NET::ERR_CERT_DATE_INVALID: How to Fix It Fast (2026 Guide)

Browser warning that an SSL certificate date is invalid
NET::ERR_CERT_DATE_INVALID means the certificate looks expired, not yet valid, or the device clock is wrong

NET::ERR_CERT_DATE_INVALID means the browser thinks the website’s SSL certificate is outside its valid date range. In plain terms, the certificate looks expired, not yet valid, or the device checking it has the wrong date, time, or time zone.

This error is common in Chrome, but the same problem can appear in Firefox, Edge, Android, Windows, and macOS. The fix is usually straightforward once you know whether the problem is on your device or on the website.

Quick Fix

  • Check your device date, time, and time zone.
  • Turn on automatic time sync.
  • Reload the page and test the site in another browser.
  • Try the site on another device.
  • Clear browser cache and restart the browser.
  • Disable VPN, proxy, or antivirus HTTPS scanning temporarily.
  • Update your browser and operating system.
  • If you own the site, check whether the SSL certificate is expired or not yet valid.
  • If you use Cloudflare, check certificate validity and renewal status.
  • Run an external SSL test to confirm the dates visitors actually receive.

What Is NET::ERR_CERT_DATE_INVALID?

Wrong device clock causing an SSL certificate date error
A wrong system clock is one of the most common causes of this certificate date error

NET::ERR_CERT_DATE_INVALID is a browser SSL warning that appears when the certificate fails a date validity check. Every SSL certificate has a start date and an expiration date. If the current time falls outside that window, the browser rejects it.

That does not always mean the site owner forgot to renew the certificate. Sometimes the certificate is fine, but the computer or phone has the wrong clock. Check the system date, time, and time zone before anything else.

You may also see:

  • Your connection is not private
  • NET::ERR_CERT_DATE_INVALID
  • SEC_ERROR_EXPIRED_CERTIFICATE in Firefox

The browser blocks the site because it cannot trust the certificate at the current time. That matters most on login pages, payment forms, webmail, and admin dashboards.

Why NET::ERR_CERT_DATE_INVALID Happens

1. Your Device Date or Time Is Wrong

This is one of the most common causes. If the device clock is ahead or behind, the browser may treat a valid certificate as not yet valid or already expired.

This often happens after a CMOS battery failure, a manual time change, travel between time zones, disabled automatic time sync, or a BIOS reset.

2. The Website Certificate Is Expired

This is the most obvious server-side cause. The SSL certificate passed its expiration date and was not renewed or redeployed. If you uploaded a custom certificate to Cloudflare, you must replace it yourself before it expires.

3. The Certificate Is Not Valid Yet

Certificates also have a start date. If the site or CDN serves a new certificate before its valid-from time, browsers reject it. A wrong server clock or a client clock can create the same result.

4. The Browser or Operating System Trust Store Is Outdated

On older Windows systems, missing root certificate updates can cause SSL problems even when the site is configured correctly. This is more likely on PCs with updates disabled or locked-down corporate devices.

5. VPN, Proxy, or Antivirus HTTPS Inspection Is Interfering

Some security tools intercept HTTPS and present their own certificates. If that local certificate is broken or out of date, the browser can show this error even though the website is fine. This is likely when many sites fail on only one device after antivirus or VPN software was installed.

Expired SSL certificate on a website server
If the error appears on every device, the live certificate is usually expired or not yet valid

6. Cloudflare or CDN Certificate Timing Issues

Managed Cloudflare certificates renew on their own. Uploaded custom certificates do not. Problems appear when a custom certificate expired, the wrong certificate is served, the origin certificate is expired, or the new certificate was not deployed.

How to Fix NET::ERR_CERT_DATE_INVALID Step by Step

1. Check the Device Date, Time, and Time Zone

  1. Open date and time settings.
  2. Confirm the date, time, and time zone.
  3. Turn on automatic time and time zone if available.
  4. Restart the browser and reload the site.

A correct clock with the wrong time zone can still trigger this error.

2. Check Whether the Error Happens on One Site or Many

  • One site fails → the website certificate is the likely issue.
  • Many sites fail → the problem is probably on your device.
  • The site works on another device → focus on the affected browser or computer.

3. Try Another Browser and Another Device

Test in Chrome, Firefox, Edge, and on a phone using mobile data. If the site fails everywhere, the certificate is likely expired or misconfigured. If it fails only on one device, check the clock, trust store, proxy, or antivirus.

4. Clear Browser Cache and Restart the Browser

Open a private window and test again. If it works there, clear cache and cookies, then restart the browser. This helps most after a certificate renewal.

5. Disable VPN, Proxy, and Antivirus HTTPS Scanning

Disconnect the VPN and quit the app. Turn off proxy settings and browser proxy extensions. Temporarily disable antivirus HTTPS scanning, then test again. If the warning disappears, the local security layer was the source.

