Error Reference › SSL / DNS
SSL / DNS

Certificate expired / date invalid

The site's TLS certificate is outside its valid date range (usually expired).

What it looks like

NET::ERR_CERT_DATE_INVALID
curl: (60) SSL certificate problem: certificate has expired

What does "Certificate expired / date invalid" mean?

Shown by browsers as a full-page warning, and by curl and other clients as a hard failure. Every certificate has a “not after” date; Let’s Encrypt certificates last 90 days, so a failed automatic renewal turns into this error within weeks.

What causes "Certificate expired / date invalid"?

  • The certificate expired and wasn't renewed.
  • Auto-renewal (e.g. certbot) failed.
  • The server clock is wrong.

How do I confirm the cause?

  1. Check the dates: openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -dates.
  2. If a renewed certificate exists but the old one is still served, the web server was not reloaded after renewal.
  3. If the certificate looks valid, check the clock on the machine showing the error — a wrong system date causes the same message.
  4. If a CDN or load balancer terminates HTTPS, check the certificate it serves — that is the one to renew, not the one on your server.

How do I fix "Certificate expired / date invalid"?

  • Renew the certificate (and reload the server).
  • Fix/automate renewal (certbot timer, ACME client).
  • Check the server's system clock/timezone.

How do I stop it happening again?

  • Automate renewal (certbot’s timer or another ACME client) together with a web-server reload.
  • Monitor certificate expiry and alert about two weeks ahead.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors