Editorial Team
TLS Radar Team
The TLS Radar team writes about SSL/TLS monitoring, certificate management, and the operational realities of running secure web services at scale. Posts are reviewed by Suleyman Musayev, founder of TLS Radar and the lead author behind the platform's scanning engine.
Areas of focus
- SSL/TLS certificate monitoring
- Certificate lifecycle and expiration management
- TLS protocol configuration and vulnerability scanning
- Incident prevention for HTTPS-dependent services
Background
- Hands-on experience operating production HTTPS infrastructure
- Authors of the TLS Radar free SSL scanner
- Built and maintain the TLS Radar monitoring platform
Recent posts
-
Managing Thousands of TLS Certificates: A Practical Framework
Once you pass a few hundred TLS certificates, managing them becomes its own discipline. A practical framework for inventory, ownership, renewals, and the silent failures that have nothing to do with expiry.
-
DigiCert CertCentral Alternatives: An Honest Comparison
Asking your certificate authority whether you need certificate monitoring is a bit like asking your barber whether you need a haircut. They will have an opinion. It will be sincere. It will also, myst
-
What 'Your Connection Is Not Private' Actually Costs You
Browser certificate warnings have a ~90% bounce rate. Worked numbers on direct revenue loss, SEO recovery, trust decay, and the structural fix.
-
The Let's Encrypt Mass Revocation Simulation Was a Warning to Every TLS Customer
On March 19, 2026, Let's Encrypt simulated a 3 million cert mass revocation. Two weeks later, another CA revoked 1.7 million real certificates in 24 hours. Both events told the same story: your CA can revoke your cert for reasons you don't control, and most renewal automation won't respond in time.
-
HARICA Revoked 63,525 Certificates in Five Days. Here's Why.
A mid-sized public CA's internal compliance documentation fell out of sync with its issuance system, forcing two separate mass revocations in July 2026. What happened, why it isn't a HARICA-specific problem, and how to check whether you're exposed to the next one.
-
The True Cost of a TLS Outage (And Why Calendars Won't Save You)
Imagine you own a bakery. You wake up one morning, walk to the shop, and find that the front door has changed its own lock overnight. Nobody told it to. It just decided. Your key - the one you've used
-
Reporting TLS Risk to Your Board
Quantified exposure, trend lines, peer comparison. How to talk about cert risk in terms leadership cares about, and the quarterly cadence that builds budget approval.
-
Fix Browser Security Warnings in Microsoft Edge
Microsoft Edge inherits Chromium's TLS validation, including which CA roots it trusts, and uses the Windows certificate trust store. Map each error to its fix, with attention to Windows-specific trust store and Group Policy specifics.
-
Fix Browser Security Warnings in Brave
Brave inherits Chromium's TLS validation, including which CA roots it trusts. Map each NET::ERR_CERT_* error code to its cause and fix, plus a few Brave-specific gotchas (Shields, Tor windows).
-
Post-Quantum TLS in 2026: What's Deployed, and the Certificate Problem
Where post-quantum TLS actually stands in 2026: hybrid key exchange (X25519MLKEM768) is shipping, PQ signatures are the open problem, and Merkle Tree Certificates are the emerging answer.
-
Fix "This Connection Is Not Private" in Safari
Safari's TLS warning, including Safari-specific rules like the 397-day validity cap and Symantec distrust. Fixes for both macOS and iOS.
-
One Certificate Inventory for the Five CAs You Actually Use
Mid-size orgs have certs from 5-10 sources: Let's Encrypt, AWS ACM, Cloudflare, DigiCert, internal CA, vendor portals. Five dashboards is zero coverage. What consolidation actually requires.
-
Fix "Warning: Potential Security Risk Ahead" in Firefox
Firefox's triangle warning explained. Map each SEC_ERROR_* / SSL_ERROR_* / MOZILLA_PKIX_* code to its cause and fix.
-
Quantum Computers and Your Website's Security: A Plain-English Guide
Will quantum computers break your website's encryption? A plain-English, no-hype guide to post-quantum cryptography, harvest-now-decrypt-later, and what a regular site owner should actually do.
-
Fix "Your Connection Is Not Private" in Chrome
Chrome's red-shield warning explained. Map each NET::ERR_CERT_* error code to its cause and fix - including the distrusted-legacy-root cause behind most current AUTHORITY_INVALID errors, and the separate risk of CA-side compliance revocations.
-
The 47-Day Certificate Schedule: SC-081v3, DCV Reuse, and What to Automate
CA/Browser Forum ballot SC-081v3 cuts certificate validity to 47 days and domain-validation reuse to 10 days by 2029. The full schedule and what it does to your renewal and validation pipeline.
-
Benefits of SSL Certificate Monitoring (And Why You Need It)
Seven concrete benefits of continuous SSL certificate monitoring - outage prevention, silent-failure detection, compliance evidence, inventory accuracy, and more.
