Secure connection and certificate errors
Secure connection or certificate error
The browser could not set up a safe, verified HTTPS connection.
Quick answer
HTTPS uses a certificate, a digital ID card that proves the website is who it claims to be. If the certificate is expired, issued for another name or not trusted, or the secure setup fails, the browser stops to protect you. Our check never bypasses this.
When to wait: Waiting does not fix a certificate; the owner has to renew or correct it.
If you are visiting the website
- Check the address first Look closely at the web address. It should be spelled exactly right. Fake sites often change one letter of a real name.
- Check your device's date and time Certificates are only valid between two dates. If your clock is wrong, a valid certificate can look expired or not yet valid. Turn on automatic date and time, then reload the page.
- Windows
- Start > Settings > Time & language > Date & time. Turn on "Set time automatically". If a "Sync now" button is shown, click it.
- macOS
- Apple menu > System Settings > General > Date & Time. Turn on "Set time and date automatically".
- Android
- Settings > System > Date & time. Turn on "Set time automatically" and "Set time zone automatically". Names can differ slightly by phone maker.
- iPhone and iPad (iOS)
- Settings > General > Date & Time. Turn on "Set Automatically".
- Sign in to public Wi-Fi first Hotel, train and café Wi-Fi often shows a login page before you get real internet. Open any plain http:// address to bring up that page, sign in, then try again.
- Try another network Switch from Wi-Fi to mobile data, or the other way round. If the warning disappears, something on the first network (such as a company filter) is changing secure connections.
- Test your security software briefly Antivirus features called HTTPS scanning or SSL scanning open encrypted traffic to look inside, which can trigger certificate warnings. Pause that feature for one test reload, then turn it back on.
- Read the exact error code The warning page shows a code such as NET::ERR_CERT_DATE_INVALID or SEC_ERROR_UNKNOWN_ISSUER. The code tells you which check failed. Open our guide for that exact code for more targeted steps.
If you run the website
- Look at the certificate from outside Run
openssl s_client -connect example.com:443 -servername example.comand pipe the result intoopenssl x509 -noout -dates -subject -issuer. You see the validity dates, the names covered and the issuer. - Renew an expired certificate With Certbot, run
sudo certbot certificatesto list certificates and expiry dates, thensudo certbot renew. Afterwards check your configuration withsudo nginx -tand reload withsudo nginx -s reload, or useapachectl configtestandapachectl gracefulon Apache. - Serve the full chain Browsers need your certificate plus the intermediate certificates (the links between your certificate and a trusted root). In nginx, the file in ssl_certificate must contain your certificate first, then the intermediates. With Certbot this is the fullchain.pem file.
- Cover every name visitors use The certificate must list each hostname, such as example.com and www.example.com, in its Subject Alternative Name list. Add missing names when you renew.
- Automate renewal and test it Run
sudo certbot renew --dry-runto test renewal without changing anything. Check that a renewal timer exists withsystemctl list-timers, and reload the web server after each renewal, for example with--deploy-hook "systemctl reload nginx". - Behind Cloudflare: use Full (strict) Set SSL/TLS encryption mode to Full (strict) and install a valid certificate on the origin (your own server). A free Cloudflare Origin CA certificate works for this, but only while traffic goes through Cloudflare. Browsers do not trust it directly.
Is it the website or me?
If only one site shows the warning on every device and network, the website almost certainly has a certificate problem. You cannot fix that from your side.
If many different sites suddenly show warnings on one device, look at that device. A wrong clock, security software that scans HTTPS or a network that intercepts traffic are the usual reasons.
What this warning is not
It is not a virus on your computer, and it does not mean you have been hacked. It means the browser could not prove that the site is the one it claims to be.
It is also not a website outage. The server answered, but the secure setup failed, so the browser stopped before sending anything private.
For developers: what the browser checks
During the TLS handshake (the opening exchange that sets up encryption) the server sends its certificate chain. The browser checks the dates, checks that the requested hostname is in the certificate, and follows the chain up to a root it trusts.
If any check fails, the browser shows a specific code.
Common questions
Is it safe to continue past the warning?
Not on any site where you log in, pay or share personal details. The warning means nobody has proven who is on the other end, so your password or card number could reach the wrong party. Go back and wait for the owner to fix it.
Why does the site work on my phone but not on my laptop?
Then the site is probably fine and something on the laptop differs. Check the laptop's clock, its security software and whether it uses a company or school network.
Will clearing cookies or cache fix a certificate warning?
Usually not. Certificates come fresh from the server on every connection and are not stored in cookies. Fix the clock or the network instead, or wait for the owner.
Can a VPN fix this?
A VPN only changes the path your traffic takes. If the network you are on intercepts HTTPS, a different path might avoid it, but a broken website certificate stays broken. Do not pay for a VPN to solve a certificate error.
Likely causes
- Common The certificate expired or was not renewed. (Website side)
- Sometimes The certificate does not cover this exact name, for example www. (Website side)
- Sometimes Your device's date and time are wrong. (Your side)
- Sometimes A public Wi-Fi login page or security software intercepts the connection. (Your side)
What to avoid
- Do not bypass the warning to enter passwords or payment details.
- Do not install unknown certificates or profiles to make the warning disappear.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- MDN: Transport Layer Security (TLS)
- Google Chrome Help: Get help with common error messages in Chrome
- Let's Encrypt: Getting Started
- Certbot documentation: User Guide
- nginx: Module ngx_http_ssl_module
- OpenSSL: s_client manual
- Cloudflare Docs: Full (strict) encryption mode
- Microsoft Support: How to set your time and time zone
- OpenSSL: x509 manual
Last reviewed: