SSL certificate expired: "Your connection is not private" with NET::ERR_CERT_DATE_INVALID

Your site's security certificate has an end date, and it passed. Every browser now warns visitors away. Nothing was hacked. The certificate simply did not renew.

What to do, in order

  1. Confirm it is really expired. Run echo | openssl s_client -connect yoursite.com:443 -servername yoursite.com 2>/dev/null | openssl x509 -noout -dates. Look at notAfter. If the date is in the future, check your computer's clock instead.
  2. Shared hosting (cPanel, Plesk): open SSL/TLS Status or AutoSSL and press Run. AutoSSL fails if your domain does not point at the host, so check the A record first.
  3. Let's Encrypt on your own server: run sudo certbot renew, then reload the web server. If it fails, the error usually says the domain did not resolve or port 80 was blocked. Open port 80; renewals need it.
  4. Cloudflare in front: visitors see Cloudflare's certificate, which renews itself. If they still see an error, the SSL mode is "Full (strict)" and your server's own certificate expired. Renew it on the server, or use a free Cloudflare Origin Certificate.
  5. Bought a paid certificate: it does not renew on its own. Buy the renewal, generate a new request, install it.
  6. Stop it happening again. Check that the renewal job exists: systemctl list-timers | grep certbot.

If you are not sure which of these applies, send me the address and I will tell you who issued the certificate and where to renew it.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.