Back to error codes
ERROR CERT_HAS_EXPIRED
SSL Certificate Expired
HTTP Error
The SSL/TLS certificate for the server has expired.
Root Cause
The certificate's notAfter date has passed. Let's Encrypt certificates expire every 90 days.
How to Fix
Renew the certificate: certbot renew. Set up automatic renewal with a cron job. Monitor certificate expiry with alerts.
Quick Summary
SSL certificate expired. Renew with certbot renew. Set up automatic renewal and monitoring. Let's Encrypt certificates expire every 90 days.
Key Takeaways
Key Takeaways
- Let's Encrypt certificates expire every 90 days
- Set up automatic renewal: certbot renew runs via cron or systemd timer
- Monitor expiry: check 30, 14, and 7 days before expiry
- Test renewal: certbot renew --dry-run
Use Cases
When to use it
- Let's Encrypt certificate not auto-renewed
- Commercial certificate expired
- Self-signed certificate expired in development
Watch out
Common Mistakes
- Not setting up automatic renewal, always automate Let's Encrypt renewal
- Not monitoring certificate expiry, set up alerts at 30 days before expiry
FAQ
CERT_HAS_EXPIRED SSL Certificate Expired, Frequently Asked
How do I set up automatic Let's Encrypt renewal?
certbot installs a cron job or systemd timer automatically. Verify with: systemctl status certbot.timer or crontab -l | grep certbot
Still having issues?
Check your network logs or use our developer tools to inspect headers, decode tokens, or validate your requests.