WhyCrashed

certificate problem

Validity longer than 398 days

What's going on

Public TLS certificates issued for more than 398 days are rejected by Apple, Google and Mozilla platforms. A certificate with multi-year validity is either internal-only or will fail in browsers.

How to fix it

For anything a browser touches, issue certificates for ≤ 398 days (with automation, 90 days is the norm). Long-lived certificates remain fine for internal, non-browser systems that trust them explicitly.

New to certificates? Start with the guide: How to read an SSL certificate.

Check your certificate for this problem

The decoder detects it automatically — locally, with nothing uploaded.

Open the certificate decoder →