Troubleshooting
Your connection is not private: NET::ERR_CERT_DATE_INVALID fix
"Your connection is not private" means the certificate failed a check: expired, wrong name, incomplete chain or a wrong clock. How to find which and fix it.
Updated · 5 min read
What "Your connection is not private" means
"Your connection is not private" means the browser reached the server and completed the first part of the secure handshake, but the certificate the server presented failed a check. The browser stops before loading anything, because it cannot confirm it is talking to the real site.
Chrome shows this page with a code underneath, such as NET::ERR_CERT_DATE_INVALID. Edge says "Your connection isn't private", Firefox shows "Warning: Potential Security Risk Ahead", and Safari shows "This Connection Is Not Private". The wording differs, but the cause is always the certificate, or the device checking it.
Read the error code first
The code under the warning tells you which check failed. In Chrome, click the code or "Advanced" to see it. The common ones:
- NET::ERR_CERT_DATE_INVALID (Firefox: SEC_ERROR_EXPIRED_CERTIFICATE): the certificate has expired or is not valid yet, or the device's clock is wrong.
- NET::ERR_CERT_COMMON_NAME_INVALID (Firefox: SSL_ERROR_BAD_CERT_DOMAIN): the certificate is valid but issued for a different name than the one in the address bar.
- NET::ERR_CERT_AUTHORITY_INVALID (Firefox: SEC_ERROR_UNKNOWN_ISSUER): the browser cannot trace the certificate to a trusted authority. Causes include a self-signed certificate, a missing intermediate certificate, or software intercepting the connection.
- NET::ERR_CERT_REVOKED: the issuing authority has withdrawn the certificate, typically after a key compromise or a mis-issuance. It needs replacing, not bypassing.
Expired certificate (NET::ERR_CERT_DATE_INVALID)
Every certificate has a fixed end date. Let's Encrypt certificates currently last 90 days. Under the CA/Browser Forum's ballot SC-081, publicly trusted certificates issued since 15 March 2026 can be valid for at most 200 days, a cap that drops to 100 days in March 2027 and 47 days in March 2029. Shorter lifetimes make renewal automation essential rather than optional.
The fix is to renew or reissue the certificate: through the hosting control panel, through the certificate authority for a purchased certificate, or with the ACME client on a self-managed server (for example, certbot renew). Reload the web server afterward so it serves the new certificate. If renewal was supposed to be automatic, find out why it failed: a renewal job lost in a server migration, a DNS change that broke domain validation, or a firewall or redirect blocking the validation path.
The same code appears when a certificate is not valid yet. That is rare on the server side, but common on devices whose clock has fallen behind, for example after a dead motherboard battery or a long time switched off. If one device shows the error for a certificate that other devices accept, check that device's clock first.
The SSL certificate checker shows the expiry date and a countdown, which makes it easy to confirm the new certificate is live and to see how much time is left before the next renewal.
Wrong name (NET::ERR_CERT_COMMON_NAME_INVALID)
A certificate lists the exact hostnames it covers in its Subject Alternative Name field. If a visitor types www.example.com and the certificate only lists example.com, the browser rejects it, even though both names are the same site to a human.
Wildcards have limits too. A certificate for *.example.com covers shop.example.com but not example.com itself and not deeper names such as a.b.example.com.
On shared hosting and behind load balancers, this error often means the server is presenting a default certificate, such as one issued for the server's own hostname, because no certificate is configured for the requested name. Issue a certificate that lists every name visitors use. The SSL checker reports whether the certificate covers both the www and apex versions of the domain.
A redirect does not get around this. If www.example.com redirects to example.com, the browser still has to complete a secure connection to www.example.com before it can receive the redirect, so the certificate must cover both names even when one of them only ever redirects.
When the problem is the visitor's device
If the SSL checker reports a valid certificate with a complete chain, yet one device still shows the warning, the cause is local. Check these:
- The clock. A device set to the wrong date sees valid certificates as expired or not yet valid. Chrome often says "Your clock is behind" or "Your clock is ahead". Turn on automatic date and time.
- Public Wi-Fi login pages. Hotel, airport and café networks intercept connections until you sign in. Open a plain http:// page to trigger the login screen, then retry.
- Security software or a workplace network that inspects HTTPS. It replaces site certificates with its own, which fails with an authority error unless its root is installed on the device.
- An outdated device. Very old operating systems may lack the root certificates that newer certificate authorities use, so they distrust certificates that current devices accept.
Should you click "Proceed" anyway?
For visitors: avoid it on any site where you log in, pay or enter personal details, because the warning exists to catch impersonation. On sites that use HSTS (HTTP Strict Transport Security), browsers remove the bypass option entirely, so the site is unreachable until the owner fixes the certificate.
For site owners, that last point is why certificate errors are outages, not cosmetic problems. Most visitors leave at the warning page, and API clients and integrations fail outright. Monitor expiry independently of your renewal automation so a silent failure surfaces weeks before the deadline instead of on the day.
Common questions
- How to fix NET::ERR_CERT_DATE_INVALID?
- If it happens on every device, the site's certificate has expired and the owner needs to renew it and reload the web server. If it happens on one device only, set that device's date and time to update automatically.
- Is "Your connection is not private" a virus?
- No. It is a browser safety warning, not malware. It can appear when security software or a network intercepts encrypted traffic, but usually it means the site's certificate has a problem.
- Why does a site show "Your connection is not private" on one device but not another?
- Either the device has a local cause, such as a wrong clock, intercepting software or old root certificates, or the server sends an incomplete certificate chain that some clients can repair and others cannot. An external SSL check tells the two apart.
- How long is an SSL certificate valid in 2026?
- Publicly trusted certificates issued since 15 March 2026 can be valid for at most 200 days. The cap falls to 100 days in March 2027 and 47 days in March 2029, and Let's Encrypt certificates currently last 90 days.
- Why is there no "Proceed" link on the warning page?
- The site uses HSTS, which tells browsers to refuse insecure or untrusted connections without exception. Only fixing the certificate on the server makes the site reachable again.
SSL certificate checker
Expiry, chain, TLS versions and security headers — graded A to F.
Check your SSL certificateRelated guides
- SSL certificate expired? What happens and how to fix it fastAn expired SSL certificate triggers a full-page browser warning. See how to renew it, fix chain errors, why auto-renewal fails, and the new 200-day limit.
- ERR_SSL_PROTOCOL_ERROR: what it means and how to fix itERR_SSL_PROTOCOL_ERROR means the secure handshake failed before the page loaded. How to tell if it's the server or your device, and the fixes for each.
- How to fix a slow TTFB: server-side fixes that actually workSlow Time to First Byte is a server or network problem, not a page problem. Find the slow phase, then fix it with caching, a CDN, database work or hosting.
- How to check DNS propagation (and why it takes so long)Check DNS propagation by comparing public resolvers with your authoritative nameservers. Learn how TTL sets the timing and why changes seem stuck for hours.