Expired SSL certificate: what it means and how to fix it

Guide · 5 min read · updated October 2026

Every HTTPS site carries a certificate with a hard expiry date. Browsers refuse to connect once it lapses — visitors see a full-page “Your connection is not private” warning, which most read as “this site is broken.” The server never went down; its ID card expired.

What actually breaks

The site isn’t “down” in the network sense — UpChecker may even report UP, because an HTTP answer still exists under the expired handshake. That mismatch is the tell: “UP here, warning in my browser” almost always means a certificate problem.

Check expiry in seconds

Run the address through UpChecker’s SSL check: it performs a real TLS handshake and reads the certificate’s notAfter date, days remaining, and issuing authority — no openssl command line needed.

Command-line equivalent, for reference:

openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -enddate

The 2-minute fix

Never let it happen again

Expiry is 100% predictable — every cert shows its date months in advance. 60–90 days of runway is the comfortable zone. Certificates have also shortened to 47 days by 2026 industry ballot, so manual renewal memorization no longer scales: automate renewal (certbot timer, ACME in the panel) and check the expiry occasionally on the SSL tool.

Check a certificate now →