Skip to content

SSL Certificate Expired and Your Website Says Not Secure: What to Do

  Posted on 11 Oct, 2026
  Web Applications
SSL Certificate Expired and Your Website Says Not Secure: What to Do

If your browser says "Your connection is not private" or "Not secure" on a website that worked yesterday, the first thing to suspect is an expired SSL (TLS) certificate. Your content and data are still there, but browsers will keep blocking visitors until a valid certificate is installed. The fix is to renew or reissue the certificate through whoever supplies it, usually your hosting company or CDN, and it is normally a small job once the right person is looking at it.

This guide is for an owner whose developer is unavailable. It covers what you can check yourself without risk, what to leave alone, and what to send to your host or to a team that handles website and web application development.

What does "Your connection is not private" usually mean?

It means the browser could not verify the website's certificate, and on a site that was fine before, an expired certificate is the first cause to rule out. A TLS certificate (still widely called an SSL certificate, after the older protocol) is a small file installed on the server. As MDN's TLS guide explains, it binds the website's encryption keys to its domain name so the browser knows it is really connected to your site, and the connection is then encrypted so nobody in between can read or alter it.

Every certificate has a start date and an end date. Once the end date passes, the browser no longer accepts it as proof of identity, so it stops and shows a full-page warning instead of sending passwords or card details to a server it cannot confirm.

Is "Not secure" the same problem?

Not always. Google's Chrome help page says the "Not secure" symbol means the site is not using a private connection. If you see that label with no full-page warning, the page may simply have loaded over plain HTTP, which is a different fault. Note exactly which message you see.

What can I safely check in about 10 minutes?

You can confirm the cause and collect the facts a host or developer needs without changing anything. Work through these in order and write down what you find.

  1. Open the site on a second device, ideally a phone on mobile data. Confirm that device's date and time are correct, because the browser compares the certificate dates with its own clock. If only one device shows the warning, the problem may be that device.
  2. On the warning page, or by selecting the icon to the left of the web address, open the certificate details. Note the expiry date, the name of the issuer, and the domain names it covers.
  3. Try both versions of your address, with and without "www", plus any subdomain you use such as shop or app. Note which ones fail.
  4. Log in to your hosting control panel and find the SSL or TLS section. Read the status, the expiry date and any error message, and take a screenshot. Do not change settings.
  5. Open the billing pages for your hosting, your domain name and any certificate you bought. Look for an unpaid invoice, an expired card or a plan that changed.
  6. Search your email, including shared addresses such as admin@ or billing@, for renewal or failure notices from your host, domain registrar or certificate seller.
  7. If you use a CDN such as Cloudflare, log in and read the certificate status shown for your domain.

Where does my website's certificate come from?

It comes from one of four places, and the issuer name you noted in step 2 usually tells you which. Many hosting plans issue a free certificate from the control panel and renew it on a schedule. A CDN can supply it instead: Cloudflare's Universal SSL documentation says it handles issuance, renewal and deployment automatically for proxied hostnames once a domain is active. A developer may have installed a Let's Encrypt client directly on the server. Or someone bought a certificate and installed it by hand, which means a person must repeat that work every time it expires.

A site behind a CDN can have two certificates, one between the visitor and the CDN and one between the CDN and your server. Either can expire, so tell whoever helps you that a CDN is involved.

Why did automatic renewal fail?

Automatic renewal fails when the certificate authority can no longer prove that you control the domain. Let's Encrypt's challenge types documentation describes the two usual tests: fetching a file from your site over port 80 at a specific address, or reading a specific TXT record in your DNS. Anything that breaks those tests breaks renewal, often silently.

Common triggers

The domain's DNS was changed, so the test reaches a different server. The site was moved behind a CDN, a firewall or a redirect that blocks the validation request. DNS hosting moved to a provider the renewal tool cannot update. The hosting plan was changed or migrated and the scheduled renewal job, or the free certificate itself, did not come with it. For purchased certificates, the cause is usually simpler: nobody renewed it, or the payment failed.

What should I not do while the site shows a certificate warning?

