# My SSL certificate has expired: what happens now

> An expired certificate does not break the site: it breaks the trust the browser grants it. Visitors get a full-screen warning advising them to leave, and most do. Putting it right is quick; the real question is why renewal, supposedly automatic, did not happen.

- Source canonique : [https://allaux.fr/en/problemes/certificat-ssl-expire](https://allaux.fr/en/problemes/certificat-ssl-expire)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Read the real expiry date: openssl s_client -connect your-domain.com:443 -servername your-domain.com shows the certificate actually served, which is not always the one the panel reports. Then reissue from the SSL/TLS section of the hosting panel. If Let’s Encrypt renewal keeps failing on its own, the cause is nearly always an .htaccess rule redirecting or blocking /.well-known/acme-challenge/.

## What actually changes

The certificate does two things: it encrypts the connection, and it attests that the server answering really belongs to the requested domain. Once the validity date has passed, the browser can no longer verify the second part and refuses to show the page without explicit confirmation from the visitor.

The consequences go beyond display. Applications that call your site — a carrier module, business software, a payment service, an indexing robot — usually refuse the connection with no way around it. An expired certificate therefore also stops automated flows whose execution nobody watches.

## Why automatic renewal failed

1. **The domain no longer points to the right place** — Automatic validation checks that you control the domain by querying the server it points to. After a nameserver change, validation fails silently for weeks before the certificate expires.
2. **A redirect blocks validation** — A rule redirecting all traffic to HTTPS or to another address also intercepts the technical path the certificate authority uses to verify the domain.
3. **Renewal was never automatic** — Some paid certificates are annual and manual. Nobody reads the warning address, and the deadline passes without anyone being told.
4. **A subdomain was forgotten** — The certificate covers a precise list of names. Adding a subdomain without including it produces a warning on that name alone, which looks like an intermittent problem.
5. **The renewal task is stopped** — On a server you administer, renewal depends on a scheduled task. If it was disabled during other work, nothing restarts it.

## Do not ask customers to click past the warning

> Teaching your customers to ignore a security warning is the worst possible answer, and it leaves a lasting mark on how the site is perceived. A certificate can usually be replaced the same day.

## After service is restored

Once the certificate is renewed, two checks are worth the detour. First the certificate chain: a valid certificate installed without its intermediate works on desktop browsers and fails on some phones, producing an apparently random problem. Then the next expiry date and the address the warning will be sent to — the only way to stop the situation repeating.

Check the HTTPS redirect is in place, otherwise both versions of the site coexist.

Check that automated calls to your site have resumed: an interrupted flow does not always restart by itself.

## Carry on with the right page

- **Moving a site to HTTPS** — The full procedure, including redirects and mixed content. ([/guides/passer-site-en-https](/guides/passer-site-en-https))
- **SSL and TLS explained** — What the certificate really guarantees, and what it does not. ([/glossaire/ssl-tls](/glossaire/ssl-tls))
- **Domain names** — If the expiry relates to the domain or nameservers rather than the server. ([/services/noms-de-domaine](/services/noms-de-domaine))
- **Web hosting** — How I organise automatic renewal on the sites I look after. ([/services/hebergement-web](/services/hebergement-web))

## FAQ

### Can an expired certificate hurt my search ranking?

Indirectly, yes: indexing robots treat an invalid certificate as an unreachable site. Over a few hours the effect is negligible; over several days, pages can drop out of the index.

### Is my site less secure during that period?

Encryption keeps working. What is missing is the identity guarantee. The real risk is commercial: visitors leave.

### Are free certificates less reliable?

The encryption level is identical. The difference is the shorter validity period, which makes automatic renewal essential, and the commercial guarantees attached.

### Why does the warning only appear on some devices?

That is the classic symptom of an incomplete certificate chain: desktop browsers fill in the missing link, some mobile browsers do not.

### Can I renew it myself?

With most shared hosts, yes, in a few clicks from the panel. On a server you administer, you need server access and a look at the scheduled renewal task.
