Tools › Guides

SSL Certificate Expired: How to Fix It

An expired certificate blocks every visitor at once, with no warning beforehand. The fix is quick; the interesting question is why renewal stopped.

Fixing it now

If you use Let's Encrypt with certbot, certbot renew issues a fresh certificate and reloads the server. On a managed host — Netlify, Vercel, Cloudflare, cPanel — renewal is usually a button, and the certificate is reissued within a minute or two.

A renewed certificate does not take effect until the web server reloads. This is the step people miss: the new certificate is on disk, the old one is still in memory, and the site still shows expired. Restart or reload the server and check again.

Why automatic renewal fails silently

Renewal is automated almost everywhere, which is exactly why expiry still catches people out — nobody watches a thing that has worked for a year. The common failures are all quiet ones.

The renewal hook stopped reloading the server. Certificates renew on schedule, the server keeps serving the old one, and everything looks healthy right up until expiry.

The HTTP-01 challenge broke. A redirect rule added months ago now catches /.well-known/acme-challenge/ and the validation fails.

The cron job or timer is not running. Server rebuilt, container replaced, timer never re-enabled.

A DNS change invalidated the method. Moving behind a proxy or changing nameservers can break DNS-01 validation with no visible symptom until renewal is due.

Stopping it happening again

Monitor the certificate from outside your own infrastructure, on a schedule, and alert on days remaining rather than on expiry. Thirty days of warning turns an outage into a chore.

Checking from outside matters: a check that runs on the same box, using the same broken automation, tends to fail in the same way and report nothing.

Check your certificate → Expiry, chain, hostname match and weak signatures — free, no signup

Common questions

How long does it take for a renewed certificate to work?

Immediately, once the web server has reloaded. Certificates are served directly by your server, so there is no DNS or cache delay — but the server must be reloaded to pick up the new file.

Can visitors still reach my site with an expired certificate?

Only by clicking through a full-page browser warning, which almost nobody does. In practice an expired certificate takes the site offline for normal visitors.

How often do SSL certificates expire?

Let's Encrypt certificates last 90 days. Commercial certificates are typically issued for one year. Both are meant to renew automatically well before expiry.

More guides