The Cloudflare edge certificate is valid but the origin certificate behind it expired, so Full (Strict) mode fails on the origin leg.
The Cloudflare edge certificate is valid but the origin certificate behind it expired, so Full (Strict) mode fails on the origin leg.
Check the origin directly by IP with an SSL tool, not through Cloudflare. Renew the origin certificate, or replace it with a 15-year Cloudflare Origin Certificate that cannot silently lapse.
Cloudflare has its own failure mode, but ERR_CERT_DATE_INVALID has a wider set of causes. The most common one overall is: The certificate expired and auto-renewal silently stopped.
Renew immediately. For Let's Encrypt, run the renewal manually and read the output — the usual cause is a failing HTTP-01 challenge after a redirect or firewall change.
The SSL checker returns the exact notAfter date and days remaining for the hostname, which immediately separates 'genuinely expired' from 'your clock is wrong'.
The Cloudflare edge certificate is valid but the origin certificate behind it expired, so Full (Strict) mode fails on the origin leg.
Check the origin directly by IP with an SSL tool, not through Cloudflare. Renew the origin certificate, or replace it with a 15-year Cloudflare Origin Certificate that cannot silently lapse.
The certificate the server presented is outside its validity window — almost always expired. Either the certificate genuinely lapsed, or the device's clock is wrong so a valid certificate looks expired.