Guides · Fix a certificate error

SSL certificate errors explained: what each browser and curl message means

Last reviewed by a person on October 4, 2026

Certificate errors come with long, cryptic names, and the name changes with the browser. The same problem looks different in Chrome, Firefox, curl and Java. Use this page to translate what you see into what is actually wrong, and where to look next.

First: is it the site, or is it you?

Before you touch any server, rule out the visitor's side. A certificate error on every site usually means:

  • The device's clock or date is wrong. A certificate looks "not yet valid" or "expired" if the computer thinks it is 2019 or next year. This is the classic cause of NET::ERR_CERT_DATE_INVALID on all sites.
  • Antivirus or a company proxy that inspects HTTPS and uses its own certificate. Try another network or device.
  • An old device that does not know newer authorities or protocol versions.

If only one site fails, and it fails on other devices too, the problem is on the site's side.

Browser messages

What you seeWhat it meansNext step
NET::ERR_CERT_DATE_INVALID (Chrome, Edge)
SEC_ERROR_EXPIRED_CERTIFICATE (Firefox)
The certificate is outside its validity dates: expired or not yet valid. A wrong date on your device causes the same error. Expired certificate
NET::ERR_CERT_COMMON_NAME_INVALID
SSL_ERROR_BAD_CERT_DOMAIN (Firefox)
The certificate is valid, but not for the name in the address bar. Name mismatch, SANs and wildcards
NET::ERR_CERT_AUTHORITY_INVALID
SEC_ERROR_UNKNOWN_ISSUER
MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT
The browser can't build a trusted chain from the certificate to a root it knows. Common causes include a self-signed certificate, a private CA, a missing intermediate certificate, or antivirus or a proxy replacing the certificate. Chain order and missing intermediates
NET::ERR_CERT_REVOKED The issuing authority has cancelled this certificate (for example after a key leak). Get a new certificate and install it. Revoked certificates cannot be reactivated.
NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM A certificate in the chain is signed with an outdated algorithm such as SHA-1. Replace the certificate or the intermediate. The chain checker shows each certificate's algorithm.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
SSL_ERROR_NO_CYPHER_OVERLAP
SSL_ERROR_UNSUPPORTED_VERSION
The browser and the server couldn't agree on a TLS version or cipher. Causes include a protocol or cipher list on the server that is too narrow or misconfigured, no certificate set up for that name on the server or CDN, or a very old browser. TLS versions and ciphers
ERR_SSL_PROTOCOL_ERROR The TLS handshake failed in an unspecific way: HTTPS is not set up on that port, a proxy is in the way, or the server is misconfigured. Test the server with the TLS checker.
ERR_CONNECTION_REFUSED, ERR_CONNECTION_TIMED_OUT Not a certificate problem: nothing is answering on port 443 (the server is down, a firewall blocks it, or the DNS points to the wrong place). Check the server and the DNS record.

curl, Python, Java and other tools

Programs print plainer text, and they are stricter than browsers, so they fail on problems a browser quietly works around:

  • curl: (60) SSL certificate problem: unable to get local issuer certificate or unable to verify the first certificate: the server does not send its intermediate certificate (a browser may have found it elsewhere), or the certificate is from a private CA. See chain order.
  • curl: (60) SSL certificate problem: certificate has expired: expired certificate, or an expired certificate in the chain that the server still sends.
  • curl: (60) SSL: no alternative certificate subject name matches target host name: name mismatch.
  • curl: (35) error:… wrong version number or unsupported protocol: not speaking TLS on that port, or a TLS version mismatch.
  • PKIX path building failed (Java): the chain cannot be built to a trusted root: missing intermediate, or a root Java does not know.
  • SSLCertVerificationError … CERTIFICATE_VERIFY_FAILED (Python): the same family as curl 60.

Do not "fix" these by turning verification off (curl -k, verify=False). That hides the symptom and removes the protection.

See what the server really sends

Free tools show it from outside, so you can tell whether the server or your device is at fault: the SSL/TLS certificate checker (expiry, issuer, trust, names), the certificate chain checker (the chain in order) and the TLS checker (TLS versions and ciphers). To catch the next one before a visitor does, monitor the domain with CertAvert: it checks every day and emails you.

Don't wait for the browser warning

Check any site's certificate in a few seconds with the SSL/TLS checker, or sign up free and CertAvert emails you before certificates expire.

Fix a certificate error: more guides

All guides