Home › Install guides › Certificate checks on any TLS port
Install guide · IT teams and MSPsCertificate checks on any TLS port
Website checks already watch HTTPS certificates. The certificate check covers every other TLS port too, such as mail servers, LDAPS, remote desktop, VPN portals and appliances, and warns well before anything expires.
Uplivra Technologies LLC · Guide for Uplivra 26.10 · Updated 28 September 2026 · Latest version: https://uplivra.com/guides/certificate-checks.html
What it checks
Add a Certificate check to a device, pick the port, and Uplivra checks:
- Expiry. A warning 30 days before it expires, and down 7 days before, or when it has expired. You can change both numbers.
- The name. The certificate must be for the name people use, such as
mail.example.com, not a different one. - The chain. It must come from a trusted authority, and the server must send its intermediate certificate. Tick Self-signed or internal certificate is fine for printers, switches and internal CAs; expiry and strength are still checked.
- Strength. A warning for RSA keys under 2048 bits, small EC keys, and SHA-1 or MD5 signatures.
- Old TLS. A warning if the port still accepts TLS 1.0 or 1.1.
It works on ports that start with TLS (443, 465, 636, 993, 995, 3389, 8443…) and on ports that switch to TLS first: SMTP (25, 587), IMAP (143), POP3 (110), FTP (21) and LDAP (389).
Add one
- Open the device and choose Add a check › Certificate on any TLS port.
- Enter the port. If the service starts in plain text and switches to TLS, choose how it does it (for example SMTP STARTTLS for port 587).
- Enter the name the certificate must be for. Leave it empty to use the device's address.
- Check once an hour or once a day: certificates change rarely.
For auditors
The compliance control Keep certificates valid (UPL-14) uses these checks and the website checks. Its evidence download lists every monitored certificate with:
- the name it's for and who issued it;
- its expiry date and the days left;
- its latest status.