Expired SSL Certificate: What It Means and How to Fix It
Your BadgerScan scan found that your site's TLS certificate has expired or is about to. That means every visitor now sees a full-page browser security warning, and many will leave before they ever reach your content. The fix is quick, and you can set it up so the certificate never lapses again.
One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.
What an expired certificate actually means
An SSL/TLS certificate is the small file that lets browsers set up an encrypted, trusted connection to your site. It proves your site is really yours and turns on the padlock and the https:// prefix in the address bar. When it is valid, everything looks normal. When it expires, browsers stop trusting it (Cloudflare, What is an SSL certificate?).
Every certificate has a fixed expiry date built into it. Once that date passes, browsers like Chrome, Safari, and Firefox will not load your site normally. Instead they show a full-page warning such as NET::ERR_CERT_DATE_INVALID or "Your connection is not private," and the visitor has to click through that screen before they can continue.
BadgerScan reads the certificate the same way any browser would, from the outside view. It simply checks the expiry date that is publicly visible on your certificate, so this finding reflects exactly what your real visitors are running into right now.
Why it is worth fixing right away
The practical problem is lost visitors. Most people are told never to bypass a browser security warning, so when they hit that full-page screen they simply close the tab. Your site is effectively unreachable for anyone who follows that advice, even though nothing else about it has changed.
It also affects trust and search. A site that shows a certificate warning looks broken or unsafe to a first-time visitor, and search engines strongly prefer sites served correctly over https. Renewing the certificate restores the padlock, clears the warning, and gets you back to normal. You can run the free scan again afterward to confirm the fix.
How to fix it, step by step
Renew the certificate now, then make sure it renews itself in the future so this never happens again. The exact buttons vary by host, but the process is the same everywhere.
- Find who issues your certificate. This is usually your hosting provider or a certificate authority. Many hosts include free SSL and have a one-click Renew or Reissue button in the control panel.
- If you use Let's Encrypt, renew it now. Let's Encrypt certificates last 90 days by design, and the
certbottool can renew them for you (Let's Encrypt, Getting Started). - Turn on automatic renewal so it never lapses again. With
certbot, runcertbot renew --dry-runto confirm the automatic renewal works, then let the built-in timer handle it going forward. - Confirm the certificate covers the exact hostname visitors use, including
wwwversus non-www. A certificate issued forexample.comalone will still warn onwww.example.com, so make sure both are included. - Check that the full chain is installed. Your server should serve your certificate plus any intermediate certificates, so every browser trusts it without extra downloads.
How to verify the fix
After renewing, open your site in a private or incognito window so you are not seeing a cached page. The padlock should appear and the warning should be gone. Click the padlock and view the certificate details to confirm the new expiry date is well in the future.
Test both www and non-www versions of your address, since they can carry different certificates. If either one still shows a warning, the certificate is missing that hostname and needs to be reissued to cover it. You can also re-run the free BadgerScan check or the SSL/TLS checker to confirm the finding has cleared.
Check your certificate in under a minute
Not sure whether your certificate is valid, covers www and non-www, and has the full chain installed? Run the free BadgerScan scan and see the outside view of your site's security in about a minute. No login, no software to install.
Run a free security scanFrequently asked questions
How long does it take for the warning to go away after I renew?
For visitors, almost immediately. Once the new certificate is installed and your server is serving it, browsers stop showing the warning on the next page load. You may need to open a private window to bypass your own cached copy.
Do I have to pay to renew my certificate?
Often no. Let's Encrypt certificates are free, and many hosting providers include free SSL and renew it for you automatically. Some certificate authorities charge for paid certificates, but for most small-business sites a free certificate is all you need.
Why did my certificate expire if I set it up before?
Certificates are only valid for a fixed window. Let's Encrypt certificates last 90 days, so without automatic renewal they lapse a few times a year. Turning on automatic renewal with certbot means it quietly renews itself before the expiry date.
How can I tell if my certificate is fixed?
Run the free BadgerScan scan again. It reads your certificate the same way a browser does and will tell you whether the expiry date is now valid and whether the hostname and chain are set up correctly.
Sources
More from CyberBadger
BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.
Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.