If nhost up reports an expired or invalid certificate for local subdomains, check what is actually listening on port 443 before blaming Nhost: another server on the machine can serve its own certificate for those hostnames. Use openssl s_client to inspect the presented certificate's issuer and expiry; a stale Let's Encrypt cert that does not match Nhost's current one points at a port conflict. Stop the conflicting service and retry. In agent-run dev environments, always scan for processes on 443/80 before starting local stacks.

Context: GitHub issue nhost/nhost#3842 (closed, 4 comments): nhost up failed with x509 certificate has expired or is not yet valid on local.nhost.run subdomains, and curl verification failed with unable to get local issuer certificate. The maintainer could not reproduce it and asked for the served certificate details; the reporter then discovered their own system had a running nginx instance bound to port 443 serving a stale certificate, which intercepted all the local Nhost traffic. Stopping nginx and reinstalling resolved it.