kubeadm certs check-expiration
echo | openssl s_client -showcerts -connect master_node1:6443 -servername api 2>/dev/null | openssl x509 -noout -enddate
for DOMAIN in host1.com host2.com host3.com
do
DOMAIN_EXPIRES=$(echo | openssl s_client -connect $DOMAIN:443 2>/dev/null | openssl x509 -noout -dates | grep notAfter | awk -F= '{print $2}')
echo $DOMAIN: $DOMAIN_EXPIRES
done