NET::ERR_CERT_DATE_INVALID: Expired Certificate or Wrong Clock?
By the Does This Really Work Or Not editorial team
Published: October 6, 2026 · Last reviewed: October 6, 2026
Quick answer: Chrome shows NET::ERR_CERT_DATE_INVALID ("Your connection is not private") when the site's security certificate is outside its valid dates. That means one of two things: the certificate has expired (or isn't valid yet), or your device's clock is wrong, so a valid certificate looks expired. The check below tells you which.
Is it you or the website? A one-minute check
- Look at your device's date and time. If they're wrong, that's the cause. Turn on automatic time, reload, and you're done.
- Click "Advanced" on the error page. Chrome often names the problem directly, for example "its security certificate expired 3 days ago".
- Run the domain through our SSL checker. It shows the certificate's expiry date as seen from outside your device. If it shows the certificate as expired, the website owner has to fix it, and nothing you change on your side will help.
Why more sites are hitting this in 2026
Certificates are getting shorter lives, so they have to be renewed more often. Under a rule adopted by the CA/Browser Forum, the industry group that sets certificate standards (ballot SC-081), the maximum lifetime of a public certificate is falling:
| Certificates issued from | Maximum validity |
|---|---|
| Before March 15, 2026 | 398 days |
| March 15, 2026 | 200 days |
| March 15, 2027 | 100 days |
| March 15, 2029 | 47 days |
The first certificates issued under the 200-day limit, in mid-March 2026, expire in early October 2026. Teams that renewed by hand once a year and put the next renewal in the calendar a year out are now finding their certificates expired months earlier than they expected. Automated renewal stops being optional as lifetimes keep shrinking.
If you're visiting the site
- Fix your clock: set date, time and time zone to automatic. A dead battery on an older computer's motherboard can reset the clock every time it boots.
- If your clock is correct, the certificate really is out of date. Don't click "Proceed (unsafe)" on a site where you log in or pay: you can't be sure you're talking to the real site. Try again later, or let the site owner know.
- On a public Wi-Fi network (hotel, airport, café), the error can appear because the network is trying to show you a login page. Open any plain
http://site to bring up the login page, then retry.
If it's your website
-
Confirm what's being served. Run our SSL checker, or from a terminal:
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -datesThe
notAfterline is the expiry date the world sees. -
Renew the certificate.
- With Let's Encrypt and Certbot: run
sudo certbot renew, and usesudo certbot renew --dry-runto check that automatic renewal will work. - With a hosting panel or CDN: use its "renew" or "reissue" button.
- With Let's Encrypt and Certbot: run
-
Reload the web server after renewing. This is the classic trap: the new certificate is on disk, but Nginx or Apache is still serving the old one from memory. Run
sudo systemctl reload nginx(orapache2/httpd), or add a deploy hook so Certbot reloads automatically. -
Check every place the certificate lives. Load balancers, CDNs, mail servers and other subdomains may each hold their own copy. Renewing one doesn't renew the others.
-
Find out why renewal didn't run on its own. Common reasons:
- The renewal timer or cron job is disabled.
- The validation check failed because port 80 is blocked or the DNS records changed.
- The domain moved to another server.
- A CAA record doesn't list the certificate authority you renew with.
-
Set up expiry monitoring that warns you 30 days and 7 days before expiry, separate from the renewal system itself. Our guide SSL Certificate Expiry Patterns covers the failure patterns behind most expiry outages.
Related errors
NET::ERR_CERT_AUTHORITY_INVALID: the certificate isn't signed by an authority the browser trusts. Typical causes are a self-signed certificate or a missing intermediate certificate.NET::ERR_CERT_COMMON_NAME_INVALID: the certificate is for a different hostname, for example it coverswww.example.combut you visitedexample.com.ERR_SSL_PROTOCOL_ERROR: the secure connection failed before any certificate check.
FAQ
Can I just click "Proceed anyway"?
Only on a site where you enter nothing sensitive and you trust the network. An expired certificate isn't proof of an attack, but the browser can no longer vouch that you've reached the real site.
My certificate auto-renews. How did it still expire?
Usually renewal succeeded but the server wasn't reloaded, or renewal failed quietly weeks ago. Run the dry-run command above and check your renewal logs.
How often will I have to renew from now on?
Under SC-081, at most every 200 days for certificates issued now, every 100 days from March 2027, and every 47 days from March 2029. Free automated certificates already renew more often than that.