"Your connection is not private" on your own website: expired SSL certificate fix

Visitors see a warning page instead of your site, often with the code NET::ERR_CERT_DATE_INVALID. Most people close the tab. Your site is still there. The certificate that proves it is yours has run out.

What it means

SSL certificates last 90 days (free ones) to a year (paid ones). When one is not renewed, every browser refuses to show the site without a warning. The code ERR_CERT_COMMON_NAME_INVALID is different: the certificate is valid but for another address, usually www vs no www.

What to do, in order

  1. Check your computer's clock first. A wrong date on one machine causes this error on every site. If other sites work, it is your certificate.
  2. Shared hosting (cPanel, Plesk, SiteGround, Bluehost and so on): open the SSL or "Let's Encrypt" section and click renew or reissue. Most hosts have a button.
  3. Your own server with Certbot: run sudo certbot renew, then reload your web server. Then check systemctl list-timers | grep certbot so it renews by itself next time.
  4. Behind Cloudflare: check the certificate on your server too, not only Cloudflare's. In Full (strict) mode an expired origin certificate breaks the site.
  5. Hosted builder (Squarespace, Wix, Shopify): the certificate is theirs to renew. It usually fails because the domain's DNS no longer points at them. Fix the DNS record they list and the certificate reissues within hours.

Check it yourself

Run echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null | openssl x509 -noout -dates. The notAfter line is the expiry date.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.