What we found
Renewing it
Based on the issuer, DNS and CAA policy
Certificate
Chain as served
Leaf first, in the order the server sent it
Issued certificates
Unexpired certs for this name in public Certificate Transparency logs
Waiting on crt.sh…
Reads the certificate a server is actually presenting, checks the chain and hostname, and lays out what you need to renew it: who issued it, whether CAA allows the reissue, and the commands to get there.
Based on the issuer, DNS and CAA policy
Leaf first, in the order the server sent it
Unexpired certs for this name in public Certificate Transparency logs
Waiting on crt.sh…