Which of your certificates still depend on a person?

Every padlock is a TLS certificate, and certificates expire. Software renews on a steady beat. A person renewing by hand leaves long, uneven gaps and year-long certificates. We read the public certificate log for a domain and its subdomains and tell you which is which — nothing to install, nothing to log in to.

How the reading works

  • Renewed by software — certificates that live 90 days or less, reissued at a regular interval. That is ACME, Let's Encrypt, or a managed certificate at a CDN.
  • Renewed by a person — certificates that live a year or more, or renewals more than five months apart. Someone buys one, installs it, and forgets until the next warning.
  • Weekday share is a supporting signal. Software renews any day of the week (about 71% weekdays); people renew on workdays.
  • Data comes from public Certificate Transparency logs via crt.sh. Private CAs and internal hostnames never appear.

Why now

The CA/Browser Forum has voted to shorten the maximum life of a public certificate: 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. A yearly hand renewal becomes four a year, then eight. The risk does not arrive on one date; it accumulates as hand-renewed hostnames come due more and more often.

Want the whole system in one read? How TLS certificates work, and why they are about to get much shorter covers the chain of trust, issuance, Certificate Transparency, and the 2026 to 2029 timeline, with illustrations.