5 Real Outages Caused by an Expired SSL Certificate

spyboy's avatarPosted by

Nobody gets a calendar invite titled “the day our certificate expires and everything breaks.” That’s the problem. Certificates sit quietly in the background for months, and then one morning they’re the reason a service is down.

If you think this only happens to small teams with messy spreadsheets, the five stories below might change your mind. Not every one involved a website certificate, but every one came down to the same thing: a certificate expired and nobody caught it in time. And each could have been avoided if someone had set up a way to automate SSL certificate renewal before the deadline arrived.

1. Microsoft Teams (February 2020)

On a Monday morning, Teams stopped working. People couldn’t sign in, messages didn’t load, and meetings failed. The cause was an authentication certificate Microsoft hadn’t renewed, and the service was down for about three hours.

Three hours doesn’t sound like much until you remember how many people were mid-workday. The fix itself was simple: renew the certificate. The hard part was that nobody noticed until it was already broken.

The lesson: Even a company that size can miss a single renewal. Reminders in someone’s inbox are not a system.

2. O2 and SoftBank (December 2018)

This is the clearest example of what one expired certificate can do. A software certificate inside Ericsson equipment expired, and mobile data stopped working for O2 customers in the UK and SoftBank customers in Japan. Tens of millions of people were affected, and in the UK some were offline for most of a day.

Ericsson acknowledged that the expired certificate was the cause and apologised. O2 later sought compensation for the cost of the outage.

The lesson: Certificates aren’t just a website thing. They sit inside telecom gear, internal tools, APIs and devices, and those are the ones people forget about.

3. Equifax (2017)

Equifax is mostly remembered for the breach itself, but an expired certificate is a big part of why it lasted so long. A certificate on the device that inspected network traffic had expired months earlier, about 10 months before the attack according to the US Government Accountability Office. Nobody noticed, so encrypted traffic, including the attackers’, passed through uninspected.

The intrusion went on for 76 days. When the certificate was finally replaced, the tool spotted the suspicious activity almost immediately. The breach affected more than 140 million people.

The lesson: An expired certificate doesn’t always cause a visible outage. Sometimes it quietly switches off a safeguard, and that can be worse.

4. Starlink (April 2023)

Starlink went down worldwide for several hours. Elon Musk’s explanation on X was short: an expired ground station certificate. It’s a reminder that satellite networks depend on the same boring renewal dates as a personal blog.

The lesson: Technology level doesn’t matter. Renewal dates don’t care how advanced your product is.

5. Cisco SD-WAN (May 2023)

In May 2023, certificates on Cisco vEdge SD-WAN devices expired, and customers found their remote sites affected. Cisco published guidance on how to identify and fix the problem, but many teams had to work through it live.

The lesson: Even vendors can have expiry dates hidden in their own hardware, which is why you need to track every certificate you rely on.

Why this is about to get harder, not easier

Here’s the part that makes this urgent. Since March 15, 2026, publicly trusted SSL/TLS certificates can last at most 200 days, down from 398. The limit drops to 100 days on March 15, 2027, and to 47 days on March 15, 2029.

Do the maths for a normal business. At 47 days, one certificate needs about eight renewals a year. If you manage 50 or 100 certificates, that’s hundreds of renewals annually. Doing that by hand isn’t just annoying, it’s how outages happen.

How SSL automation actually works

SSL automation sounds technical, but the idea is simple. Instead of a person remembering to renew each certificate, software does it for you:

  1. It tracks every certificate you own, including ones nobody remembers buying.
  2. It requests the renewal automatically before expiry, usually through a protocol called ACME.
  3. It validates your domain without manual steps, using DNS or HTTP checks.
  4. It installs the new certificate on your server, load balancer, or CDN.
  5. It alerts you if something fails, so a problem becomes a ticket, not an outage.

You don’t need a huge enterprise setup to start. For a few sites, an ACME client on your server is enough. For many domains, a central certificate management tool is worth it.

A quick checklist to start this week

  • List every certificate you have, with its expiry date and where it’s installed.
  • Find the ones that are renewed by hand today. Those are your risk.
  • Pick an automation method that fits your stack: an ACME client, a hosting panel, or a management platform.
  • Set expiry alerts at 30, 14 and 7 days as a safety net, even after you automate.
  • Test the renewal process before you need it.

Where Certera fits in

If you’re an agency, a reseller or an enterprise team juggling many domains, this is the situation Certera is built for. Their SSL certificates work with automated renewal workflows, so you spend less time chasing expiry dates and more time on the work you actually get paid for.

The bottom line

None of these outages happened because someone didn’t care. They happened because renewal was a manual job in a world with too many certificates and too many dates. With lifespans shrinking every year, SSL automation stops being a nice extra and becomes basic housekeeping.

Set it up once, and the next expiry is just another Tuesday.

FAQs

1. What happens when an SSL certificate expires?
Browsers show a full-page security warning, and most visitors leave instead of clicking through. Behind the scenes, APIs, apps and connected services that rely on the certificate can stop working too. That’s why a missed renewal can look like a full outage.

2. How do I automate SSL certificate renewal?
There are three common ways. You can install an ACME client such as Certbot or acme.sh on your server. You can use your hosting panel’s auto-renew feature. Or you can use a certificate management platform that tracks and renews certificates across many domains. A single site can get by with the first two. Agencies, resellers and enterprises usually need the third, because the number of renewals grows with every domain.

3. What is SSL automation?
SSL automation means software handles the certificate lifecycle for you: tracking expiry dates, requesting renewals, validating your domain, installing the new certificate and alerting you if something fails. Most of it runs on a protocol called ACME.

4. Can I automate renewal for paid SSL certificates?
Yes, as long as the certificate authority supports automated issuance, usually through ACME or an API. Many do.

5. How often will I need to renew my SSL certificate?
More often every year. The maximum validity for publicly trusted certificates is 200 days now. It drops to 100 days on March 15, 2027, and to 47 days on March 15, 2029. Even if you buy a multi-year plan, each individual certificate still has to follow these limits.

6. How do I know if automatic renewal has failed?
Set up monitoring. Use alerts at 30, 14 and 7 days before expiry, and check the expiry date from outside your own server. Automation can fail silently, for example when a DNS record changes, so an alert is your safety net.

7. Will an expired certificate hurt my SEO?
Not directly as a ranking penalty, but the effects add up. Visitors bounce off the warning page, bots can’t crawl the site properly, and downtime loses traffic. Prevention is much easier than recovery.


Discover more from Spyboy blog

Subscribe to get the latest posts sent to your email.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.