Secure connection and certificate errors
Your connection is not private: causes and safe next steps
Chrome stopped before connecting because the website could not prove who it is.
Quick answer
This is the warning Chrome shows when the certificate of a website, its digital ID card, fails a check. Chrome stops before it sends anything private, such as passwords or form entries, to the site. This page explains the Chrome warning and when continuing is never acceptable; our page "Secure connection or certificate error" covers the same family of problems in every browser and in our own check.
When to wait: An expired certificate stays broken until the owner renews it. A warning caused by a Wi-Fi sign-in page goes away once you sign in.
If you are visiting the website
- Check the address and read the code Make sure the address is spelled exactly right, because look-alike names are a classic trick. Then read the code under the warning: DATE_INVALID points to a clock or an expired certificate, AUTHORITY_INVALID to an issuer Chrome does not trust, COMMON_NAME_INVALID to a name mismatch.
- Let your device set the clock automatically A certificate is valid only between two dates. A clock that is days or years off makes a valid certificate look expired, and Chrome then often says "Your clock is behind" or "Your clock is ahead". Correct the clock, then reload.
Windows
Select Start > Settings > Time & language > Date & time and switch on Set time automatically and Set time zone automatically.
macOS
In System Settings, open General > Date & Time and switch on the option that sets date and time automatically.
Android
In Settings, open System > Date & time and switch on automatic date, time and time zone. Some phone makers name these menus a little differently.
iPhone and iPad (iOS)
In Settings, open General > Date & Time and switch on Set Automatically.
- Sign in to the Wi-Fi, then compare with mobile data Hotel, airport and train networks often hold back secure pages until you accept their terms, and Chrome may then show "Connect to Wi-Fi". Sign in on the network page and reload; if the warning stays, switch to mobile data for one test.
- Pause HTTPS scanning for one test Some security suites open encrypted traffic to inspect it, which can trigger this warning on many sites at once. Pause that feature, reload once, then switch it back on.
- Tell the owner if only this site fails When one site shows the warning on every device and network, the certificate on its server is the problem. Send the owner the code and the time, and come back once it is fixed.
If you run the website
- Read the certificate your server sends Run
openssl s_client -connect example.com:443 -servername example.comand pass the output toopenssl x509 -noout -dates -subject -issuer. You see the validity dates, the name on the certificate and who issued it. - Renew, and test the renewal Let's Encrypt certificates are valid for 90 days by default, and Let's Encrypt recommends renewing them every 60 days.
sudo certbot renew --dry-runtests renewal against the staging server without saving any certificates; reload the web server after each real renewal. - Cover every hostname Every name visitors use, such as example.com and www.example.com, has to appear in the Subject Alternative Name list. A missing name produces NET::ERR_CERT_COMMON_NAME_INVALID.
- Send the intermediate certificates Serve your certificate followed by its intermediates; with Certbot that is the fullchain.pem file. Without them, some devices cannot connect your certificate to a trusted root and report NET::ERR_CERT_AUTHORITY_INVALID.
- Fix certificates before you turn on HSTS With Strict-Transport-Security in place, browsers give visitors no way past any certificate error on your site. Make renewal reliable before you set a long max-age or ask for preloading.
Which code is shown at the bottom?
The code under the warning names the check that failed. Read it before you try a fix.
NET::ERR_CERT_DATE_INVALID: by the clock of your device, the certificate has expired or is not valid yet. Correct the clock first; if the clock is right, only the owner can renew.
NET::ERR_CERT_AUTHORITY_INVALID: the certificate comes from an issuer Chrome does not trust, or part of the chain is missing. Self-made certificates on routers, test servers and inspecting security tools cause it as well.
NET::ERR_CERT_COMMON_NAME_INVALID: the certificate is valid but issued for a different name. A link to the www version of a site, or to the version without www, is a typical trigger.
Rarer codes such as NET::ERR_CERT_REVOKED belong to the same family. ERR_CERT_KNOWN_INTERCEPTION_BLOCKED means Chrome recognised a certificate that is known to be used to intercept traffic by someone other than the owner of the device.
Each code has its own page, listed under Related messages near the end of this page.
When is it safe to continue?
Not on a website that you do not run yourself. Nobody has proven who is on the other end, so the page you would see could be a copy, and anything you type there, such as passwords, payment details or messages, could reach the wrong party. The warning is doing its job: go back, try later or contact the owner.
The narrow exception is a device or test site you run yourself, such as the setup page of your own router with a self-made certificate, when you know why it is not trusted. Even then, compare the address with the one you expect, character by character.
Some sites offer no way to continue at all. They use HSTS, a rule that tells browsers to accept only valid secure connections, and Chrome then notes that network errors and attacks are usually temporary.
Common questions
Does this warning mean my computer has a virus?
No. It means Chrome could not verify the certificate of one site. It says nothing about infection, but you should not enter personal data on that page.
Why do I suddenly see it on every website?
Then the cause is on your side: a wrong clock, security software that inspects secure traffic, or a network that intercepts connections, such as a Wi-Fi network that wants you to sign in first. Fix the clock, sign in, or test on another network.
Do Incognito mode or clearing cookies help?
Chrome's help suggests Incognito mode as one thing to try on a computer, because it helps you spot a Chrome extension that causes the warning. A broken certificate on the server stays broken there too, because the certificate is checked on every new connection.
Why is there no way to continue on some sites?
Sites that use HSTS tell Chrome to refuse any certificate error without exception. That protects you; wait or ask the owner to fix the certificate.
Likely causes
- Common The certificate of the site has expired or was not renewed in time. (Website side)
- Sometimes The certificate does not list the exact name you opened, for example the version with www. (Website side)
- Sometimes The date or time on your device is wrong. (Your side)
- Sometimes A Wi-Fi sign-in page or security software sits in the middle of the connection. (Your side)
- Rare Someone on the network pretends to be the website. (Either side)
What to avoid
- Do not continue past the warning on a website you do not run yourself, and never sign in, pay or type personal details there.
- Do not install a certificate or profile that a website or pop-up asks for to make the warning go away.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Chromium source: components/security_interstitials_strings.grdp (texts of Chrome's certificate warning)
- Chromium source: net/base/net_error_list.h (network error codes)
- Google Chrome Help: Get help with common error messages in Chrome
- MDN: Strict-Transport-Security header
- Let's Encrypt: FAQ (certificate lifetime and renewal)
- Certbot documentation: User Guide
- Microsoft Support: How to set your time and time zone
Last updated:
Was this helpful?
We count only yes and no for this page: no IP address, no domain, no text. Privacy