An expired SSL certificate causes visitors to see a warning in their browser and marks your website as unsafe. Fortunately, this is usually quick to fix: you request a new certificate and install it again. In this article, you’ll learn why certificates expire, how to solve the problem, and how to make sure this happens automatically going forward… or actually, how to prevent it entirely.
What an expired SSL certificate means
An SSL certificate (nowadays often called TLS) always has a validity period. Once that period has passed, the browser no longer trusts your certificate and the visitor sees a message like “Your connection is not private.” The website technically remains accessible, but most visitors won’t click past such a warning, and search engines may rank the page lower.
An expired certificate usually occurs because automatic renewal failed, for example due to a changed DNS setting, a full disk on the server, or because the certificate was requested manually and no one remembered to renew it.
From an expired certificate to a renewed, secure connection.
How to check if your certificate has expired
Not sure whether your certificate has really expired or if something else is going on? Check it in these ways:
- Click the padlock icon next to the URL in your browser and view the certificate details, including the expiration date.
- Open your website in an incognito window to make sure you’re not seeing a cached, old version of the page.
- Log in to Plesk and check the status and validity period under SSL/TLS Certificates for the domain.
Step-by-step plan: renewing the certificate
In most cases, you can resolve an expired certificate yourself via Plesk, without needing any technical knowledge.
Log in to Plesk
Go to your Plesk environment and open the domain whose certificate has expired.
Open SSL/TLS Certificates
Here you can immediately see whether the current certificate has expired or is invalid.
Request a new certificate
Choose a free Let’s Encrypt certificate or upload your own certificate if you’ve purchased one.
Link the certificate to the domain
Make sure the new certificate is actively set for both the main domain and any subdomains.
Check the website again
Reload the site in an incognito window and check whether the padlock icon displays correctly again.
Does the warning persist after installing a new certificate? This may be because your domain’s DNS records aren’t correctly pointing to your hosting server. In that case, check your domain settings in your domain names management.
Preventing expired certificates
The best solution is simple: make sure your certificate renews automatically. Let’s Encrypt certificates are short-lived by nature and are therefore renewed automatically by default, provided automatic renewal is properly configured and not blocked by, for example, an incorrectly configured DNS record or a full server.
Check regularly, for instance once a quarter, whether automatic renewal is still active. With a properly configured hosting environment with free SSL, you’ll practically never need to worry about this again.
Frequently Asked Questions
Does it take time before a new certificate works?
Usually a new certificate is active within a few minutes. Make sure your browser cache is cleared or test in an incognito window to avoid outdated messages.
Will my email also stop working if the SSL certificate expires?
That depends on the configuration. Sometimes email uses a separate certificate. If in doubt, check this via your email hosting settings in Plesk.
Can I install a certificate myself without technical knowledge?
Yes, with a free Let’s Encrypt certificate via Plesk this can be done within a few clicks, without needing to manually upload files.
Conclusion
An expired SSL certificate is annoying, but usually quick to fix by requesting and linking a new certificate in Plesk. After that, make sure automatic renewal is properly configured so you can prevent this problem in the future.