NET::ERR_CERT_VALIDITY_TOO_LONG appears when an SSL certificate is issued for > 398 days. Since September 2020, Apple, Google and Mozilla reject certs longer than that — per Baseline Requirements 1.7.3. Fix: reissue with validity ≤ 397 days (Let's Encrypt = 90 days, always fits).
This error blocks HTTPS access. Below: causes, fixes, working config, FAQ.
days=10000 — a common admin mistakecertbot renew --force-renewalopenssl req -x509 -days 365 (not 3650!)server {
listen 443 ssl http2;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
ssl_prefer_server_ciphers off;
ssl_stapling on;
ssl_stapling_verify on;
}SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freeShorter certs force more frequent reissuance → lower key-compromise risk and faster retirement of vulnerable certs.
That is 13 months + renewal buffer. Apple introduced the cap in 2020: max 398 days. Google and Mozilla followed.
No. This is a built-in safetynet policy, not toggleable.
ZeroSSL, Buypass — free alternatives with 90-day certs. Commercial (DigiCert, Sectigo) — 1 year. All ≤ 398 days.