Back to Insights
SSL CertificatesCertificate expirationHTTPSCertificate Management 2024-10-18

What Happens When an SSL Certificate Expires?

Expired SSL certificates can trigger browser warnings, interrupt access and erode trust. Learn why certificates expire and how to prevent missed renewals.

SSL certificates support two important functions: encryption and identity authentication. Their limited validity helps keep the information supporting that authentication current. If a website presents an expired certificate, a visitor’s browser will usually display a security warning.

More organizations are using certificates and HTTPS to authenticate their sites and encrypt communications with visitors. Website operators nevertheless often ask why certificates expire, what happens when they do and how to avoid missed renewals. This article addresses those questions.

Why do SSL certificates expire?

All SSL certificates involve validation. Even a basic DV certificate requires proof of control over the domain. Limited certificate lifetimes ensure that this evidence is revisited rather than remaining valid indefinitely.

Website ownership and businesses change: companies may be sold, reorganized or closed. A CA needs the information used to validate a server or organization to remain sufficiently current and accurate.

The original article uses the former electronics retailer Circuit City as an illustration. Imagine a business closing and its assets and domain changing hands while an old certificate remained valid indefinitely. A malicious new operator who obtained the relevant domain and credentials could misuse outdated identity information. This is a hypothetical illustration of stale trust, not a claim that Circuit City experienced that attack.

The source also cites historical 27-month certificate lifetimes and Apple’s September 1, 2020 change rejecting newly issued certificates longer than approximately 13 months. Those historical limits are not current renewal guidance. As checked in September 2026, the CA/Browser Forum’s public TLS Baseline Requirements cap newly issued subscriber certificates at 200 days from March 15, 2026, 100 days from March 15, 2027, and 47 days from March 15, 2029. Operators must monitor the actual certificate’s expiration and current applicable rules. See the CA/Browser Forum’s certificate validity requirements.

What happens when a certificate expires?

Browsers validate certificates during connection setup. Once a certificate is outside its validity period, the connection will usually be interrupted with a warning such as the one below.

Browser warning for an expired certificate

Many visitors will leave rather than proceed. The resulting loss of traffic and confidence can affect business operations.

The original article cites repeated LinkedIn certificate-expiration incidents as an example of outages and reputational harm, describing two incidents within two years. Its relative reference to “last year” is not precise enough to assign a new date here. Interrupted access can affect users, revenue and search visibility. Expiration does not itself decrypt data, but bypassing warnings or introducing insecure workarounds can create additional exposure—especially for sensitive services.

How can you prevent missed renewals?

Small businesses may have only a few certificates, while large networks can have many. Missed renewals are often a matter of incomplete inventory or oversight rather than a lack of technical ability.

A reliable certificate management platform can help track certificates and renewal responsibilities. The original Chinese article described Racent’s service at the time: automated reminders within 90 days of expiration, supplemented by phone and email notifications. That historical service description should not be treated as a guarantee of NicSRS’s current reminder schedule; confirm the process for your account and certificate lifetime.

If your website already shows an expiration warning, promptly obtain a replacement SSL certificate and replace the expired certificate on every affected endpoint.

Choose a suitable certificate and manage it through a trustworthy platform with clear monitoring and renewal procedures. The original article identifies Shanghai Ruicheng Information Technology Co., Ltd. (Racent) as a provider of these services in China. For current international support, please contact us.