Expired Certificate


Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: justsaddles.co.nz mail.justsaddles.co.nz
Certificate ID: justsaddles_co_nz_c20c8_31689_1514755798_cae5a13d854de7e9b57e7f2a6679a122

Issuer: Let’s Encrypt
Key Size: 2,048 bits (c20c8f2d …)
Expiration: Dec 31, 2017 9:29:59 PM (More information

I ran this command:

It produced this output: ErrorThis certificate is expired.

My web server is (include version):

The operating system my web server runs on is (include version): ?

My hosting provider, if applicable, is: OnlyDomains

I can login to a root shell on my machine (yes or no, or I don’t know): I don’t know

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):


Did you have a question? You’ve issued two more certs since the one you identify (see https://crt.sh/?q=%justsaddles.co.nz), and are about due to renew again.


What software is telling you this?

According to ssllabs.com your certificate is current and valid:

Subject:	www.justsaddles.co.nz 
Fingerprint SHA256: cf4c48ef42bf1f19f77b2f847de5b1fabe623eff99d13d3915f3556c7d43f662
Pin SHA256: Ht1krTTBIj0G7a1X8Yjl3lU9/9q36/szBCv+YTDHyWo=
Common names:	www.justsaddles.co.nz
Alternative names:	justsaddles.co.nz www.justsaddles.co.nz
Serial Number:	03ad90e2793a8716d61be6964aeafeabd885
Valid from:	Tue, 13 Feb 2018 20:30:56 UTC
Valid until:	Mon, 14 May 2018 20:30:56 UTC (expires in 1 month)
Key:	RSA 2048 bits (e 65537)
Weak key (Debian):	No
Issuer:	Let's Encrypt Authority X3 
AIA: http://cert.int-x3.letsencrypt.org/



Thanks for your email and yes please, I don’t seem to be getting the issued Certs. How do I access them? Can you advise where these Certs have been sent? I’m pretty new to all this and took over this domain in Sep 2018. I also have the below messages in gmail as the emails are redirected to my gmail account.

Mail fetch history for “info@justsaddles.co.nz”
Fri, Jan 5, 2018 at 12:08 AM
SSL Security Error. [ Help ]
Server returned error “SSL error: certificate has expired”
Thu, Jan 4, 2018 at 1:48 PM
SSL Security Error. [ Help ]
Server returned error “SSL error: certificate has expired”
Thu, Jan 4, 2018 at 10:41 AM
SSL Security Error. [ Help ]
Server returned error “SSL error: certificate has expired”
Thu, Jan 4, 2018 at 4:25 AM
SSL Security Error. [ Help ]
Server returned error “SSL error: certificate has expired”
Thu, Jan 4, 2018 at 12:13 AM
SSL Security Error. [ Help ]
Server returned error “SSL error: certificate has expired”

Any assistance or guidance would be very much appreciated as I am not an Info tech expert by any means :confused:


Basically, your cPanel server has an expired SSL certificate installed for your mail.justsaddles.co.nz domain.

This is separate to your website’s main certificate, which is why you don’t get the problem when you access the website in your browser.

Since we do not know how the certificate was setup initially, it’s hard to tell you what you need to do. If your host has some kind of Let’s Encrypt/free SSL integration, then you need to use that.

Otherwise maybe try find out from whoever setup the certificate in the first place how they did it.


Hi there,

many thanks for your reply. I truly appreciate it. I will attempt to get this resolved and to backtrack with the previous domain and website owners/holders who set this all up. It was transferred over to me in Sep 2017, obviously with info not included and of course, if you don’t know what is meant to be there, you don’t know what isn’t there :thinking:


It might help to beak down a little bit of what’s happened so far. A cert was issued on 2 Oct 17 (expiring 31 Dec 17) covering justsaddles.co.nz and mail.justsaddles.nz. More recent certs were issued on 15 Dec 17 (expiring 15 Mar 18), 13 Feb 18 (expiring 14 May 18), and today, 14 Apr 18 (expiring 13 Jul 18), but all of the certs after 2 Oct 17 cover justsaddles.co.nz and www.justsaddles.co.nz. The newer certs don’t cover mail.justsaddles.co.nz.

So, going from the known facts to some reasonable speculation–the cert that was issued in October wasn’t done with any sort of auto-renewal. A cert was issued for the mail server as a one-shot deal. In mid-December, a separate cert was issued for the web server, and that was done with some form of auto-renewal (as evidenced by the fact that it’s been consistently renewed after 60 days). I’d speculate that the certs are unrelated, and may even be used on different servers.


:thinking: Hmm, interesting, but thanks for that… The support period from previous owners finished in Nov 2017…also, how do I locate the private Key? I’m trying to sort the SSL with OnlyDomains but it is somewhat frustrating. Message states… The private key may already be on your server. You can either paste the private key here or try to retrieve the matching key for your certificate.


Login to cPanel -> SSL/TLS -> Private Keys.


:cake::bouquet: thank you kindly for your assistance. Still working on it as it seems the keys are invalid, :anguished: so contacting only domains again to try and sort the issue.