Picking a certificate renewal window
Why checking certificates before the final week avoids hurried maintenance.
A certificate can be valid today and still deserve attention. A twenty day window leaves room for DNS delays, service restarts, and provider-side rate limits.
The renewal check should include the file on disk and the process that reads it. A fresh certificate is not useful until the service has reloaded it.
Small reminders work best when they are paired with a visible verification command.
Filed under: maintenance