28 September 2026 · One command a day
How do I list all my SSL certificates and their expiry dates with certbot?
The certbot certificates command lists every SSL certificate that certbot manages on your server, along with the domains each one covers and the date it expires. It reads certbot's own records, so it shows what certbot thinks it is looking after, not what nginx is serving right now. You reach for it when you want a quick inventory, or when you are not sure whether a renewal actually happened.
The command
sudo certbot certificates
There are no flags to remember. sudo is needed because certbot keeps its certificates and renewal settings under /etc/letsencrypt, which only root can read. certificates is a subcommand that only reports. It does not contact Let's Encrypt, request anything or change any files, so it is safe to run as often as you like.
What you will see
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Found the following certs:
Certificate Name: example.com
Serial Number: 4a91c2e07b3d5f8a1e6c9d0b2f4a7e3c1d5
Key Type: ECDSA
Domains: example.com www.example.com
Expiry Date: 2026-12-15 09:32:11+00:00 (VALID: 78 days)
Certificate Path: /etc/letsencrypt/live/example.com/fullchain.pem
Private Key Path: /etc/letsencrypt/live/example.com/privkey.pem
Certificate Name: sitename.example.com
Serial Number: 7d2e4b9a0c1f3e5d8b6a4c2e0f9d7b5a3c1
Key Type: ECDSA
Domains: sitename.example.com
Expiry Date: 2026-10-06 14:05:47+00:00 (VALID: 8 days)
Certificate Path: /etc/letsencrypt/live/sitename.example.com/fullchain.pem
Private Key Path: /etc/letsencrypt/live/sitename.example.com/privkey.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Each block is one certificate. The name is the label certbot uses internally, and it usually matches the first domain you requested. The domains line shows every hostname the certificate covers. The expiry line is the one to check. Let's Encrypt certificates last 90 days and certbot's timer normally renews them once 30 days or fewer remain. The second certificate above has 8 days left, which means renewal has been failing. Run a dry-run renewal to find out why. A lapsed certificate shows INVALID: EXPIRED instead. The two paths are what you point nginx at in its ssl_certificate and ssl_certificate_key lines.
When to use it
- You host several sites and want one list of every certificate and its expiry, instead of checking each domain in a browser.
- A browser warns that a site's certificate has expired, and you need to see whether certbot still knows about that domain at all.
- You are about to remove a site and want the exact certificate name to pass to
certbot delete.
Watch out for
A certificate marked VALID here is not proof that visitors are getting it. Certbot renews the files on disk, but nginx keeps serving whatever it loaded at its last reload. If a renewal ran without a reload, this list can say 78 days while the browser says expired. Check what the site is actually sending with openssl from the command line, and if the two disagree, reload nginx.
Questions people ask
Can I check just one certificate?
Yes. Add --cert-name example.com and certbot lists only that one, using the certificate name from the first line of each block.
Why does it not show a certificate I know is installed?
Certbot only lists certificates it issued and keeps records for under /etc/letsencrypt/renewal. Certificates from a control panel, another ACME client or a paid provider will not appear, even if nginx is using them.
Seeing every certificate on the machine in one list, with the file paths nginx uses, is only possible on a server you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.
Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.
Affiliate link.