TLS
Your TLS certificate has expired. Here's how to restore the site fast.
Published 2026-05-20 · Last updated 2026-05-20 · Vantyris editorial
To your customers, an expired TLS certificate takes the site fully offline. Modern browsers show a full-screen warning ('Your connection is not private') with no easy 'continue anyway' button. Until you renew, you have zero traffic. The usual cause is a failed auto-renewal, and renewing by hand takes minutes.
What this means for your business
- Every TLS certificate has an expiry date. Let's Encrypt certificates last 90 days. Paid certificates typically last 12 months. Auto-renewal handles this in the background, until something breaks the cron job, the API key, or the DNS challenge.
- When the certificate expires, browsers refuse to connect. They show your visitor a security warning instead of your site, and your conversion rate sits at zero until the renewal completes.
- Most expirations are operational failures, not crypto attacks. In the usual story, the auto-renewal stopped working three weeks ago and nobody noticed, because the host's emails went to a mailbox no one reads.
How to fix
Log in to your web host or certificate manager, trigger a manual renewal, then find out why auto-renewal failed.
- Trigger a manual renewal. Most hosts have a 'Renew now' button in the SSL section of their control panel. Cloudflare manages its certificate for you, and it rarely expires. If something has expired behind Cloudflare, look at your origin server's certificate, not Cloudflare's edge. Work out which one expired (origin or edge) before you chase the wrong one.
- If the host UI doesn't help, use the command line. If you're using certbot (the most common Let's Encrypt client), run
sudo certbot renew --force-renewalon the server. Then reload your web server withsudo systemctl reload nginx(orapache2). - Verify. Visit your site in an incognito window. The browser warning should be gone and the padlock back. Run a Vantyris scan or ssllabs.com/ssltest to confirm the new certificate's validity period.
- Investigate why auto-renewal failed. Common causes: the renewal cron stopped firing, the ACME client lost its API key, your DNS provider changed (breaking DNS-01 challenges), or your firewall blocks port 80 (breaking HTTP-01 challenges). Fix the root cause, or this happens again in 90 days.
- Set up monitoring. Enrol the target in Vantyris continuous monitoring with the 'TLS cert expires within 14 days' alert enabled, or use a free monitor like UptimeRobot's TLS check. You should never learn about an expired cert from a customer email.
Owner: Your web host's support team, or your developer if you self-host. · Time: 30 minutes if your host supports one-click renewal, longer if you need to debug auto-renewal.
Common gotchas
- Check you're looking at the right certificate. Behind Cloudflare, three are in play: the visitor-facing edge cert (managed by Cloudflare), the origin cert (managed by you), and any intermediate cert in the chain. An expired edge cert is rare. An expired origin cert is common.
- Some auto-renewals fail silently because the renewal email goes to a noreply mailbox or gets filtered as spam. Send renewal notifications to a real person's inbox.
- If you recently moved to a new host and copied the cert across, the new server may have no auto-renewal client installed at all.
How to verify the fix
Vantyris's tls.cert_expired finding clears once the new cert is live. Or paste your domain into ssllabs.com/ssltest and confirm the 'Valid until' date is at least 30 days in the future.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
How often do certificates need renewing?
Let's Encrypt: every 90 days, automatically. Paid certificates: every 12 months, usually by hand unless your CA offers ACME automation. Most modern setups should be fully automated. Manual renewal is a sign the setup needs upgrading.
Can I just buy a cert with a longer expiry?
No. Certificate lifetimes have been shrinking industry-wide (the current cap is 398 days, and there are proposals for 90-day maximums by 2027). Build for automated renewal.
Why doesn't the browser let me skip the warning?
On many sites with HSTS enabled, browsers won't let visitors bypass a certificate error. That's by design. HSTS says 'this domain MUST be HTTPS', so an invalid cert is treated as an attempted attack.
References
Related explainers
- HTTPS for small business: how to enable it in 15 minutes.
- HSTS: the security header that locks HTTPS on for good.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris