📅 Certificate Validity Period Calculator

Enter the certificate's issue date and validity length (in days, matching what openssl -days takes) to compute the exact expiry date and how long is left.

How the expiry date is worked out

The issue date is read as midnight UTC and the validity length is added as whole days, which is exactly what openssl x509 -days counts from notBefore:

expiry    = issue + days × 86,400,000 ms   (UTC)
years     = days / 365
remaining = ceil((expiry - now) / 86,400,000)

Issue on 2026-01-15 with 398 days and the certificate stops being valid on 2027-02-17, shown as ~1.09 years. Because both ends sit at UTC midnight, no time zone or daylight-saving shift can move the answer by a day. The years figure divides by 365 flat, so it reads slightly high across a leap year.

The ceiling you are working against

Public TLS certificates have a maximum lifetime set by the CA/Browser Forum, and it is falling on a fixed schedule. The number depends on the day of issue:

From 15 Mar 2026200 days
From 15 Mar 2027100 days
From 15 Mar 202947 days

The box defaults to 398, the old cap that applied to certificates issued before March 2026. Private CAs and internal PKI are not bound by any of this - a self-signed lab certificate can run for 3650 days if you want it to.

The panel turns amber under 30 days remaining and red once the date has passed, counting how many days ago it went. Renewal automation should fire well before amber; at a 47-day lifetime, 30 days is most of the certificate.

Frequently asked questions

When does a 398-day certificate issued today expire?

398 days later to the day. From 2026-01-15 that is 2027-02-17: 365 days reaches 2027-01-15, and the remaining 33 days run to 17 February.

What is the maximum lifetime for a public TLS certificate?

200 days for certificates issued on or after 15 March 2026, dropping to 100 days in March 2027 and 47 days in March 2029. Browsers reject a public certificate whose validity period exceeds the cap in force when it was issued.

Does the count start from when I generated the CSR?

No. It starts at the certificate's notBefore, set by the CA when it signs, which can be hours or a day earlier than the moment you receive the file. Use notBefore from the issued certificate as the issue date here, not your CSR date.