495 SSL Certificate Error (nginx): Client Cert Failed
495 SSL Certificate Error: nginx got your mTLS cert and rejected it — expired, wrong CA, or bad chain. Find why in 3 checks. Free instant check, no sign-up.
DiagnoseGuides for certificate errors, chain and hostname mismatches, expiry, TLS handshake failures, and HSTS. Each guide includes a free SSL check for your host.
495 SSL Certificate Error: nginx got your mTLS cert and rejected it — expired, wrong CA, or bad chain. Find why in 3 checks. Free instant check, no sign-up.
Diagnose497 HTTP Request Sent to HTTPS Port: nginx got plain HTTP on a TLS port. Fix in 3 checks — scheme, proxy, redirect. Free instant check, no sign-up.
DiagnoseCloudflare Error 525 means the TLS handshake to your origin failed. Check the origin cert, port 443, and TLS version in 3 steps. Free instant check, no sign-up.
DiagnoseCloudflare Error 526 means your origin cert failed validation under Full (Strict). Fix it in 3 checks: chain, expiry, hostname. Free instant check, no sign-up.
DiagnoseSet a CAA DNS record to control which certificate authorities can issue for your domain, and avoid the parent-domain and caching traps that block legitimate renewals.
DiagnoseCloudflare SSL modes compared: Off, Flexible, Full, Full (Strict), and which one stops redirect loops and 526 errors. Free instant SSL check, no sign-up.
DiagnoseERR_BAD_SSL_CLIENT_AUTH_CERT means a site's mTLS check rejected your client certificate — missing, expired, or untrusted. Free instant check, no sign-up.
DiagnoseERR_SSL_BAD_RECORD_MAC_ALERT means a TLS record was corrupted, not a bad certificate. Check MTU, Wi-Fi, and antivirus. Free instant check, no sign-up.
DiagnoseERR_SSL_DECRYPT_ERROR_ALERT means a TLS handshake signature failed, not a bad cert. Isolate client, middlebox, or server. Free instant check, no sign-up.
DiagnoseERR_SSL_KEY_USAGE_INCOMPATIBLE means the cert's keyUsage or EKU forbids TLS server use. Isolate it in 3 checks. Free instant check, no sign-up.
DiagnoseERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN means a pinned Google cert was re-signed in your path. Find the interceptor in 3 checks. Free instant SSL check, no sign-up.
DiagnoseERR_SSL_PROTOCOL_ERROR? Diagnose it in 3 checks: TLS handshake, port 443 reachability, redirect and proxy config. Free instant check, no sign-up.
DiagnoseERR_SSL_UNRECOGNIZED_NAME_ALERT means the server rejected your SNI hostname before any cert. Check vhost, cert names, and SNI. Free instant check, no sign-up.
DiagnoseERR_SSL_VERSION_OR_CIPHER_MISMATCH means no shared TLS version or cipher. Fix in 3 checks: protocol, cipher, certificate. Free instant check, no sign-up.
DiagnoseERR_SSL_WEAK_EPHEMERAL_DH_KEY: a server's Diffie-Hellman key is too small to trust. Fix it with strong DH params or ECDHE. Free instant check, no sign-up.
DiagnoseMOZILLA_PKIX_ERROR_INADEQUATE_KEY_SIZE: Firefox blocked a sub-2048-bit RSA key. Find the cert in 3 checks — leaf, chain, proxy. Free instant check, no sign-up.
DiagnoseMOZILLA_PKIX_ERROR_MITM_DETECTED: something is intercepting your TLS. Tell antivirus scanning from a real attack in 3 checks. Free instant check, no sign-up.
DiagnoseMOZILLA_PKIX_ERROR_NOT_YET_VALID_CERTIFICATE means a cert isn't valid yet — usually a wrong clock. Check in 3 steps. Free instant check, no sign-up.
