Right now, the only ssl check that exist is how many days to expiration. But what if the ssl certificate is replaced with a default ssl certificate (in case of let's encrypt auto renewal failure)? That certificate has a valid expiration date but doesn't match the website name. This causes users to get blocked going to the website and the website may as well be down (in the eyes of the client).

