Ffile2fix
Sign in Get started

Fix "NET::ERR_CERT_DATE_INVALID"

Your connection is not private
Attackers might be trying to steal your information from example.com (for example, passwords, messages, or credit cards).
NET::ERR_CERT_DATE_INVALID

This error means the certificate's validity dates do not include today's date. Usually the site's certificate has expired because auto-renewal failed. Less often, the visitor's device clock is set to the wrong date.

Also appears as: Warning: Potential Security Risk Ahead. SEC_ERROR_EXPIRED_CERTIFICATE · This Connection Is Not Private. This website may be impersonating "example.com". · curl: (60) SSL certificate problem: certificate has expired · NET::ERR_CERT_DATE_INVALID - certificate is not yet valid (notBefore in the future)

Common causes

  • The certificate expired because Let's Encrypt or AutoSSL renewal failed
  • The certificate was renewed but the web server was not reloaded
  • An expired intermediate certificate is still in the chain file
  • A CDN or load balancer still serves an old certificate
  • The visitor's computer or phone clock is wrong
  • Renewal is blocked because the HTTP-01 challenge path returns 404 or redirects wrongly

How to fix it

  1. Check the expiry date. Run echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates. If notAfter is in the past, the certificate has expired.
  2. Renew the certificate. With certbot run sudo certbot renew. On cPanel go to SSL/TLS Status and click Run AutoSSL. Read any error it prints about the domain validation.
  3. Reload the web server. Run sudo systemctl reload nginx or sudo systemctl reload apache2 so it loads the new files. A renewed certificate is not served until reload.
  4. Update the CDN or load balancer. If the certificate lives on Cloudflare, AWS or a load balancer, upload or renew it there too. The origin certificate alone does not change what visitors see.
  5. Fix renewal for the future. Make sure /.well-known/acme-challenge/ is reachable over HTTP and not redirected to a missing page. Test with sudo certbot renew --dry-run.
  6. Check the visitor's clock. If the certificate is valid but one person sees the error, set their device to automatic date and time.

Show certificate dates and test automatic renewal

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
  | openssl x509 -noout -dates
sudo certbot renew --dry-run
systemctl list-timers | grep certbot

How to stop it happening again

  • Use automated renewal and check that its timer or cron job runs
  • Add a deploy hook that reloads the web server after renewal
  • Monitor certificate expiry and alert 14+ days ahead
  • Keep DNS and challenge paths working for validation

Frequently asked questions

Is it safe to click 'Proceed anyway'?

Not for logins or payments. An expired certificate still encrypts, but the browser cannot confirm the site is trustworthy, and attackers rely on users clicking through.

Why does it still show expired after renewing?

The web server, CDN or browser is still using the old certificate. Reload the server, update the CDN and test in a private window.

How long are Let's Encrypt certificates valid?

They last 90 days, and certbot renews them when about 30 days remain. Let's Encrypt is moving to shorter lifetimes, so automation matters even more.