Secure connection and certificate errors
NET::ERR_CERT_DATE_INVALID
The certificate looks expired or not yet valid.
Quick answer
Certificates are valid only between two dates. Either the website's certificate really expired, or your device's clock is wrong, which makes a valid certificate look out of date.
When to wait: Waiting does not help unless the owner is renewing right now.
If you are visiting the website
- Read the wording on the warning If Chrome or Edge says "Your clock is behind" or "Your clock is ahead", the browser already suspects your device clock. Fix the clock first. If there is no clock message, the website's certificate may really have expired.
- Turn on automatic date and time A certificate is only valid between two dates. If your device thinks it is a different day, a good certificate looks expired. Let the device take the time from the internet, check the time zone, then reload.
- Windows
- Start > Settings > Time & language > Date & time. Turn on "Set time automatically" and check the time zone. If a "Sync now" button is shown, click it.
- macOS
- Apple menu > System Settings > General > Date & Time. Turn on "Set time and date automatically".
- Android
- Settings > System > Date & time. Turn on "Set time automatically" and "Set time zone automatically". Names can differ slightly by phone maker.
- iPhone and iPad (iOS)
- Settings > General > Date & Time. Turn on "Set Automatically". If it is greyed out, a Screen Time passcode or a work profile may be blocking the change.
- Linux
- Run
timedatectl statusand look for "System clock synchronized: yes". If it says no,sudo timedatectl set-ntp trueturns on network time on systemd-based systems.
- Check whether other secure sites fail too Open two or three well-known HTTPS sites. If they all show date warnings, your clock is the cause. If only this one site fails, the site's certificate has most likely expired.
- Try another device Open the same address on a phone or another computer with a correct clock. If it works there, the problem is on your first device.
- If your clock keeps resetting On older desktop PCs, a clock that jumps back after every shutdown can point to a worn-out motherboard battery (a small coin cell). Automatic time fixes it after start-up, but a repair shop can replace the battery.
- Tell the website owner If your clock is right and the site still fails, the certificate has expired. Contact the site through another channel and mention the error code and the date you saw it.
If you run the website
- Confirm the expiry date Run
sudo certbot certificates, or check from outside withopenssl s_client -connect example.com:443 -servername example.compiped intoopenssl x509 -noout -dates. The notAfter line is the last valid moment. - Renew now and reload Run
sudo certbot renew. Then test withsudo nginx -tand reload withsudo nginx -s reload, or runapachectl configtestandapachectl graceful. Until the server reloads it keeps serving the old certificate. - Find out why automatic renewal failed Run
sudo certbot renew --dry-runto test renewal safely against the staging server. Check that a timer or cron job exists withsystemctl list-timers. Common blockers are a closed port 80, changed DNS or a moved web root. - Reload automatically after renewal A renewed file on disk is not enough. Add a hook such as
--deploy-hook "systemctl reload nginx"so the server picks up each new certificate. - Update every place that serves the certificate Load balancers, extra servers, mail servers and CDN origins may each hold their own copy. Behind Cloudflare in Full (strict) mode, an expired origin certificate shows visitors a 526 error instead.
- Monitor expiry Certbot renews when less than one third of a certificate's lifetime remains. Add an external expiry alert, so a silent renewal failure is caught before visitors see it.
Your clock or their certificate?
Every certificate has a start date and an end date. Your browser compares them with your device clock, not with an internet clock.
So two very different problems look the same: a site that forgot to renew, or a device that thinks it is another year. The quickest test is to open other secure sites and see if they fail too.
How it differs from other certificate errors
ERR_CERT_AUTHORITY_INVALID is about who issued the certificate. ERR_CERT_COMMON_NAME_INVALID is about the site name.
This error is only about time. That makes it the one error a visitor can often fix alone, by correcting the clock.
For developers: what happens technically
The certificate holds notBefore and notAfter fields. If the client's current time is outside that window, validation fails before any page content is sent.
Firefox shows the same problem as SEC_ERROR_EXPIRED_CERTIFICATE. Safari shows a general "This Connection Is Not Private" page.
Common questions
Is it safe to continue past the warning if the certificate only expired yesterday?
Do not do it on sites with logins, payments or personal data. An expired certificate can no longer prove who is on the other end, and you cannot tell from the warning whether that is the only problem. Wait for the owner to renew.
Why does my computer clock keep going wrong?
Usually automatic time is turned off, or the time zone is wrong. On older desktop PCs a weak motherboard battery can reset the clock after every shutdown.
The owner says the certificate is renewed. Why do I still see the warning?
The server may still be serving the old certificate because it was not reloaded, or one of several servers was missed. Reload the page later, and tell the owner the time you checked.
Does Let's Encrypt renew certificates by itself?
Not by itself. A client such as Certbot must run regularly and renew when less than one third of the lifetime is left. If that job breaks, the certificate expires.
Likely causes
- Common The website forgot to renew its certificate. (Website side)
- Common Your device's date or time is wrong. (Your side)
What to avoid
- Do not bypass the warning to log in or pay.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Chromium source: net/base/net_error_list.h
- Google Chrome Help: Get help with common error messages in Chrome
- Mozilla Support: What do the security warning codes mean?
- Let's Encrypt: Getting Started
- Certbot documentation: User Guide
- Apple Support: Set the date and time automatically on Mac
- Apple Support: If you can't change the time or time zone on your Apple device
- Microsoft Support: How to set your time and time zone
- Google Pixel Phone Help: How to fix Wi-Fi connection problems (date and time)
- Linux man page: timedatectl(1)
- OpenSSL: x509 manual
Last reviewed: