Chrome shows the interstitial with the certificate's exact expiry date, which is the fastest confirmation of whether the clock or the certificate is wrong.
Chrome shows the interstitial with the certificate's exact expiry date, which is the fastest confirmation of whether the clock or the certificate is wrong.
Click Advanced on the warning page to read the reported dates. If the notAfter date is in the future, your clock is wrong; if it is in the past, the certificate genuinely lapsed.
Chrome has its own failure mode, but ERR_CERT_DATE_INVALID has a wider set of causes. The most common one overall is: The certificate expired and auto-renewal silently stopped.
Renew immediately. For Let's Encrypt, run the renewal manually and read the output — the usual cause is a failing HTTP-01 challenge after a redirect or firewall change.
The SSL checker returns the exact notAfter date and days remaining for the hostname, which immediately separates 'genuinely expired' from 'your clock is wrong'.
Chrome shows the interstitial with the certificate's exact expiry date, which is the fastest confirmation of whether the clock or the certificate is wrong.
Click Advanced on the warning page to read the reported dates. If the notAfter date is in the future, your clock is wrong; if it is in the past, the certificate genuinely lapsed.
The certificate the server presented is outside its validity window — almost always expired. Either the certificate genuinely lapsed, or the device's clock is wrong so a valid certificate looks expired.