Comparing hosting options?
This guide covers the real price tiers, what managed actually means, and when to upgrade.
Want it handled instead?
Managed VPS hosting from $29/mo, no cPanel, free zero-downtime migration.
Last updated: August 2026
What visitors are seeing right now
Chrome shows "Your connection is not private" with the code NET::ERR_CERT_DATE_INVALID. Safari and Firefox show similar walls. Visitors can click through "Advanced," but almost nobody does, an expired certificate reads as "this site is dangerous," and for a business site the traffic loss is close to total until it's fixed.
The fix, fastest path first
1. Confirm expiry is the actual problem. Run your domain through a free SSL checker (SSL Labs, or just click the padlock area in Chrome → certificate details). If the certificate shows a past expiry date, continue. If it's valid but errors persist, your problem is a name mismatch or an incomplete certificate chain, different fixes.
2. If your SSL came free with hosting (most common): log into your hosting panel, find SSL/Security, and hit reissue or renew. Free Let's Encrypt certificates renew instantly. If the renew button fails, the usual culprit is a DNS or domain-verification problem, check that your domain hasn't expired too (it happens together more often than you'd think).
3. If you bought the certificate separately: renew with the provider, generate a new CSR from your hosting panel if asked, install the new certificate files, and restart the web server if you manage it yourself.
4. Clear and verify. Test in an incognito window and on your phone using cellular data. Certificate errors can linger in cached sessions.
Why did auto-renew fail?
Because "auto" has dependencies. The renewals we see fail come down to: an expired payment card on the SSL or hosting account, a domain that changed DNS providers (breaking the verification the renewal relies on), a CAA DNS record blocking the certificate authority, or a server whose renewal cron job silently died months ago. Auto-renewal is a system, and systems need monitoring.
Making it never happen again
- Turn on auto-renewal and confirm the payment method on file is current
- Add SSL expiry monitoring, free tools will email you at 30/14/7 days out; our client dashboard tracks it continuously
- Check your domain registration expiry at the same time; set both to auto-renew
- Note that maximum certificate lifetimes have been shortening industry-wide, which means renewals happen more often, making monitoring more important each year, not less
SSL and domain expiry monitoring is included in every plan we run, precisely because this is the most embarrassing preventable outage a business can have.
FAQ
Did the expired certificate hurt my Google rankings? A short outage (hours to a couple of days) typically has no lasting ranking effect. Extended expiry can, Google reduces crawling of sites serving certificate errors, and the abandonment behavior compounds it.
Is a free Let's Encrypt certificate good enough for business? For encryption, yes, the cryptography is identical to paid certificates. Paid certificates add things like organization validation and warranties, which matter for some enterprises but rarely for a small business site.
My certificate is valid but Chrome still warns, why? Usually mixed content (the page loads some images/scripts over http://) or a missing intermediate certificate in the chain. Both are fixable server-side without buying anything.
How long does a renewal take to go live? Minutes, normally. If you just fixed an expired domain as well, DNS propagation can add up to a few hours.
Want hosting you never have to think about?
Managed VPS hosting at $29/mo, or $19 alongside any care plan. No cPanel to learn: you tell us what you need in chat and an engineer does it, usually within minutes. Free zero-downtime migration.