Synthetic Industry

Troubleshooting guide · updated 2026-10-10

Certificate expired? Diagnose the served certificate and renewal path separately

Identify the affected hostname and authorised certificate manager without assuming a missing reminder email means renewal stopped.

Record the precise warning

Identify the hostname and browser message: expired, wrong name and an untrusted chain are different findings. Check the certificate actually served to that hostname; a certificate installed elsewhere may not be the one a visitor receives. Do not instruct visitors to bypass the warning as a repair.

  • Keep the public hostname and expiry date if visible.
  • Identify whether the certificate is managed by a host, CDN or server operator.
  • Keep private keys and account credentials out of an enquiry.

A missing email is not the renewal diagnosis

Let's Encrypt ended expiration reminder emails on 4 June 2025. The announcement did not end automated renewals. If renewal failed, the authorised manager should inspect its existing renewal and validation logs; waiting for a reminder is no longer a reliable operational control.

  • Ask who owns the renewal configuration and alerting.
  • Inspect redacted validation errors and preceding DNS or hosting changes.
  • Do not install a second competing renewal process without understanding the first.

Scope the safe repair

Confirm the named certificate, validation route and server or provider setting that needs repair. Changes to DNS, firewall, web-server configuration or provider accounts require approved access and a reversal plan. A renewal command that succeeds is only part of acceptance if the site still serves the old certificate.

  • Verify the served hostname and chain after the approved change.
  • Check the agreed renewal mechanism and future failure-alert route.
  • Avoid buying a certificate or changing accounts as an unauthorised shortcut.

What success means

The agreed hostname serves a valid certificate without the named warning, and the authorised operator has evidence of the repaired renewal path. That does not prove every security property of the website. Request the repair with hostname and redacted warning; no private key is needed initially.

Sources and limits