What happens when an SSL certificate expires
The moment a certificate expires, browsers stop showing your site and show a full-page warning instead. Most visitors turn back at that point.
What visitors see
Instead of your page they get a message such as "Your connection is not private", with an error code that mentions the certificate date. They can click through on some browsers, but few do. Apps and other systems that talk to your site simply stop working, because they refuse the connection.
Nothing is wrong with your server or your content. The certificate that proves the site is yours has passed its end date.
Why certificates expire without anyone noticing
- Renewal is automatic on most hosts, so nobody keeps the date in mind.
- The automatic renewal quietly stopped: a scheduled job was removed, a server was rebuilt, or a DNS change broke the check that proves you own the domain.
- The certificate was bought by hand a year ago and the reminder went to someone who has left.
- The renewal worked, but the web server was never reloaded, so it still serves the old certificate.
How to fix it
- If your host manages certificates, open its control panel and renew or reissue the certificate there, or contact its support.
- If you use an automatic tool on your own server, run its renewal by hand and read the error it prints.
- Reload or restart the web server so it picks up the new certificate.
- Check the site from outside to confirm the new expiry date is being served.
How to never be surprised again
Free certificates usually last 90 days, so a broken renewal shows up within weeks. A warning a week ahead leaves time to fix it on a normal working day. KeenCrow reads your certificate on every check and emails you 7, 3 and 1 days before it expires.
Check a certificate now, free How certificate monitoring works