Blog/SSL / TLS

How to Check Your SSL Certificate and Fix Common Issues

An expired or misconfigured SSL certificate triggers browser warnings that block visitors, tanking traffic and trust. Here's how to check yours and fix the most common problems.

May 9, 20266 min read

What is an SSL certificate?

An SSL/TLS certificate is a digital document that binds a public cryptographic key to your domain name and organisation. When a browser connects to your site, it checks this certificate to verify: (1) the server is genuinely who it claims to be, and (2) the connection is encrypted.

Without a valid certificate, browsers show full-page blocking warnings ("Your connection is not private") that most users don't click through. Google also ranks HTTPS pages above HTTP equivalents and may deindex pages with certificate errors.

How to check your SSL certificate

1

Browser padlock

Click the padlock icon in Chrome/Firefox/Safari. Shows issuer, valid dates, and whether the connection is using a current TLS version. Quick but limited.

2

Flux8Shield free scanner

Scans your site's SSL/TLS configuration automatically. Checks certificate expiry, cipher strength, TLS version support, HSTS, and mixed content — all in one scan.

3

openssl command line

echo | openssl s_client -servername yourdomain.com -connect yourdomain.com:443 2>/dev/null | openssl x509 -noout -dates — shows exact expiry dates.

4

Google Search Console

Under "Security & Manual Actions → Security Issues", GSC reports HTTPS certificate issues discovered during Googlebot crawls.

5 common SSL errors and fixes

NET::ERR_CERT_DATE_INVALIDCritical

Certificate expired

Your certificate has passed its expiry date. All browsers show a full-page warning and block access.

Fix: Renew the certificate immediately. For Let's Encrypt: run certbot renew. For commercial CAs: purchase a renewal and install. Enable auto-renewal to prevent recurrence.

NET::ERR_CERT_COMMON_NAME_INVALIDCritical

Domain name mismatch

The domain on the certificate doesn't match the domain being visited (e.g., certificate covers example.com but you're visiting www.example.com).

Fix: Issue a new certificate that covers all variants — use a wildcard (*.example.com) or a multi-domain (SAN) certificate that lists both example.com and www.example.com.

Mixed content warningHigh

Mixed content (HTTP resources on HTTPS page)

Your HTTPS page loads some resources (images, scripts, iframes) over HTTP. Browsers block active mixed content (scripts, styles) entirely.

Fix: Update all resource URLs to HTTPS. Search your codebase for http:// references. Set up a Content-Security-Policy: upgrade-insecure-requests; header as an additional safety net.

Weak cipher / old TLS versionMedium

TLS 1.0 or 1.1 enabled

TLS 1.0 and 1.1 are deprecated. Browsers may show warnings, and some enterprise clients refuse connections on these versions.

Fix: Configure your server to only accept TLS 1.2 and TLS 1.3. In Nginx: ssl_protocols TLSv1.2 TLSv1.3. In Apache: SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1

Missing HSTS headerMedium

No HSTS enforcement

Without HSTS, users who type your domain without https:// may be vulnerable to protocol downgrade attacks before the HTTPS redirect happens.

Fix: Add the Strict-Transport-Security header with at least max-age=31536000. Once confirmed stable, add includeSubDomains and consider HSTS preloading.

Setting up auto-renewal

Certificate expiry is 100% preventable with auto-renewal. Most modern hosting platforms (Netlify, Vercel, Cloudflare) renew certificates automatically with zero configuration. For self-managed servers, Let's Encrypt's Certbot handles this with a single cron job.

# Certbot auto-renewal (runs twice daily via systemd or cron) 0 */12 * * * /usr/bin/certbot renew --quiet

Check your SSL certificate free

Instant cert check + expiry countdown + TLS config + 40 security checks.

Free Security Scan →

Frequently asked questions

How do I know if my SSL certificate is valid?

Click the padlock icon in your browser address bar. It shows the certificate issuer and expiry date. For a more detailed check, Flux8Shield's free scanner shows certificate validity, expiry countdown, and any configuration issues.

How often should I renew my SSL certificate?

Most certificates are issued for 90 days (Let's Encrypt) or up to 1 year (commercial CAs — the maximum allowed since 2020). Set up auto-renewal to avoid lapses. Let's Encrypt's Certbot can automate this entirely.

Does an expired SSL certificate affect SEO?

Significantly. Google treats expired certificates as security issues. Chrome shows a full-page "Your connection is not private" warning that blocks most users from entering. Bounce rates spike to near 100% and Google may derank affected pages.

What is mixed content and why is it a problem?

Mixed content occurs when an HTTPS page loads resources (images, scripts, styles) over HTTP. Browsers either block or flag these resources. Script and stylesheet mixed content is blocked entirely in modern browsers, which can break page functionality.

What is the difference between SSL and TLS?

SSL (Secure Sockets Layer) is the older, now-deprecated protocol. TLS (Transport Layer Security) is the current standard. Despite this, "SSL certificate" remains the common term for TLS certificates. No modern server should use SSL 2.0 or 3.0 — both are considered broken.