iOS trusts the certificate against the device clock. A phone whose date drifted, or one restored from an old backup, reads a perfectly valid certificate as expired or not yet valid.
iOS trusts the certificate against the device clock. A phone whose date drifted, or one restored from an old backup, reads a perfectly valid certificate as expired or not yet valid.
Settings → General → Date & Time → Set Automatically, then reload. If the date was already correct, the certificate really has expired and only the site owner can renew it.
iPhone has its own failure mode, but ERR_CERT_DATE_INVALID has a wider set of causes. The most common one overall is: The certificate expired and auto-renewal silently stopped.
Renew immediately. For Let's Encrypt, run the renewal manually and read the output — the usual cause is a failing HTTP-01 challenge after a redirect or firewall change.
The SSL checker returns the exact notAfter date and days remaining for the hostname, which immediately separates 'genuinely expired' from 'your clock is wrong'.
iOS trusts the certificate against the device clock. A phone whose date drifted, or one restored from an old backup, reads a perfectly valid certificate as expired or not yet valid.
Settings → General → Date & Time → Set Automatically, then reload. If the date was already correct, the certificate really has expired and only the site owner can renew it.
The certificate the server presented is outside its validity window — almost always expired. Either the certificate genuinely lapsed, or the device's clock is wrong so a valid certificate looks expired.