Error Reference › SSL / DNS
SSL / DNS
Certificate expired / date invalid
The site's TLS certificate is outside its valid date range (usually expired).
What it looks like
NET::ERR_CERT_DATE_INVALID
curl: (60) SSL certificate problem: certificate has expired
What does "Certificate expired / date invalid" mean?
Shown by browsers as a full-page warning, and by curl and other clients as a hard failure. Every certificate has a “not after” date; Let’s Encrypt certificates last 90 days, so a failed automatic renewal turns into this error within weeks.
What causes "Certificate expired / date invalid"?
- The certificate expired and wasn't renewed.
- Auto-renewal (e.g. certbot) failed.
- The server clock is wrong.
How do I confirm the cause?
- Check the dates: openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -dates.
- If a renewed certificate exists but the old one is still served, the web server was not reloaded after renewal.
- If the certificate looks valid, check the clock on the machine showing the error — a wrong system date causes the same message.
- If a CDN or load balancer terminates HTTPS, check the certificate it serves — that is the one to renew, not the one on your server.
How do I fix "Certificate expired / date invalid"?
- Renew the certificate (and reload the server).
- Fix/automate renewal (certbot timer, ACME client).
- Check the server's system clock/timezone.
How do I stop it happening again?
- Automate renewal (certbot’s timer or another ACME client) together with a web-server reload.
- Monitor certificate expiry and alert about two weeks ahead.