Fixing it now
If you use Let's Encrypt with certbot, certbot renew issues a fresh certificate and reloads the server. On a managed host — Netlify, Vercel, Cloudflare, cPanel — renewal is usually a button, and the certificate is reissued within a minute or two.
A renewed certificate does not take effect until the web server reloads. This is the step people miss: the new certificate is on disk, the old one is still in memory, and the site still shows expired. Restart or reload the server and check again.
Why automatic renewal fails silently
Renewal is automated almost everywhere, which is exactly why expiry still catches people out — nobody watches a thing that has worked for a year. The common failures are all quiet ones.
The renewal hook stopped reloading the server. Certificates renew on schedule, the server keeps serving the old one, and everything looks healthy right up until expiry.
The HTTP-01 challenge broke. A redirect rule added months ago now catches /.well-known/acme-challenge/ and the validation fails.
The cron job or timer is not running. Server rebuilt, container replaced, timer never re-enabled.
A DNS change invalidated the method. Moving behind a proxy or changing nameservers can break DNS-01 validation with no visible symptom until renewal is due.
Stopping it happening again
Monitor the certificate from outside your own infrastructure, on a schedule, and alert on days remaining rather than on expiry. Thirty days of warning turns an outage into a chore.
Checking from outside matters: a check that runs on the same box, using the same broken automation, tends to fail in the same way and report nothing.
Check your certificate → Expiry, chain, hostname match and weak signatures — free, no signupCommon questions
How long does it take for a renewed certificate to work?
Immediately, once the web server has reloaded. Certificates are served directly by your server, so there is no DNS or cache delay — but the server must be reloaded to pick up the new file.
Can visitors still reach my site with an expired certificate?
Only by clicking through a full-page browser warning, which almost nobody does. In practice an expired certificate takes the site offline for normal visitors.
How often do SSL certificates expire?
Let's Encrypt certificates last 90 days. Commercial certificates are typically issued for one year. Both are meant to renew automatically well before expiry.