Certificate status
Every certificate in Tidehawk carries one status. The same five tiers are used on the dashboard, in the inventory, on client pages and on the certificate detail page, so a certificate never reads one way on one screen and another way on the next.
The tiers
Section titled “The tiers”| Status | When it applies |
|---|---|
| Expired | Fewer than 0 days remaining |
| Critical | 0 to 7 days remaining |
| Warning | 8 to 30 days remaining |
| Healthy | More than 30 days remaining |
| Resolved | Superseded by a renewal, or marked resolved by a person |
The two thresholds are 7 days for critical and 30 days for warning. They are fixed, and they are not configurable.
How days remaining is counted
Section titled “How days remaining is counted”Days remaining is the time between now and the certificate’s end of validity, rounded up to a whole day. A certificate expiring in 30 hours therefore reads 2 days, not 1.
Once the date has passed, the count goes negative and is shown with a minus sign, for example −12d. That is a certificate that expired twelve days ago and has not been replaced.
Resolved beats the dates
Section titled “Resolved beats the dates”Resolved is checked before anything else. A certificate that has been superseded by a renewal, or that someone marked as renewed by hand, reads Resolved no matter what its own expiry date says. That is why a certificate that expired last month can sit quietly as resolved: its replacement is the one being watched.
Colours
Section titled “Colours”Expired and Critical both use red. Warning is amber, Healthy is green, and Resolved uses a plain neutral pill. Expired shares the red of Critical because both mean the same thing operationally: someone needs to act now.
The same tiers apply to domains
Section titled “The same tiers apply to domains”Domain registrations use these tiers too, with one addition. A domain whose expiry date has not come back from the registry yet reads Not tracked rather than being assumed healthy. See domain expiry tracking.
Status is not the same as your alert rules
Section titled “Status is not the same as your alert rules”This is worth being clear about, because the numbers look similar.
The tiers above decide what colour a row is. Your alert rules decide who gets told and when. They are separate systems with separate thresholds, and changing one does not change the other.
A new workspace starts with certificate alerts at 60, 30, 7 and 1 days. So a certificate 45 days out already triggers the 60-day alert while still showing as Healthy, because 45 is more than 30. That is expected, not a bug: the alert is the early warning and the pill is the urgency of the situation right now.
Certificates on the auto-renewing track
Section titled “Certificates on the auto-renewing track”A certificate on the auto-renewing track is coloured by the same tiers as everything else, so a Let’s Encrypt certificate genuinely does turn amber in its final 30 days. What differs is when it alerts: Tidehawk expects it to renew on its own and only raises an alert when the renewal looks stuck. See renewals and supersession.