Secure connection and certificate errors
Firefox: Warning: Potential Security Risk Ahead
Firefox could not confirm the website's certificate.
Quick answer
Firefox checks each site's certificate, its digital ID. This warning means the check failed: the certificate may be expired, for another name or from an unknown issuer. The error code under Advanced tells you which. Usually the website must fix it.
When to wait: Waiting does not help; the certificate must be fixed.
If you are visiting the website
- Go back Choose the "Go Back" button on the warning page. It is the safe choice while you find the cause.
- Read the error code Click Advanced to see the code. SEC_ERROR_EXPIRED_CERTIFICATE points to dates. SEC_ERROR_UNKNOWN_ISSUER points to an untrusted issuer. SSL_ERROR_BAD_CERT_DOMAIN means a wrong name. MOZILLA_PKIX_ERROR_MITM_DETECTED means something on your side is intercepting the connection.
- Check your device's date and time Expired-certificate codes on many sites usually mean your clock is wrong. Turn on automatic time and reload.
- Windows
- Start > Settings > Time & language > Date & time. Turn on "Set time automatically".
- macOS
- Apple menu > System Settings > General > Date & Time. Turn on "Set time and date automatically".
- Linux
- Run
timedatectl status. If "System clock synchronized" says no, runsudo timedatectl set-ntp trueon systemd-based systems. - Android
- Settings > System > Date & time. Turn on "Set time automatically".
- Check antivirus HTTPS scanning Mozilla names SSL scanning in security software as a common cause, especially for MOZILLA_PKIX_ERROR_MITM_DETECTED. Pause that feature for one reload, then turn it back on and update the program.
- Try another network Company networks and public Wi-Fi login pages can present their own certificates. Test on mobile data or after signing in to the Wi-Fi.
- Tell the website owner If the warning appears on every device and network, the site's certificate is at fault. Send the owner the code from the Advanced section.
If you run the website
- Match the fix to the code Expired: renew with
sudo certbot renewand reload. Unknown issuer: serve the full chain or use a public authority. Bad domain: add the missing hostname to the certificate. - Check what Firefox receives Run
openssl s_client -connect example.com:443 -servername example.com -showcertsand pipe your certificate intoopenssl x509 -noout -dates -subject -issuer. Check dates, names and that intermediates are sent. - Serve the full chain In nginx the ssl_certificate file must hold your certificate first, then the intermediates. With Certbot use fullchain.pem.
- Test renewal Run
sudo certbot renew --dry-runand make sure the web server reloads after each renewal.
Is it the website or me?
If many sites show this warning at once, look at your device first: the clock, antivirus HTTPS scanning or a company network.
If only one site shows it, everywhere, the site's certificate is the problem.
What this warning is not
It does not mean your computer has a virus. It means Firefox could not confirm the identity of the site.
It is also different from "Secure Connection Failed", where the secure connection could not be set up at all.
Why Firefox can behave differently from Chrome
Firefox shows its own codes and has its own security checks. A site can therefore pass in one browser and fail in another.
Always fix the cause the code names rather than switching browsers to avoid the warning.
Common questions
Is it safe to click past the warning?
Not for any site with logins, payments or personal data. Firefox cannot confirm who you are talking to. Only consider it for your own test device on your own network.
What does MOZILLA_PKIX_ERROR_MITM_DETECTED mean?
Mozilla describes it as a special case of an unknown issuer, where something between you and the site is intercepting the connection. Security software that scans HTTPS is a common reason.
Why do I see this warning on every website?
Then the cause is on your side. Check the clock first, then security software and any company network or proxy.
Will clearing cookies make the warning go away?
No. The warning comes from the certificate check, not from cookies.
Likely causes
- Common The website's certificate is expired or misconfigured. (Website side)
- Sometimes Your clock is wrong. (Your side)
- Sometimes Antivirus or a company network intercepts HTTPS. (Your side)
What to avoid
- Do not accept the risk to enter passwords or payment details.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Mozilla Support: Secure connection and security warning error pages in Firefox
- Mozilla Support: What do the security warning codes mean?
- OpenSSL: s_client manual
- Certbot documentation: User Guide
- Linux man page: timedatectl(1)
- OpenSSL: x509 manual
Last reviewed: