Skip to content

Certificate status

Every certificate in Tidehawk carries one status. The same five tiers are used on the dashboard, in the inventory, on client pages and on the certificate detail page, so a certificate never reads one way on one screen and another way on the next.

Status When it applies
Expired Fewer than 0 days remaining
Critical 0 to 7 days remaining
Warning 8 to 30 days remaining
Healthy More than 30 days remaining
Resolved Superseded by a renewal, or marked resolved by a person

The two thresholds are 7 days for critical and 30 days for warning. They are fixed, and they are not configurable.

Days remaining is the time between now and the certificate’s end of validity, rounded up to a whole day. A certificate expiring in 30 hours therefore reads 2 days, not 1.

Once the date has passed, the count goes negative and is shown with a minus sign, for example −12d. That is a certificate that expired twelve days ago and has not been replaced.

Resolved is checked before anything else. A certificate that has been superseded by a renewal, or that someone marked as renewed by hand, reads Resolved no matter what its own expiry date says. That is why a certificate that expired last month can sit quietly as resolved: its replacement is the one being watched.

Expired and Critical both use red. Warning is amber, Healthy is green, and Resolved uses a plain neutral pill. Expired shares the red of Critical because both mean the same thing operationally: someone needs to act now.

Domain registrations use these tiers too, with one addition. A domain whose expiry date has not come back from the registry yet reads Not tracked rather than being assumed healthy. See domain expiry tracking.

Status is not the same as your alert rules

Section titled “Status is not the same as your alert rules”

This is worth being clear about, because the numbers look similar.

The tiers above decide what colour a row is. Your alert rules decide who gets told and when. They are separate systems with separate thresholds, and changing one does not change the other.

A new workspace starts with certificate alerts at 60, 30, 7 and 1 days. So a certificate 45 days out already triggers the 60-day alert while still showing as Healthy, because 45 is more than 30. That is expected, not a bug: the alert is the early warning and the pill is the urgency of the situation right now.

A certificate on the auto-renewing track is coloured by the same tiers as everything else, so a Let’s Encrypt certificate genuinely does turn amber in its final 30 days. What differs is when it alerts: Tidehawk expects it to renew on its own and only raises an alert when the renewal looks stuck. See renewals and supersession.