← Back to Articles
Troubleshooting2026-08-15•4 min read

Certificate Expired: The Emergency Renewal Playbook

· CSR.plus Team

Certificate Expired: The Emergency Renewal Playbook
  • •An expired certificate breaks HTTPS immediately — browsers show NET::ERR_CERT_DATE_INVALID for every visitor.
  • •Renew, redeploy with the full chain, then verify. Most renewals take under 15 minutes.
  • •Prevent recurrence with monitoring: track days-remaining for every certificate you manage.
ERR_DATE_INVALID
Browser error
NET::ERR_CERT_DATE_INVALID
<15 min
Typical fix
renew + deploy + verify
90 days
Renewal window
Let’s Encrypt, auto by default
Monitoring
Prevention
alert at 30 days remaining

Confirm the diagnosis

Run openssl s_client -connect yourdomain.com:443 -servername yourdomain.com and read notAfter. Compare with the server date. If the certificate has expired, every HTTPS visitor sees NET::ERR_CERT_DATE_INVALID, and some clients fail entirely. Do not confuse this with an expired root or an old cached copy — check the served leaf.

Renew and redeploy in 15 minutes

If your CA offers auto-renewal (Let’s Encrypt via certbot with a systemd timer), run the renewal command and reload the web server. For manual renewals, download the new certificate and full chain, update the server files, reload, and verify with s_client. Clear CDN caches if you terminate TLS at the edge.

Never let it happen again

Track days-remaining for every certificate with a monitor (or this site’s monitor tool) and alert at 30 days. Automate renewal where possible, and add a CI check that fails on expired certificates in staging. Review expired-certificate statistics — the majority of expiry incidents are simply missed renewals.

FAQ

Can I use the certificate while the renewal is pending?

No. Once notAfter passes, the certificate is invalid everywhere. Renew first, then redeploy — the gap is usually minutes, not days.

Why did the automatic renewal fail?

Common reasons: the renewal timer was disabled, port 80/443 validation was blocked by a firewall, or DNS did not point at the server. Check certbot renew --dry-run output.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles