US government websites including NASA's and the DOJ's are inaccessible to public after 80+ expired TLS certificates were not renewed due to government shutdown
Over 80 government websites are down after TLS certificates and there's nobody on hand to renew them.
Context & Ripple Effects
The certificate lapses are the visible symptom of a problem reported days earlier: the shutdown gutted the federal cybersecurity workforce itself, with NIST losing 85% of its staff to furloughs and the DNI's analysis and operations side cut by 60%. Certificate renewal is exactly the kind of unglamorous routine maintenance that stops when nobody is at a desk.
It also lands on a web already shown fragile at the protocol layer — back in 2016, over 13M HTTPS sites were exposed to a TLS decryption attack, a reminder that broken or weakened TLS on government domains is not a cosmetic issue but an interception risk.
First-order effects
- NASA, DOJ, and 80+ other agency websites become inaccessible or trigger browser security warnings, cutting the public off from government information and services for as long as the shutdown keeps renewal staff away.
Second-order effects
- Expired certificates mean browsers refuse or flag connections, so visitors who bypass warnings face downgrade and interception exposure on .gov domains — turning a staffing gap into a live attack surface.
- Agencies returning from the shutdown inherit a triage backlog: deciding which of the lapsed certificates get renewed first effectively decides which public services come back first.
Third-order effects
- If every funding lapse repeats this failure mode, expect pressure to automate certificate lifecycle management across .gov or shift it to always-on third-party operators, so basic site availability no longer depends on appropriations.
- The same dependency is now showing up in law as well as infrastructure — the later lapse where CISA 2015 itself expired during a shutdown suggests shutdowns have become recurring stress tests of the entire federal cybersecurity stack, not just its websites.
The trend: Government shutdowns are evolving from budget standoffs into recurring operational failures that expose how much federal cybersecurity rests on continuously staffed routine maintenance.