TLS & Cache Checker.Certificates, protocols, cache: one pass.
Certificate chain, protocol versions and cache behavior verified in a single pass, including the check that matters most this decade: whether your certificate operations are ready for the industry’s shortening lifetimes, stepping down from 200 days in 2026 toward 47 days by 2029.
TLS & Cache Checker in four questions.
Chain validity, expiries, issuer posture, and whether renewal automation is in place for the shortening-lifetime era.
Protocol versions and negotiation, is the edge serving TLS 1.3 to clients that speak it?
Repeat-request probes show real HIT/MISS behavior per asset class, not what the config file claims.
Lifetimes step down from March 2026; manual renewal processes stop being survivable. The checker grades your readiness.
How it works.
The same signals our analysts use in paid assessments, automated.
Handshakes at multiple protocol versions capture what the edge actually negotiates, and the full chain it presents.
CoreEvery certificate in the chain checked for validity, expiry windows and known-problem issuers.
CoreSequenced requests reveal true cache behavior: HIT, MISS, and the TTLs actually honored at the edge.
CoreExpiries and renewal patterns are graded against the industry’s published lifetime reduction schedule.
CoreWhat you’ll get.
Every certificate, its validity and its renewal deadline.
IncludedWhat was negotiated at each attempted version.
IncludedHIT/MISS behavior per asset class, with honored TTLs.
IncludedA grade on whether your renewal operations survive 47-day certificates.
IncludedWho it’s for.
Certificate lifetimes begin shortening in March 2026; this is the readiness check.
Find the asset classes silently missing cache before the bandwidth bill does.
Chain and protocol posture, documented in a shareable report.
Prove the new edge negotiates and caches the way the old one did, or better.
Free at launch. In build now.
The toolkit automates the detection and benchmark data behind the assessments we already run, the tools are how we prove the data is good.
Every tool ships free with shareable reports; the business model is the advisory behind it, not your email address.
First releases are in build. Dates are windows, not promises, we ship when the detection is trustworthy.
Want the answer before the tool exists? A free assessment runs the same analysis, human-graded, usually within 24 hours, and puts you on the early-access list for TLS & Cache Checker.
TLS & Cache Checker in context.
The research this tool automates.
TLS & Cache Checker questions,
answered straight.
When does the checker launch?
It’s in development in the first toolkit wave, 2026 launch window; the tools page has the early-access list.
What’s the 47-day certificate story?
The CA/Browser Forum has scheduled maximum certificate lifetimes to step down from today’s 398 days to 200 days in March 2026, then 100 days in 2027, reaching 47 days by March 2029. Manual renewal doesn’t survive that; the checker grades whether your automation will.
How does it test caching without my logs?
Sequenced repeat requests observe the edge’s actual HIT/MISS responses and honored TTLs per asset class, behavior, not configuration claims.
Will it flag weak ciphers?
Protocol and negotiation posture is in the launch scope, graded against current guidance rather than exhaustive cipher enumeration.
Is it safe to run against production?
Yes, it’s a handful of ordinary HTTPS requests, indistinguishable from a browser visit.
I need this checked today.
A free assessment covers TLS and cache posture, human-graded, usually within 24 hours.
All product names, logos and brands referenced in tool reports are the property of their respective owners and are used for identification purposes only. CDN World tools perform passive, non-intrusive analysis. Tool capabilities and launch timing described on this page are plans, not commitments, and may change.
