Development

SSL Certificate Expired? What It Means and How to Fix It

Your SSL certificate has expired and visitors are seeing a security warning. What has happened, how to fix it today, what it costs, and how to stop it happening again.

Your website was fine yesterday. Today visitors are hitting a full screen warning telling them the connection is not private, and the phone has stopped ringing. Almost always, the cause is an SSL certificate that has expired.

It looks alarming and it is bad for business while it lasts, but it is one of the simpler website problems to fix. Here is what has actually happened, how to fix it today, and how to make sure it never happens again.

What an SSL certificate actually does

An SSL certificate is what puts the padlock in the address bar and the s in https. It does two jobs: it encrypts what passes between your website and the person using it, and it proves your site is really your site.

Certificates are issued for a fixed period, and since 2020 that period has been about 13 months at most. Many are now issued for 90 days and renewed automatically. When one reaches its end date without being renewed, browsers stop trusting it and put a warning in front of your visitors.

What the error looks like

The wording differs by browser, which is why the same problem gets searched in several ways.

BrowserWhat your visitor sees
ChromeYour connection is not private, with a code like NET::ERR_CERT_DATE_INVALID
SafariThis connection is not private
FirefoxWarning: potential security risk ahead, with SEC_ERROR_EXPIRED_CERTIFICATE
EdgeYour connection isn’t private

If the code mentions a date, the certificate has expired. If it mentions the name, the certificate is for a different address than the one being visited, which is a related but different problem covered further down.

Why it matters more than it looks

Most visitors will not click through the warning, and they should not. To someone who does not build websites, that screen looks like your business has been hacked. They leave, and a good number of them will not come back.

  • Enquiries stop. Nobody submits a form on a site their browser has warned them about.
  • Search results still show you. Google will keep listing the page for a while, so people keep arriving and keep seeing the warning.
  • Trust takes longer to recover than the site does. The fix takes an hour. The impression takes longer.

How to fix an expired SSL certificate

1. Confirm that expiry is really the problem

Click the padlock or the warning icon in the address bar and look at the certificate details. There will be a valid from and valid to date. If the valid to date has passed, that is your answer.

2. Find out who issues it

Certificates come from one of three places, and which one decides how you fix it.

  • Your hosting company, included and automatic. Most modern hosting includes a free certificate that renews itself. If yours has expired, something has broken in that automation and your host can usually re-trigger it in minutes.
  • Your hosting company, paid. Some hosts sell certificates as an add-on. Check whether the subscription lapsed or the card on file expired. This is the most common cause we see.
  • Bought separately. Less common for small businesses. If you bought one from a certificate provider directly, log in there and renew.

3. Renew or reissue it

With most hosting control panels this is a button. Find the SSL or security section, and look for renew, reissue, or install certificate. If the free automatic certificate is available, switch to it: it renews itself and costs nothing.

4. Check it took effect

Load your site in a private browsing window, because your normal browser may cache the old certificate and keep showing the warning after the fix. Check the padlock is back and the new expiry date is roughly three months or a year away.

5. Check the whole site, not just the homepage

Test a service page, the contact page, and if you have one, the checkout. Also check both with and without www, because they can behave differently.

Related errors that are not expiry

What you seeWhat it usually meansFix
Invalid SSL certificate, name mismatchThe certificate covers one address and the visitor is on another, often www versus non-wwwReissue covering both, and set one to redirect to the other
Not trusted, or self-signedThe certificate was generated locally rather than issued by a recognised authorityReplace it with a proper issued certificate
Mixed content warningThe certificate is fine, but the page loads an image or script over an insecure connectionUpdate those links to https
Certificate chain incompleteAn intermediate certificate was not installed with the main oneReinstall including the full chain your provider supplies

Does an expired certificate hurt your Google rankings?

Not immediately, and not directly in the way people fear. Google has treated https as a lightweight ranking signal since 2014, so losing it does not wipe you out overnight. The real damage is behavioural: people arrive, see a warning, and leave straight away. Sustained over weeks, that is the thing worth worrying about, not the certificate itself.

Fix it quickly and there is usually nothing lasting to recover from.

How much does an SSL certificate cost?

For most small business websites, nothing. Free certificates from Let’s Encrypt are issued automatically by nearly every reputable host, they renew themselves, and they give exactly the same padlock and the same encryption as a paid one.

Paid certificates exist mainly for organisations needing extended validation or a warranty, which is rarely a small business. If you are being charged for a basic certificate, it is worth asking your host whether the free automatic option is available instead.

How to make sure it never happens again

  • Switch to a certificate that renews automatically, if you are not on one.
  • Check the card on file with your host has not expired. A lapsed payment is the usual culprit behind a lapsed certificate.
  • Put the expiry date in your calendar with a reminder a month before.
  • Set up free uptime monitoring, which will alert you the moment the warning appears rather than a customer telling you.
  • Check your domain renewal date at the same time. A lapsed domain causes a worse version of the same problem.

All of that is part of what a website maintenance plan covers, which is the honest reason we rarely see this on sites we look after. It is not clever work, it is just work somebody has to remember to do.

The practical difference monitoring makes is who finds out first. On the sites we look after, an expiring certificate, a security warning or an indexing problem reaches us as an automated alert. On the sites nobody watches, it reaches the owner as a customer saying they could not get through.

If you are stuck

If you have gone through the steps above and the warning is still there, the usual causes are a cached certificate, a missing intermediate certificate, or a certificate installed on one server while your domain points at another. All three are quick for someone who does this often.

Worth running our website audit checklist while you are in there, because a lapsed certificate is often the visible symptom of a site nobody has looked at in a while. If nobody is looking after yours, tell us about it and we will give you a straight answer about what it needs.

Paul Fletcher

Written by

Paul Fletcher

Web Developer

Paul builds fast, reliable websites and online shops, and makes sure they work well on every phone and laptop.

More guides by Paul Fletcher →

FAQs

Every SSL certificate is issued for a fixed period, usually 90 days or about a year. When it reaches its end date without being renewed, browsers stop trusting it and show visitors a full screen warning saying the connection is not private. The website itself is fine, it is the certificate that has lapsed.

Find out who issues it, which is usually your hosting company, then renew or reissue it from the SSL section of your hosting control panel. If a free automatic certificate is available, switch to it because it renews itself. Afterwards, check the site in a private browsing window, since your normal browser may cache the old certificate.

For most small business websites, nothing. Free certificates from Let's Encrypt are issued automatically by nearly every reputable host and give exactly the same padlock and encryption as a paid one. Paid certificates mainly exist for organisations needing extended validation, which is rarely a small business.

Not immediately or directly. Google has treated https as a lightweight ranking signal since 2014, so losing it does not wipe out your rankings overnight. The real damage is behavioural: people arrive from search, see a security warning and leave. Sustained over weeks that matters, so fix it quickly and there is usually nothing lasting to recover from.

That usually means a name mismatch, where the certificate covers one address and the visitor is on another, most often www versus non-www. The fix is to reissue the certificate covering both and set one to redirect to the other. Other causes are a self-signed certificate or a missing intermediate certificate in the chain.

Move to a certificate that renews automatically, check the payment card on file with your host has not expired, put the expiry date in your calendar with a month's notice, and set up uptime monitoring so you hear about it before a customer does. Check your domain renewal date at the same time.

Free quote

Want a website that works as hard as you do?

Tell us what you do and we will come back with clear, honest next steps.

Get in touch