How to fix “Your connection is not private”

The browser does not trust the site’s certificate. What each NET::ERR_CERT code means, and how to fix it on either side.

1–2 minutes
Laptop showing code next to a coffee mug

This warning means the site’s HTTPS certificate failed one of the browser’s checks: it expired, it is for a different name, or it was not issued by a trusted authority. The code under the message says which.

CodeMeans
NET::ERR_CERT_DATE_INVALIDExpired, or your device’s clock is wrong
NET::ERR_CERT_COMMON_NAME_INVALIDCertificate is for a different domain
NET::ERR_CERT_AUTHORITY_INVALIDSelf-signed or from an untrusted issuer
ERR_CERT_REVOKEDThe issuer cancelled the certificate

If you are visiting the site

  • Check your device’s date and time. A wrong clock makes every certificate look invalid.
  • Avoid entering passwords or payment details on a site showing this warning.
  • On public Wi-Fi, the network may be intercepting traffic before you log in to it. Open any http:// site to trigger its login page.
  • Some antivirus software inspects HTTPS and can cause it; try with that feature off.

If you run the site

Check what the server is actually sending:

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -issuer -dates -ext subjectAltName

Expired

Renew it. With Let’s Encrypt:

sudo certbot renew
sudo systemctl reload nginx

Then find out why automatic renewal failed: sudo certbot renew --dry-run usually shows the reason (a blocked port 80, a changed DNS record, or a stopped timer).

Wrong name

The certificate does not include the name visitors use, often www. Reissue with every name:

sudo certbot --nginx -d example.com -d www.example.com

Also check the right site’s certificate is served: a missing server_name sends visitors to the default site’s certificate.

Untrusted issuer or missing chain

Use a public authority such as Let’s Encrypt rather than a self-signed certificate, and make sure the server sends the full chain. With Certbot on Nginx, use fullchain.pem, not cert.pem.

See how HTTPS works for the background.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.