Secure connection and certificate errors
NET::ERR_CERT_AUTHORITY_INVALID
The certificate was issued by someone the browser does not trust.
Quick answer
Browsers only trust certificates from known certificate authorities. This one is self-signed, missing part of its chain, or replaced by a network or security tool that inspects traffic.
When to wait: Waiting does not help.
If you are visiting the website
- Check if many sites show it Open two or three big HTTPS sites. If they all show this error, something on your device or network is replacing certificates. If only one site fails, the problem is most likely that website.
- Switch to a different network Company, school and some public networks inspect encrypted traffic with their own certificates. Leave that network for a moment and test again.
- Windows
- Start > Settings > Network & internet > Wi-Fi. Turn Wi-Fi off and connect through a phone hotspot, or join a different network.
- macOS
- Click the Wi-Fi icon in the menu bar and choose a different network, or a phone hotspot.
- Android
- Settings > Network & internet > Internet. Turn Wi-Fi off so the phone uses mobile data, then reload.
- iPhone and iPad (iOS)
- Settings > Wi-Fi. Turn Wi-Fi off so the iPhone uses mobile data, then reload.
- Sign in to the Wi-Fi portal Public Wi-Fi often redirects you to its own login page, which cannot present a certificate for the site you asked for. Open a plain http:// address, finish the sign-in, then retry.
- Test HTTPS scanning in your antivirus Antivirus tools with HTTPS scanning or SSL scanning issue their own certificates. If that tool is broken or outdated, browsers reject them. Pause the feature for one reload, then switch it back on and update the program.
- On a work or school device, ask IT Managed devices often need a company certificate installed by IT. If this error appears on such a device, your IT team should fix it. Do not install certificates or profiles from anyone else.
- Tell the website owner If the error appears on every network and device, the site's certificate chain is broken or self-signed. Contact the site through another channel and mention the exact error code.
If you run the website
- Show the chain your server sends Run
openssl s_client -connect example.com:443 -servername example.com -showcerts. It lists every certificate the server sends, in order. If you only see your own certificate, the intermediates are missing. - Install the full chain Put your certificate first and the intermediate certificates after it in the file used by ssl_certificate in nginx. With Certbot, point to fullchain.pem, not cert.pem. Test with
sudo nginx -t, then reload. - Replace self-signed or internal certificates Self-signed certificates and certificates from a private company authority are not trusted by public browsers. Use a certificate from a publicly trusted authority; Let's Encrypt issues them free of charge.
- Check Cloudflare Origin CA use A Cloudflare Origin CA certificate is only trusted by Cloudflare. If you pause Cloudflare or set a record to DNS-only, visitors connect to your server directly and see this error. Keep the record proxied, or use a public certificate on the origin.
- Retest from outside After changes, test from a network outside your company. Your own machine may trust an internal authority that visitors do not have.
Is it the website or me?
One site failing everywhere points to the website. Its chain is incomplete or the certificate is self-signed.
Every site failing on one network or device points to interception. A company filter, antivirus HTTPS scanning or a Wi-Fi login page is presenting its own certificate.
How it differs from ERR_CERT_COMMON_NAME_INVALID
With a name error, a trusted authority issued the certificate, but for a different site name. With an authority error, the browser cannot connect the certificate to any authority it trusts.
Both stop the page for the same reason: the browser cannot prove who it is talking to.
For developers: why the chain matters
Browsers ship with a list of trusted root certificates. Your certificate is signed by an intermediate, which is signed by a root.
If the server leaves out the intermediate, some browsers can fill the gap and others cannot. That is why a missing chain can work on your laptop but fail on a visitor's phone.
Common questions
Is it safe to continue past the warning?
No, not on a site where you log in, pay or enter personal details. This error is exactly what an attacker in the middle of your connection would cause. Go back unless it is your own test server.
Should I install the certificate the website offers so the warning goes away?
No. Installing a certificate tells your device to trust everything signed by it. Only install certificates that your own IT team gives you through official channels.
Why does it work on my laptop but not on my phone?
Often the server is missing an intermediate certificate. Some browsers remember or fetch missing pieces, others do not. The site owner needs to serve the full chain.
What does SEC_ERROR_UNKNOWN_ISSUER mean in Firefox?
It is Firefox's name for the same problem: the issuer of the certificate is not known or trusted. Mozilla lists missing intermediate certificates and security software that scans HTTPS as common reasons.
Likely causes
- Common The server is missing the intermediate certificate (incomplete chain). (Website side)
- Sometimes The certificate is self-signed. (Website side)
- Sometimes Antivirus, a company network or public Wi-Fi intercepts HTTPS. (Your side)
What to avoid
- Do not bypass the warning to enter passwords or payment details.
- Do not install certificates someone sends you to make the warning go away.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Chromium source: net/base/net_error_list.h
- Google Chrome Help: Get help with common error messages in Chrome
- Mozilla Support: What do the security warning codes mean?
- OpenSSL: s_client manual
- nginx: Module ngx_http_ssl_module
- Cloudflare Docs: Origin CA certificates
- Let's Encrypt: Getting Started
Last reviewed: