DNS, Security & Integrations
Renew SSL Certificate
Renew an expiring or expired SSL certificate before (or after) it causes a security warning for visitors.
The Problem
Your SSL certificate has expired or is about to, and visitors are seeing (or will soon see) a security warning telling them your site isn't safe — which most people take seriously and leave rather than ignore.
About this problem
SSL certificates aren't permanent — most, especially free Let's Encrypt ones, last 90 days and are meant to auto-renew, while paid certificates often run a year. When auto-renewal is set up correctly this is invisible, but it's common for the automation to silently fail (a changed server configuration, a renewal cron job that stopped running, an account issue) leaving the certificate to quietly expire without anyone noticing until a visitor reports the warning.
This usually comes up as an urgent fix once someone notices the warning, but it's also a good moment to set up monitoring so it doesn't happen silently again.
What's Included
- Renewing the certificate immediately to resolve the current expiry
- Diagnosing why automatic renewal didn't happen, if it was supposed to
- Fixing the underlying renewal automation so it doesn't silently fail again
- Verifying the renewed certificate is correctly installed and trusted
What's NOT Included
- Switching certificate providers unless the current one is the actual cause of renewal failures
- Ongoing monitoring beyond fixing the renewal automation itself (see server monitoring/alerts service for that)
- Paid certificate purchase/billing issues with a certificate authority
How It Works
- Renew the certificate immediately to stop the expiry (or active expired state) affecting visitors right away.
- Check why automatic renewal didn't trigger, if it was supposed to — common causes include a broken cron job, a changed file path, or a DNS/validation failure.
- Fix the underlying automation so future renewals happen reliably without manual intervention.
- Test the renewal process end to end if practical, rather than just trusting it'll work next time.
- Verify the newly installed certificate shows the correct new expiry date and loads cleanly in a browser.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How often do SSL certificates need renewing?
- Free Let's Encrypt certificates last 90 days and are meant to auto-renew well before that; paid certificates typically last a year or more.
- Why didn't my SSL certificate renew automatically?
- Common causes are a broken renewal cron job, a server configuration change that broke the validation process, or a DNS issue blocking the automated check.
- What happens if I don't renew an expired SSL certificate?
- Visitors get a security warning and most browsers actively discourage proceeding, which drives visitors away and can affect trust in your site.
- Can I set up automatic SSL renewal so I never have to think about it again?
- Yes, that's the whole point of Let's Encrypt's design, and fixing a broken auto-renewal setup is usually part of resolving the immediate expiry too.
- Will renewing my SSL certificate change my website's URL?
- No, renewal just replaces the certificate behind the scenes — your URLs and site structure are completely unaffected.
- How quickly can an expired SSL certificate be fixed?
- Usually within the same session once I have the access needed — it's one of the faster fixes on this list.