Why the expiry date is the whole product
An expired certificate does not degrade. It stops.
There is no grace period. The moment the term ends, browsers stop trusting the file
and show a full page warning that a visitor has to deliberately click through. Most
people do not click through. They read it as a warning about you, back out, and take
the next result in the list. A "not secure" label costs you some visitors. An expired
certificate costs you nearly all of them.
It also fails everywhere at once, which is why the phone starts ringing.
- Every page shows the warning, including whichever one your advertising is
pointing at.
- Forms stop submitting. Booking and payment tools loaded from another company
refuse to run on a page the browser does not trust.
- Anything talking to the site without a person watching, a supplier's system, an
app, a feed, simply fails, and fails quietly.
- If the same name covers your mail, mail programs start showing their own
warnings. That reaches you as "our email is broken", not as a certificate
problem.
It expires at the worst time by arithmetic, not bad luck
A certificate's term runs from the day it was issued, and the day it was issued is
usually the day the site launched or the day of a rebuild. So the expiry date is the
anniversary of a busy week, not of a quiet one. That is why so many of them lapse
during a sale, a season or an event, and why it never feels like coincidence.
The other half of it is that nothing is watching. A site does not announce that it
has gone untrusted. A customer does, usually the next morning.
Nothing is damaged by an expiry. No data is lost. The site is simply
unusable until a valid certificate is installed, which makes it a strange kind of
outage: completely preventable, and completely invisible until it happens. If you are
in one now, work through the first
hour when your site goes down.