# SSL Certificate Support and HTTPS Fixes

Source: https://dijitulsupport.co.uk/ssl-certificate-support/
Updated: 2026-10-10

> dijitul support fixes SSL certificate problems on UK websites: expired or missing certificates, "Not secure" warnings, mixed content, redirect loops and certificates that do not cover the www version. We install or renew the certificate, force HTTPS correctly and fix insecure links. One-off SSL fixes are £45 an hour + VAT.

## Common symptoms

- Chrome shows "Not secure" next to your web address
- "Your connection is not private" with NET::ERR_CERT_DATE_INVALID
- ERR_CERT_COMMON_NAME_INVALID when visiting the www or non-www version
- The padlock is missing on some pages but not others
- ERR_TOO_MANY_REDIRECTS after switching on HTTPS
- Your contact form or payment page throws a security warning

## Key facts

- Free Let's Encrypt and AutoSSL certificates are fine for almost every small business site
- Certificates issued from 15 March 2026 can be valid for a maximum of 200 days under CA/Browser Forum Ballot SC-081
- That maximum falls to 100 days in March 2027 and 47 days in March 2029, so automatic renewal matters
- Mixed content (http images or scripts on an https page) removes the padlock or breaks features
- Cloudflare "Flexible" SSL is a common cause of ERR_TOO_MANY_REDIRECTS
- One-off SSL fixes £45 an hour + VAT; certificate monitoring is part of our plans

## What the error is telling you

Browser SSL errors look alarming, but each one points to a specific fault:

| What visitors see | Usual cause |

| NET::ERR_CERT_DATE_INVALID | The certificate has expired, often because automatic renewal failed |
| ERR_CERT_COMMON_NAME_INVALID | The certificate does not cover that hostname, often www or a subdomain |
| ERR_TOO_MANY_REDIRECTS | Two systems redirecting in a loop, typically Cloudflare Flexible SSL plus a server redirect to HTTPS |
| "Not secure" with no error page | The site is served over plain http, or the page loads insecure content |
| Padlock missing on some pages | Mixed content: images, scripts or fonts still loaded over http |

## Why certificates keep expiring

Most hosts now issue free certificates through Let's Encrypt or cPanel AutoSSL, which renew automatically. Renewal fails when the domain validation check cannot reach the server. That happens when DNS points somewhere else (for example through Cloudflare or after a migration), when an *.htaccess* rule blocks the */.well-known/acme-challenge/* folder, or when a CAA DNS record does not allow the certificate authority to issue.

This is going to matter more. Under CA/Browser Forum Ballot SC-081, certificates issued from 15 March 2026 can last no longer than 200 days, falling to 100 days from March 2027 and 47 days from March 2029. Anyone still renewing certificates by hand once a year will have to switch to automated renewal, and any site where automation is quietly broken will expire more often.

## Fixing mixed content

Mixed content is the most common reason a site with a valid certificate still loses its padlock. It happens when a page served over https loads something over http, usually images inserted into posts before the site moved to https, hard-coded URLs in the theme, or old embed codes. Browsers now upgrade or block much of it, which can break sliders, fonts or forms.

We fix it properly by updating URLs in the database (with a serialisation-safe search and replace), correcting theme and plugin settings, and updating the WordPress Site Address and Home URL. We avoid relying on a plugin that rewrites pages on the fly, since it hides the problem and adds load. We then add an *upgrade-insecure-requests* policy and HSTS where appropriate.

## Getting HTTPS redirects right

Every version of your address (http and https, with and without www) should end up at one canonical https address in a single 301 redirect. Chains of two or three redirects slow the first visit and dilute signals to Google. We set this at server level or in Cloudflare with "Full (strict)" SSL mode so traffic is encrypted all the way to the server, and check that your sitemap, canonical tags and Google Search Console property all use the same address.

Only once everything works on HTTPS do we switch on HSTS, which tells browsers to refuse plain http for your domain. Turning it on too early, or with the preload flag before every subdomain supports HTTPS, can lock visitors out of parts of your site, so we roll it out in stages.

## Paid certificates, wildcards and email

For almost every small business website a free, automatically renewing certificate is the right choice; a paid certificate does not make the connection more secure. A wildcard certificate can help if you run many subdomains, and some organisations want organisation-validated certificates for policy reasons. We can install any of these. We also check certificates on other services that use your domain, such as webmail or a client portal, since an expired certificate there causes the same warnings. For broader security, see website security.

## Cost

Fixing an expired certificate or redirect loop usually takes well under an hour; clearing widespread mixed content can take longer. We charge **£45 an hour + VAT**, 30-minute minimum then 15-minute blocks. On our monthly plans from £25 a month + VAT, uptime and security monitoring help catch certificate problems early. Get in touch if your site is showing a warning now.

## FAQs

### Why does my website say "Not secure"?

Either the site is loading over plain http without a certificate, the certificate has expired or does not match the address, or the page includes mixed content loaded over http. dijitul support identifies which, installs or renews the certificate and fixes the insecure links, at £45 an hour + VAT.

### Do I need to pay for an SSL certificate?

Usually not. Free Let's Encrypt or AutoSSL certificates give the same encryption as paid ones and renew automatically. Paid certificates make sense for specific needs, such as organisation validation or wildcard cover on some hosts, but not for most small business websites.

### How long do SSL certificates last now?

Under CA/Browser Forum Ballot SC-081, certificates issued from 15 March 2026 can be valid for up to 200 days. That falls to 100 days from 15 March 2027 and 47 days from 15 March 2029, which makes reliable automatic renewal essential.

### What is mixed content?

Mixed content is when a secure https page loads images, scripts, fonts or iframes over insecure http. Browsers remove the padlock or block those items, which can break parts of the page. The fix is to update the old http links in the database, theme and plugins.

### Why do I get too many redirects after turning on HTTPS?

Usually two systems disagree. A common case is Cloudflare set to Flexible SSL, which talks to your server over http, while the server redirects http to https, creating a loop. Switching Cloudflare to Full (strict) with a valid certificate on the server fixes it.

## Pricing and contact

Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Plans: Essential £25/month + VAT (Website software updates (core, plugins, themes) applied and checked, Daily backups, Uptime monitoring, Security monitoring); Business £50/month + VAT (Everything in Essential, 1 hour of fixes or changes every month, Priority support); Complete £99/month + VAT (Everything in Business, 3 hours of fixes or changes every month, IT and Microsoft 365 helpdesk for your team). Ad-hoc support is £45 an hour + VAT. The first 30 minutes are the minimum charge, then we bill in 15-minute blocks. Contact: 01623 650333, support@dijitul.uk, https://dijitulsupport.co.uk/contact/
