Common causes
- The certificate expired because Let's Encrypt or AutoSSL renewal failed
- The certificate was renewed but the web server was not reloaded
- An expired intermediate certificate is still in the chain file
- A CDN or load balancer still serves an old certificate
- The visitor's computer or phone clock is wrong
- Renewal is blocked because the HTTP-01 challenge path returns 404 or redirects wrongly
How to fix it
- Check the expiry date. Run echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates. If notAfter is in the past, the certificate has expired.
- Renew the certificate. With certbot run sudo certbot renew. On cPanel go to SSL/TLS Status and click Run AutoSSL. Read any error it prints about the domain validation.
- Reload the web server. Run sudo systemctl reload nginx or sudo systemctl reload apache2 so it loads the new files. A renewed certificate is not served until reload.
- Update the CDN or load balancer. If the certificate lives on Cloudflare, AWS or a load balancer, upload or renew it there too. The origin certificate alone does not change what visitors see.
- Fix renewal for the future. Make sure /.well-known/acme-challenge/ is reachable over HTTP and not redirected to a missing page. Test with sudo certbot renew --dry-run.
- Check the visitor's clock. If the certificate is valid but one person sees the error, set their device to automatic date and time.
Show certificate dates and test automatic renewal
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -dates
sudo certbot renew --dry-run
systemctl list-timers | grep certbot How to stop it happening again
- Use automated renewal and check that its timer or cron job runs
- Add a deploy hook that reloads the web server after renewal
- Monitor certificate expiry and alert 14+ days ahead
- Keep DNS and challenge paths working for validation