certificate problem
Validity longer than 398 days
What's going on
Public TLS certificates issued for more than 398 days are rejected by Apple, Google and Mozilla platforms. A certificate with multi-year validity is either internal-only or will fail in browsers.
How to fix it
For anything a browser touches, issue certificates for ≤ 398 days (with automation, 90 days is the norm). Long-lived certificates remain fine for internal, non-browser systems that trust them explicitly.
New to certificates? Start with the guide: How to read an SSL certificate.
Check your certificate for this problem
The decoder detects it automatically — locally, with nothing uploaded.
Open the certificate decoder →