-
You Probably Have 2-3x More Certificates Than You Think
Most teams underestimate certificate count by 2-3x. Five common sources of shadow certs and the discovery exercise that closes the gap.
-
How to Renew an Expired SSL Certificate
All the common renewal paths - Let's Encrypt with certbot, commercial CAs like DigiCert and Sectigo, and managed cloud platforms - plus how to install and verify the renewed certificate.
-
Shorter SSL Certificate Lifetimes: What the 2026-2029 Changes Mean for You
SSL certificate lifetimes are shrinking - 200 days now, 100 in 2027, 47 by 2029. What the CA/Browser Forum's changes mean for you, and why more renewals means more chances to miss one.
-
What Happens When Your SSL Certificate Expires?
An expired SSL certificate triggers browser warnings, kills conversions, costs SEO, creates compliance exposure, and burns engineering time. Here's what each cost actually looks like.
-
TLS Scan Report, Check by Check: A Technical Walkthrough
A check-by-check technical walkthrough of a TLS scan report - grade methodology, hostname/SAN, chain, protocols, ciphers, and vulnerabilities - each with the openssl command to reproduce it.
-
How to Check Your SSL Certificate's Expiration Date
Four ways to check when your SSL certificate expires (or has already expired) - from a single shell command to continuous monitoring that catches every certificate across your domains.
-
Internal Monitoring Sees Your Origin. External Monitoring Sees What Your Customer Sees.
The TLS handshake is path-dependent. Why internal monitoring misses CDN-side issues, regional differences, OCSP failures, and cert pinning breaks - and what external validation actually requires.
-
How to Fix an SSL Certificate Outage: A Step-by-Step Guide
Diagnose and fix an SSL/TLS outage fast - then reduce the odds of the next one. Identify the failure category (expired, chain, hostname, cipher, untrusted), apply the right fix, and run a useful post-mortem.
-
How to Read Your SSL Scan Report (Without Being a Security Expert)
Got an SSL scan report and not sure what the grade, issues, and certificate details mean? A plain-English guide to reading every part of the report and knowing what to fix first.
-
My SSL Certificate Expired - How to Fix It ASAP
Your SSL certificate expired and the site is showing browser warnings? Here's exactly what to do: confirm it has expired, get a working certificate back up fast, install, verify, and prevent the next one.
-
I don't want to learn what PKI, CA, ACME, EKU stand for, I only want a working certificate for my website
You do not need to learn PKI, ACME, or CA jargon to get a working SSL certificate. Get one free in minutes, and let independent monitoring keep it working.
-
Manage Your SSL Certificates by Just Asking Claude
Check any site's SSL certificate, get a free new one, and get warned before yours expires - all by asking Claude in plain English. No dashboards, no API keys, no security expertise.
-
PKI Isn't Your Product
Post-quantum migration, 47-day validity, DCV method churn, ecosystem distrust events. That's the PKI work your team should be doing. Renewal monitoring isn't.
-
NET::ERR_CERT_AUTHORITY_INVALID in Chrome and Brave: The Real Causes in 2026
Two reasons Chrome and Brave throw NET::ERR_CERT_AUTHORITY_INVALID: distrusted legacy roots (SSL.com 2016, DigiCert G1, Entrust) - the live, current cause - and CA-side compliance revocations, illustrated by a mid-sized CA's forced revocation of 63,525 certificates in July 2026. CA-agnostic diagnostics and fix steps.
-
SSL/TLS in Your Terminal: The TLS Radar Claude Code Plugin
Scan certificates, issue free Let's Encrypt certs via Beacon, and set up monitoring without leaving Claude Code. Open source, OAuth-based, no API keys - here's the full command reference.
-
Valid SSL Certificate, but Chrome Says 'Not Secure'? Here's Why
Your SSL certificate works in Firefox and Safari but Chrome and Brave throw NET::ERR_CERT_AUTHORITY_INVALID? The real cause is almost always a distrusted legacy root - plus a separate, growing risk of CA-side compliance revocations. What to ask your CA to reissue.
-
How to Set Up SSL Certificate Alerts (Email, Slack, Webhooks)
A short tutorial on configuring SSL certificate expiration alerts that actually get noticed - email, Slack, and webhooks compared.
-
Let's Encrypt vs Paid SSL Certificates: Which One Should You Use?
A clear, practical comparison of Let's Encrypt and paid SSL certificates - what each one is best at, where they fall short, and how to choose.
-
How to Prevent SSL Certificate Expiration Downtime
A practical guide to setting up alerts, automation, and monitoring so your certificates never expire unexpectedly.
-
What Is SSL/TLS Certificate Monitoring and Why Does It Matter?
Learn why automated SSL/TLS certificate monitoring is essential for preventing outages, maintaining security, and staying compliant.