6. Update Your Browser and Operating System

Update Chrome, Edge, or Firefox, plus Windows, macOS, Android, or iOS. On Windows, missing trusted-root updates can break certificate validation on older systems.

Server administrator checking SSL certificate expiration dates
Renewing a certificate is not enough if the live server is still serving the old file

7. If You Own the Site, Check the Certificate Expiration Date

Verify the expiration date, the valid-from date, the domain names covered, and the certificate chain. If it is expired, renew it and deploy the new file to the live server.

8. Confirm the New Certificate Was Really Installed

Many renewals succeed in the panel while the live site still serves the old certificate. Check the certificate path, private key path, virtual host or server block, and any load balancer in front of the origin.

9. Check Apache or NGINX HTTPS Configuration

On Apache, confirm the correct SSL virtual host:

<VirtualHost *:443>
    ServerName example.com
    SSLEngine on
    SSLCertificateFile /path/to/fullchain.pem
    SSLCertificateKeyFile /path/to/privkey.pem
</VirtualHost>

On NGINX, confirm the certificate files on the correct hostname:

server {
    listen 443 ssl;
    server_name example.com www.example.com;
    ssl_certificate /path/to/fullchain.pem;
    ssl_certificate_key /path/to/privkey.pem;
}

Typical mistakes: the old certificate is still referenced, the wrong server block handles HTTPS, or the renewal was installed for only one hostname.

10. If You Use Cloudflare, Check Edge and Origin Certificates

Check edge certificate validity, custom certificate expiry if you uploaded one, origin certificate validity, and the SSL/TLS mode between Cloudflare and the origin. With Full (strict), an invalid origin certificate can fail validation and surface as Error 526.

11. Run an External SSL Test

Test the public domain with an SSL checker. Look for an expired certificate, a certificate that is not yet valid, the wrong certificate on the hostname, or an incomplete chain.

Advanced Troubleshooting

Inspect the Certificate Dates with OpenSSL

openssl s_client -connect example.com:443 -servername example.com

This shows the certificate currently served, the valid-from date, the expiration date, and the chain returned by the server.

Check the System Clock Outside the OS

If the clock drifts after every restart, check the BIOS or UEFI clock, the CMOS battery on older PCs, and the time sync service. If the clock keeps resetting, the SSL error will return.

Review Recent Changes

Ask what changed first: certificate renewal, hosting migration, Cloudflare enabled or paused, new antivirus, a new VPN, or clock drift after an update.

Prevention Tips

  • Keep automatic date and time sync enabled.
  • Replace a weak CMOS battery if the PC clock resets often.
  • Renew site certificates early, not on the last day.
  • Verify the live deployment after every renewal.
  • Monitor Cloudflare custom certificate expiration if you upload your own certs.
  • Keep browsers and operating systems updated.
  • Avoid unnecessary HTTPS inspection on admin devices.
  • Run an external SSL test after DNS, hosting, or CDN changes.

When to Contact Support

Contact the website owner or host if only one site shows the error, the certificate is clearly expired, or the problem started right after renewal or migration.

Review Cloudflare SSL if the domain is behind Cloudflare, a custom certificate may have expired, or Full (strict) is failing origin validation.

Focus on the device if many websites fail, only one computer is affected, disabling VPN or antivirus fixes it, or the system clock keeps drifting.

Related SSL Errors

FAQ

What does NET::ERR_CERT_DATE_INVALID mean?

The browser believes the website certificate is outside its valid date range. The certificate may be expired, not yet valid, or your device clock may be wrong.

Can a wrong computer clock cause NET::ERR_CERT_DATE_INVALID?

Yes. Incorrect date, time, or time zone is the first thing to check for time-related secure connection errors.

Why do I get NET::ERR_CERT_DATE_INVALID on every website?

That usually points to a local problem: wrong system time, broken antivirus HTTPS inspection, a proxy or VPN, or an outdated operating system trust store.

Can Cloudflare cause NET::ERR_CERT_DATE_INVALID?

Yes. It can happen if a custom certificate expired, the wrong certificate is deployed, or the origin certificate is invalid in a strict validation setup.

How do I fix NET::ERR_CERT_DATE_INVALID on my website?

Check expiration and start dates, confirm the renewed certificate is actually installed, review Apache or NGINX HTTPS config, and test the public hostname with an external SSL checker.

Final Thoughts

NET::ERR_CERT_DATE_INVALID looks technical, but the root cause is usually simple. Either the device checking the certificate has the wrong time, or the certificate being served really is outside its valid date range.

Start with the system clock. Then test whether the problem affects one site or many. After that, check certificate expiration, live deployment, Cloudflare setup, and trust store issues. That order solves it faster than random SSL changes.

Leave a Comment