• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
OpenTechTips

OpenTechTips

Comprehensive IT Guides for Pros and Enthusiasts

MENUMENU
  • HOME
  • ALL TOPICS
    • Exchange
    • InfoSec
    • Linux
    • Networking
    • Scripting
      • PowerShell
    • SSL
    • Tools
    • Virtualization
    • Web
    • Windows
  • ABOUT
  • SUBSCRIBE
Home » Is it safe to visit a webpage with an expired SSL certificate?

Is it safe to visit a webpage with an expired SSL certificate?

May 16, 2020 - by Zsolt Agoston - last edited on May 20, 2020

Does expired mean it is not working anymore?

Is it safe to visit a webpage with an expired SSL certificate?

When an SSL certificate is signed, it gets an expiry date. It doesn't matter if it is "self-signed" - meaning that a not trusted server signed it (for instance the webserver itself) - or if a public CA (Certificate Authority) vouches for the authenticity of the keys, the certificate is valid for a predefined period of time. Does it mean that when that date is passed and the certificate is not renewed, the website (or other service the certificate was protecting) stops working? Or more precisely, does encryption stops to work? The answer is simple: no. Encryption still works, the certificate itself does not lose any of it's functionality because it is expired. But does the service (web server, etc) stop working when an expired certificate is used? It solely depends on the program that is using the certificate. It might decide to stop working, but again, not because the certificate itself is not functional.

But why different lifespans?

SSL certificates can have different lifespans, as little as a few days, or as long as many years. Simply put, a certificate can be cracked, it is just the matter of time. Attackers can guess or brute force the private key - which is a very long, 309 digits prime number, that can take decades or longer to figure out, but eventually it will be cracked. That's why certificates are changed every so often. If an attacker figures out the private key, they can decrypt the communication in between the server and any clients. Now how do I decide what validity period I need? It depends on security needs and your wallet. Public CAs offer certificates that are valid for 1, 2 and 3 years. The longer their lifespan is, the more expensive they are. It is very unlikely that a private key is cracked within any of these time periods. A 3-year SSL is more expensive simply because the CA charges you for the convenience of not be bothered with SSL expiry dates for a longer time. Also, it is cheaper to pay a little higher price once, than to pay for SSL renewals every year.

Is a 3-year SSL more secure than one which is valid for only 1 year?

No. They all use that same key lengths (256bit usually) and algorithms (RSA or more likely elliptic-curve DH)

So, Safe or Not?

Yes and no. Yes, because an expired certificate provides just as a strong encryption than before expiry. At this point let's talk about the reason why SSL certificates are signed. An SSL certificate does not only provide encryption, but it proves that you are visiting the authentic website,  as the public CA only signs a certificate if the owner is verified. This way you can make sure your data that you share with the visited server (credit card details during payments or other personal information) is in safe hands. The reason why using a publicly verified SSL certificate is important is that any website can be spoofed. Your network traffic can be redirected to a rogue web server that acts as the original, but is owned by malicious parties. This is where a valid SSL protects you. The rogue website will not have the private key of the original certificate, as that is solely owned by the original webserver. So, they only can use a "forged" one instead that will trigger a security warning in your web browser. However, if that warning only appears because of the certificate is expired, not because it is from an untrusted CA, you might safely use the website, despite of the warning.

Always check what triggered the warning!

Reader Interactions

Comments Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Tools

Secondary Sidebar

CONTENTS

  • Does expired mean it is not working anymore?
  • But why different lifespans?
  • Is a 3-year SSL more secure than one which is valid for only 1 year?
  • So, Safe or Not?

  • Terms of Use
  • Disclaimer
  • Privacy Policy
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}