NET::ERR_CERT_DATE_INVALID: expired certificate or wrong clock?

How to tell whether the certificate expired or the device clock is wrong, how to renew and reload properly, and how to never be surprised by it again.

· 3 min read · By the Spot Downtime team

NET::ERR_CERT_DATE_INVALID (“Your connection is not private”) means the site's certificate isn't valid right now, according to your device's clock. Either the certificate has expired, or your clock is wrong. Firefox shows the same problem as SEC_ERROR_EXPIRED_CERTIFICATE.

First: is it the site or your clock?

If every HTTPS site shows this error, it's your device. A computer with a dead clock battery, or a phone set to the wrong date, sees every certificate as expired or not yet valid. Turn on automatic date and time, and the error goes away.

If it's only one site, check its certificate from outside:

SSL certificate checkerSee a certificate's exact validity dates, issuer and covered names, as the rest of the world sees it.

For site owners: renew, then reload

If the checker shows an expired certificate, renew it and make sure the web server actually loads the new one:

bash
sudo certbot renew
sudo systemctl reload nginx          # the step most often forgotten
sudo certbot certificates            # confirm the new expiry

Renewed, but still expired?

  • Not reloaded. The server still serves the old certificate from memory. Reload or restart it.
  • A different copy. A load balancer, CDN or second server has its own certificate that wasn't updated.
  • A different server. DNS points somewhere other than the machine you renewed on.

“Not yet valid”

Rarer, but it happens: a brand-new certificate on a server whose clock is behind, or visitors with clocks set in the past. Check the server clock with timedatectl and make sure NTP is on.

Certificates are getting shorter

Publicly trusted certificates can now be valid for at most 200 days, dropping to 100 days in 2027 and 47 in 2029. More renewals means more chances for one to fail quietly. Read why certificates still expire for the usual causes.

Never be surprised by it

An expired certificate is entirely predictable, yet it still takes sites down. Spot Downtime reads the expiry date on every HTTPS check and warns you 14 days ahead, with SSL monitoring included on every website monitor.

Keep reading