Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

28 September 2026 · One command a day

How do I list all my SSL certificates and their expiry dates with certbot?

The certbot certificates command lists every SSL certificate that certbot manages on your server, along with the domains each one covers and the date it expires. It reads certbot's own records, so it shows what certbot thinks it is looking after, not what nginx is serving right now. You reach for it when you want a quick inventory, or when you are not sure whether a renewal actually happened.

The command

sudo certbot certificates

There are no flags to remember. sudo is needed because certbot keeps its certificates and renewal settings under /etc/letsencrypt, which only root can read. certificates is a subcommand that only reports. It does not contact Let's Encrypt, request anything or change any files, so it is safe to run as often as you like.

What you will see

Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Found the following certs:
  Certificate Name: example.com
    Serial Number: 4a91c2e07b3d5f8a1e6c9d0b2f4a7e3c1d5
    Key Type: ECDSA
    Domains: example.com www.example.com
    Expiry Date: 2026-12-15 09:32:11+00:00 (VALID: 78 days)
    Certificate Path: /etc/letsencrypt/live/example.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/example.com/privkey.pem
  Certificate Name: sitename.example.com
    Serial Number: 7d2e4b9a0c1f3e5d8b6a4c2e0f9d7b5a3c1
    Key Type: ECDSA
    Domains: sitename.example.com
    Expiry Date: 2026-10-06 14:05:47+00:00 (VALID: 8 days)
    Certificate Path: /etc/letsencrypt/live/sitename.example.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/sitename.example.com/privkey.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Each block is one certificate. The name is the label certbot uses internally, and it usually matches the first domain you requested. The domains line shows every hostname the certificate covers. The expiry line is the one to check. Let's Encrypt certificates last 90 days and certbot's timer normally renews them once 30 days or fewer remain. The second certificate above has 8 days left, which means renewal has been failing. Run a dry-run renewal to find out why. A lapsed certificate shows INVALID: EXPIRED instead. The two paths are what you point nginx at in its ssl_certificate and ssl_certificate_key lines.

When to use it

Watch out for

A certificate marked VALID here is not proof that visitors are getting it. Certbot renews the files on disk, but nginx keeps serving whatever it loaded at its last reload. If a renewal ran without a reload, this list can say 78 days while the browser says expired. Check what the site is actually sending with openssl from the command line, and if the two disagree, reload nginx.

Questions people ask

Can I check just one certificate?

Yes. Add --cert-name example.com and certbot lists only that one, using the certificate name from the first line of each block.

Why does it not show a certificate I know is installed?

Certbot only lists certificates it issued and keeps records for under /etc/letsencrypt/renewal. Certificates from a control panel, another ACME client or a paid provider will not appear, even if nginx is using them.

Seeing every certificate on the machine in one list, with the file paths nginx uses, is only possible on a server you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: How do I test that certbot can renew my SSL certificate? · How do I check a website's SSL certificate from the command line? · How do I query a specific DNS server with dig?