SSL certificate expired: why it happens and how to fix it
Updated October 1, 2026
"Your connection is not private", NET::ERR_CERT_DATE_INVALID, or "certificate has expired" in a log.
The certificate your server presents is past its end date. The good news is that it is almost always quick to fix.
The steps below go from confirming the problem to making sure it doesn't come back.
1. Confirm what is actually being served
Don't assume it's the certificate you just renewed. Check what the server really presents, with the free SSL checker or:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -enddate
If the date shown is in the past, the server is still using the old certificate. If it is in the future but your browser complains, see the other causes at the end.
2. Find out why it was not renewed
- Automatic renewal failed. With Let's Encrypt and certbot, run
sudo certbot renew --dry-runand read the error. Common causes: port 80 blocked by a firewall, a redirect that breaks the HTTP challenge, a DNS record that changed, or the renewal timer not running (systemctl list-timers). - Renewed, but the server wasn't reloaded. Web servers keep the old certificate in memory until reloaded. Run
sudo systemctl reload nginx(orapache2,haproxy). - Someone has to renew it by hand. Paid and internal certificates often have no automation and depend on a reminder in somebody's calendar.
- The certificate lives somewhere else. A load balancer, CDN, mail server or another node may hold its own copy.
3. Renew and install
For Let's Encrypt: sudo certbot renew, then reload the web server. For a paid certificate, get a new
one from the provider, install the new certificate and the intermediate chain file, then reload. Make sure the
new files are the ones your server config points to.
4. Check every place that serves the name
Re-run the check against each endpoint: the website, www and the bare domain, API hostnames, mail
servers and any other port. One forgotten place is a common reason a "fixed" problem keeps coming back.
5. Stop it happening again
- Test renewals now and then (
certbot renew --dry-run) and make sure a reload hook is set. - Monitor the certificate from outside. A check that looks at the real certificate catches failed renewals, wrong certificates and forgotten nodes, which log-based reminders miss.
- Get an email while there is still time to act, not when the warning appears. CertAvert sends expiry alerts before a certificate runs out (free for 3 domains).
If the date is fine but the browser still complains
Check the device's clock (a wrong date makes every certificate look expired or not yet valid), and look for a missing intermediate certificate or a name mismatch. See certificate name mismatch.
Don't wait for the browser warning
Check any site's certificate in a few seconds with the free SSL checker, or sign up free and CertAvert emails you before certificates expire.