a DigitalOcean team are used for load balancer SSL termination and custom Spaces CDN endpoints, and must be detached from those resources before they can be deleted.
DigitalOcean docs: manage SSL certificates (external link), verified
Expiry reminders after Let's Encrypt's emails stopped
Let's Encrypt no longer emails anyone before a certificate expires, and DigitalOcean's docs describe no expiry email for the certificates it manages. DigitalOcean renews its Let's Encrypt certificates only while it manages the domain's DNS, and custom certificates are yours to replace by hand. The app checks every certificate in the team the same way, whoever issued it.
Let's Encrypt ended its expiration notification email service on 4 June 2025.
Let's Encrypt: expiration notification service has ended (external link), verified
For a load balancer, DigitalOcean creates and automatically renews a Let's Encrypt certificate when you manage the domain with DigitalOcean DNS.
DigitalOcean docs: configure SSL termination (external link), verified
What Duskwatch doesn't do here
- No push for certificates: an expiring certificate is a finding in the app.
- No uploading, renewing or deleting certificates.
- No private keys, ever.
- No checking certificates on servers outside DigitalOcean, such as one installed on a droplet with Certbot.
Questions
Does DigitalOcean renew my certificate?
Let's Encrypt certificates, yes, automatically, as long as the domain's DNS is managed by DigitalOcean. Custom certificates you uploaded must be replaced by hand.
Will anyone remind me before a certificate expires?
Let's Encrypt stopped its expiry emails on 4 June 2025. Duskwatch flags every certificate in your team that ends within 14 days, as a finding in the app rather than a push.
Where is a certificate used?
The certificate screen lists the load balancers and Spaces CDN endpoints in your team that use it. If none do, it says "Not in use".
Why does a Let's Encrypt certificate show as expiring?
Automatic renewal should happen well before the end date, so one that is this close usually means renewal is failing. Check that the domain's DNS is still managed by DigitalOcean.