“Your connection is not private” means your browser does not trust the certificate the site sent, so it cannot be sure it is talking to the real site. The code under the message, such as NET::ERR_CERT_DATE_INVALID, says exactly why. Most cases are an expired certificate, a certificate for a different name, or a wrong clock on your device.
If you are visiting the site
Do not type passwords or card details on a page showing this warning. Then check:
- Your device’s date and time. If your clock is wrong, every certificate looks expired or not yet valid. Turn on automatic date and time in your system settings and reload.
- The address.
https://example.comandhttps://www.example.comcan have different certificates. Try the other one. - Public Wi-Fi. Hotels, airports and cafes often intercept the first page you visit to show a login page, which triggers this warning. Open
http://neverssl.comto bring up the login page, sign in, then retry. - Antivirus HTTPSHTTPS The secure version of the web, shown by the padlock. Everything sent between you and the site is scrambled so nobody in between can read or change it. More about HTTPS → scanning. Some security software inspects HTTPS traffic with its own certificate. If the warning appears on many sites at once, switch that feature off.
- Another device or network. If the site works on your phone with mobile data, the problem is your network or device. If it fails everywhere, only the site owner can fix it.
Clicking Advanced > Proceed is only reasonable on your own test server or router admin page, never on a site where you log in or pay.
What the codes mean
| Code | Meaning | Usual fix |
|---|---|---|
NET::ERR_CERT_DATE_INVALID | Certificate has expired, or your clock is wrong | Renew the certificate, or fix the device clock |
NET::ERR_CERT_COMMON_NAME_INVALID | Certificate is for a different name | Include every name, such as www, in the certificate |
NET::ERR_CERT_AUTHORITY_INVALID | Certificate is self-signed or the chain is incomplete | Install a trusted certificate with its full chain |
NET::ERR_CERT_REVOKED | The issuer cancelled the certificate | Get a new one |
ERR_CERT_WEAK_SIGNATURE_ALGORITHM | Certificate uses an outdated algorithm such as SHA-1 | Reissue it |
SEC_ERROR_UNKNOWN_ISSUER (Firefox) | Same as AUTHORITY_INVALID | Full chain, trusted issuer |
SSL_ERROR_BAD_CERT_DOMAIN (Firefox) | Same as COMMON_NAME_INVALID | Correct names |
If you run the site
1. See exactly what your server sends
Test from the command line, which shows the names, dates and issuer in one go:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -issuer -dates -ext subjectAltName
Look at notAfter for the expiry date, and the Subject Alternative Name list for every name the certificate covers. Online checkers such as SSL Labs’ server test show the same, plus chain problems.
2. Expired certificate
With Let’s EncryptLet’s Encrypt A free, non-profit service that gives websites the certificate they need for the padlock, and renews it automatically. More about Let’s Encrypt →, certificates last 90 days and renew automatically, so an expired one means renewal has been failing. Check and renew:
sudo certbot certificates
sudo certbot renew --dry-run
sudo certbot renew
If the dry run fails, its message says why. The common reasons:
- The domain no longer points at this server, so Let’s Encrypt cannot reach it. Check the A recordA record The line in a domain’s settings that says which server’s address to send visitors to. Like a forwarding address card for your website. More about A record →.
- PortPort A numbered door on a server. Each service listens behind its own door: web pages on 443, email on others, remote login on 22. More about Port → 80 is blocked by the firewallFirewall A gatekeeper that decides which connections are allowed into a server and blocks the rest. More about Firewall →. HTTP validation needs it open, even if the site redirects to HTTPS.
- **A rule blocks
/.well-known/acme-challenge/**, such as an NginxNginx A fast, popular program that sends web pages to visitors and can pass requests on to apps behind it. More about Nginx → rule denying hidden paths, or a redirect that sends that path elsewhere. - The renewal timer is not running. Check with
systemctl list-timers | grep certbot.
After renewing, reload the web serverWeb server The program that answers visitors’ browsers and sends them your website. Also used for the computer it runs on. More about Web server → so it uses the new certificate: sudo systemctl reload nginx. A certificate that renewed on disk but was never reloaded keeps serving the old one. See how to get a free SSL certificate with Let’s Encrypt.
3. Wrong name
ERR_CERT_COMMON_NAME_INVALID usually means the certificate covers example.com but not www.example.com, or the reverse. Reissue it with every name visitors use:
sudo certbot --nginx -d example.com -d www.example.com
It also happens when a server hosts several sites and sends the wrong site’s certificate, usually because the server_name in Nginx does not match the domain, so Nginx falls back to the first site it knows.
4. Incomplete chain
Browsers trust a certificate because it is signed by an intermediate certificate, which is signed by a root they already know. If your server sends only your own certificate without the intermediate, some browsers and most phones show ERR_CERT_AUTHORITY_INVALID, while desktop Chrome may still work because it has fetched the intermediate before.
With Certbot, point Nginx at fullchain.pem, not cert.pem:
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
With a purchased certificate, join your certificate and the issuer’s intermediate bundle into one file, yours first.
5. Self-signed certificates
A self-signed certificate is not trusted by anyone else’s browser. Replace it with a free trusted one from Let’s Encrypt. Control panelsControl panel A website you log into to manage your hosting with buttons and forms, instead of typing commands. cPanel and Plesk are the common ones. More about Control panel → often install a self-signed certificate on new sites until AutoSSL or Let’s Encrypt runs, so check the panel’s SSL page after adding a domain.
6. Behind Cloudflare or another CDN
Visitors receive the CDNCDN A network of servers around the world that keep copies of your site’s files, so each visitor gets them from somewhere nearby. Faster pages, less work for your server. More about CDN →’s certificate, so check its SSL settings. In Cloudflare, “Full (strict)” mode needs a valid certificate on your server too; with an expired one there, visitors see a Cloudflare error page instead. Cloudflare’s free Origin CA certificate is trusted by Cloudflare only, so it is fine behind the proxy but triggers this warning if the proxy is switched off.
Confirm it is fixed
Run the openssl command from step 1 again and check the dates and names. Then load the site in a private window on a phone using mobile data, which catches chain problems a desktop may hide.
Official documentation
- SSL Server Test, Qualys SSL Labs.
Related
- How HTTPS works.
- ERR_SSL_PROTOCOL_ERROR, when no secure connection can be made at all.
- ERR_TOO_MANY_REDIRECTS, a common side effect of HTTPS changes.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.



