Sound familiar?
- Chrome shows "Not secure" next to your web address
- "Your connection is not private" with NET::ERR_CERT_DATE_INVALID
- ERR_CERT_COMMON_NAME_INVALID when visiting the www or non-www version
- The padlock is missing on some pages but not others
- ERR_TOO_MANY_REDIRECTS after switching on HTTPS
- Your contact form or payment page throws a security warning
Key facts
- Free Let's Encrypt and AutoSSL certificates are fine for almost every small business site
- Certificates issued from 15 March 2026 can be valid for a maximum of 200 days under CA/Browser Forum Ballot SC-081
- That maximum falls to 100 days in March 2027 and 47 days in March 2029, so automatic renewal matters
- Mixed content (http images or scripts on an https page) removes the padlock or breaks features
- Cloudflare "Flexible" SSL is a common cause of ERR_TOO_MANY_REDIRECTS
- One-off SSL fixes £45 an hour + VAT; certificate monitoring is part of our plans
What the error is telling you
Browser SSL errors look alarming, but each one points to a specific fault:
| What visitors see | Usual cause |
|---|---|
| NET::ERR_CERT_DATE_INVALID | The certificate has expired, often because automatic renewal failed |
| ERR_CERT_COMMON_NAME_INVALID | The certificate does not cover that hostname, often www or a subdomain |
| ERR_TOO_MANY_REDIRECTS | Two systems redirecting in a loop, typically Cloudflare Flexible SSL plus a server redirect to HTTPS |
| "Not secure" with no error page | The site is served over plain http, or the page loads insecure content |
| Padlock missing on some pages | Mixed content: images, scripts or fonts still loaded over http |
Why certificates keep expiring
Most hosts now issue free certificates through Let's Encrypt or cPanel AutoSSL, which renew automatically. Renewal fails when the domain validation check cannot reach the server. That happens when DNS points somewhere else (for example through Cloudflare or after a migration), when an .htaccess rule blocks the /.well-known/acme-challenge/ folder, or when a CAA DNS record does not allow the certificate authority to issue.
This is going to matter more. Under CA/Browser Forum Ballot SC-081, certificates issued from 15 March 2026 can last no longer than 200 days, falling to 100 days from March 2027 and 47 days from March 2029. Anyone still renewing certificates by hand once a year will have to switch to automated renewal, and any site where automation is quietly broken will expire more often.
Fixing mixed content
Mixed content is the most common reason a site with a valid certificate still loses its padlock. It happens when a page served over https loads something over http, usually images inserted into posts before the site moved to https, hard-coded URLs in the theme, or old embed codes. Browsers now upgrade or block much of it, which can break sliders, fonts or forms.
We fix it properly by updating URLs in the database (with a serialisation-safe search and replace), correcting theme and plugin settings, and updating the WordPress Site Address and Home URL. We avoid relying on a plugin that rewrites pages on the fly, since it hides the problem and adds load. We then add an upgrade-insecure-requests policy and HSTS where appropriate.
Getting HTTPS redirects right
Every version of your address (http and https, with and without www) should end up at one canonical https address in a single 301 redirect. Chains of two or three redirects slow the first visit and dilute signals to Google. We set this at server level or in Cloudflare with "Full (strict)" SSL mode so traffic is encrypted all the way to the server, and check that your sitemap, canonical tags and Google Search Console property all use the same address.
Only once everything works on HTTPS do we switch on HSTS, which tells browsers to refuse plain http for your domain. Turning it on too early, or with the preload flag before every subdomain supports HTTPS, can lock visitors out of parts of your site, so we roll it out in stages.
Paid certificates, wildcards and email
For almost every small business website a free, automatically renewing certificate is the right choice; a paid certificate does not make the connection more secure. A wildcard certificate can help if you run many subdomains, and some organisations want organisation-validated certificates for policy reasons. We can install any of these. We also check certificates on other services that use your domain, such as webmail or a client portal, since an expired certificate there causes the same warnings. For broader security, see website security.
Cost
Fixing an expired certificate or redirect loop usually takes well under an hour; clearing widespread mixed content can take longer. We charge £45 an hour + VAT, 30-minute minimum then 15-minute blocks. On our monthly plans from £25 a month + VAT, uptime and security monitoring help catch certificate problems early. Get in touch if your site is showing a warning now.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
Why does my website say "Not secure"?
Either the site is loading over plain http without a certificate, the certificate has expired or does not match the address, or the page includes mixed content loaded over http. dijitul support identifies which, installs or renews the certificate and fixes the insecure links, at £45 an hour + VAT.
Do I need to pay for an SSL certificate?
Usually not. Free Let's Encrypt or AutoSSL certificates give the same encryption as paid ones and renew automatically. Paid certificates make sense for specific needs, such as organisation validation or wildcard cover on some hosts, but not for most small business websites.
How long do SSL certificates last now?
Under CA/Browser Forum Ballot SC-081, certificates issued from 15 March 2026 can be valid for up to 200 days. That falls to 100 days from 15 March 2027 and 47 days from 15 March 2029, which makes reliable automatic renewal essential.
What is mixed content?
Mixed content is when a secure https page loads images, scripts, fonts or iframes over insecure http. Browsers remove the padlock or block those items, which can break parts of the page. The fix is to update the old http links in the database, theme and plugins.
Why do I get too many redirects after turning on HTTPS?
Usually two systems disagree. A common case is Cloudflare set to Flexible SSL, which talks to your server over http, while the server redirects http to https, creating a loop. Switching Cloudflare to Full (strict) with a valid certificate on the server fixes it.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.