Do not do anything that hides the warning or changes how the domain is routed. Specifically:

  • Do not tell customers to click through the warning. It trains them to ignore the one signal that protects them from a fake copy of your site.
  • Do not change DNS records, switch off HTTPS, or lower the security mode at your CDN to make the message go away.
  • Do not buy a new certificate in a hurry before you know where the current one comes from. It may not be needed and still has to be installed correctly.
  • Do not delete the old certificate, cancel services or edit server files.
  • Do not enter passwords or card details on the site yourself until it is fixed.

When should I call a developer or my host, and what should I have ready?

Call as soon as you have confirmed the warning on a second device, because the fix needs access you should not be experimenting with. Your hosting company's support team is often the right first contact, since it controls the panel that issues the certificate. Send one message containing:

  • The exact address that fails, the exact wording of the warning and any error code on the page, with a screenshot.
  • The expiry date, issuer and domain names from the certificate details.
  • The names of your hosting company, domain registrar and CDN, and who holds each login.
  • Anything that changed in the last three months: a new host, a new plan, DNS edits, a CDN or firewall added, a redesign.
  • Screenshots of the SSL status in your hosting panel and of any renewal emails.

Reissuing the certificate, correcting DNS and repairing the renewal job are the developer's or host's tasks, not yours.

How do I stop it happening again?

Make renewal automatic and monitor it, because certificate lifetimes are getting shorter. As of October 6, 2026, the CA/Browser Forum Baseline Requirements, the rules certificate authorities follow to be trusted by browsers, cap new public TLS certificates at 200 days. That cap was 398 days until March 15, 2026, and it is scheduled to fall to 100 days on March 15, 2027 and 47 days on March 15, 2029. A purchased certificate therefore can no longer run for a full year.

Free certificates are shortening too. Let's Encrypt, whose certificates currently last 90 days by default, has announced a move to 64 days on February 10, 2027 and 45 days on February 16, 2028. Renewing by hand on that schedule is not realistic.

Ask whoever maintains the site to confirm three things: renewal runs automatically, an independent monitor emails more than one person before expiry, and certificates are re-checked after any DNS, hosting or CDN change. That belongs in an ongoing software maintenance and support arrangement rather than in one person's memory.

Quick answers

What does "Your connection is not private" mean on my own website?

The browser could not verify your website's TLS certificate, and on a site that worked before, an expired certificate is the first thing to check. Visitors are blocked until a valid certificate is installed; your content and data are not deleted.

How do I check when my SSL certificate expires?

Open the site, select the icon to the left of the web address or the details link on the warning page, and view the certificate. It shows the issuer, the domain names covered and the expiry date.

How long is an SSL certificate valid in 2026?

As of October 6, 2026, the CA/Browser Forum Baseline Requirements cap new public TLS certificates at 200 days. The cap is scheduled to fall to 100 days on March 15, 2027 and 47 days on March 15, 2029. Let's Encrypt certificates last 90 days by default.

Should I tell customers to click through the certificate warning?

No. The warning appears because the browser cannot confirm it is talking to your real site, and customers who learn to ignore it are easier to trick later. Tell them the site is temporarily unavailable and get the certificate fixed.

Why did my SSL certificate not renew automatically?

Automatic renewal has to prove again that you control the domain. It commonly fails after a DNS change, a move to a new host or CDN, a firewall or redirect that blocks the validation request, or a plan change that removed the free certificate.

Conclusion

An expired certificate looks alarming but is usually a contained problem: confirm it on a second device, read the expiry date and issuer, check your hosting, billing and email for the reason, and pass those facts to your host or developer. Do not ask customers to bypass the warning and do not change DNS or security settings yourself.

If you have no developer available, you can contact Entrant Technologies and we will take a look.

Entrant Technologies
Post written by
Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations.
View all posts by Entrant Technologies →
Latest Blogs
 
A monthly website maintenance checklist should include eight things: software updates, backups and a test restore, security, uptime and speed, forms and checkout tested end to end, broken links and Se ...
on 11 Oct, 2026 Read More
 
If your browser says "Your connection is not private" or "Not secure" on a website that worked yesterday, the first thing to suspect is an expired SSL (TLS) certificate. Your content and data are stil ...
on 11 Oct, 2026 Read More
 
You add subscriptions to an online store by installing a subscription app or extension on your platform (or building a custom billing module), connecting it to a payment provider that stores cards wit ...
on 11 Oct, 2026 Read More