DiagnoseMOZILLA_PKIX_ERROR_SELF_SIGNED_CERT: Firefox rejected a self-signed cert. Fix in 3 checks — chain, issuer, trust store. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_AUTHORITY_INVALID: the cert won't trace to a trusted root. Fix in 3 checks: chain, self-signed, private CA. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_COMMON_NAME_INVALID means the cert doesn't cover the hostname. Check SAN list, DNS target, and endpoint. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_DATE_INVALID means the cert is expired, not yet valid, or your clock is wrong. Tell the three apart in 3 checks. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_INVALID blocks a malformed cert, no bypass. 3 checks find it: all sites vs one, middlebox, or broken cert. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_KNOWN_INTERCEPTION_BLOCKED means Chrome flagged an interception cert in your TLS chain. See who is intercepting in 3 checks. Free instant SSL check, no sign-up.
DiagnoseNET::ERR_CERT_NAME_CONSTRAINT_VIOLATION: a trusted CA can't issue this name. Fix in 3 checks: chain, constraints, SANs. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_NON_UNIQUE_NAME means the cert covers an internal name or private IP no public CA may certify. Fix in 3 checks. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_REVOKED means a CA revoked the certificate. Check if it's truly revoked, which cert you serve, then reissue. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_SYMANTEC_LEGACY means Chrome distrusts a legacy Symantec cert. Check the issuer, then reissue from a modern CA. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_VALIDITY_TOO_LONG means your cert exceeds the 398-day limit. Check the validity span, then reissue a shorter cert. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_WEAK_KEY: a cert's RSA key is too small for Chrome. Find the weak cert in the chain and reissue at 2048-bit. Free instant check, no sign-up.
DiagnoseNET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM means a SHA-1 signature is in the chain — leaf or intermediate, never the root. Find which cert in 3 checks. Free instant check, no sign-up.
DiagnoseNET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED: no proof the cert was CT-logged. Tell a real cert from TLS interception in 3 checks. Free instant SSL check.
DiagnoseNo required SSL certificate was sent means nginx wanted an mTLS client cert and got none. Isolate client vs server in 3 steps. Free instant check, no sign-up.
DiagnoseSEC_ERROR_EXPIRED_CERTIFICATE means Firefox sees an expired certificate, or your clock is wrong. Tell them apart in 3 checks. Free instant check, no sign-up.
DiagnoseSEC_ERROR_EXPIRED_ISSUER_CERTIFICATE means a root or intermediate in your chain expired, not the leaf. Find it in 3 checks. Free instant check, no sign-up.
DiagnoseSEC_ERROR_REVOKED_CERTIFICATE: Firefox found the cert on a revocation list. Server serving a revoked cert, or a local proxy? Free instant check, no sign-up.
DiagnoseSEC_ERROR_UNKNOWN_ISSUER: Firefox can't chain your certificate to a trusted root. Check for a missing intermediate or antivirus HTTPS scanning. Free instant check, no sign-up.
DiagnoseSSL certificate expired or expiring? Recover in 4 steps: renew, deploy to every endpoint, verify the chain, automate. Free instant check, no sign-up.
DiagnoseSSL chain missing or domain mismatch? Tell the two apart in 2 checks, then fix the SAN or install the intermediate chain. Free instant check, no sign-up.
DiagnoseSSL_ERROR_BAD_CERT_ALERT: the server rejected your client certificate, not its own. Check the cert, its CA, and expiry. Free instant check, no sign-up.
DiagnoseSSL_ERROR_BAD_CERT_DOMAIN means the cert doesn't cover this hostname. Check the SAN list, www vs apex, and wildcard scope. Free instant check, no sign-up.
DiagnoseSSL_ERROR_HANDSHAKE_FAILURE_ALERT: the server refused the handshake, not the cert. Check TLS version, ciphers, client certs. Free instant check, no sign-up.
DiagnoseSSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT is a rejected TLS downgrade, not a cert error. Check antivirus HTTPS scanning, proxies. Free instant check, no sign-up.
DiagnoseSSL_ERROR_NO_CYPHER_OVERLAP: Firefox and the server share no TLS version or cipher. Fix in 3 checks: protocol, cipher, SNI. Free instant check, no sign-up.
DiagnoseSSL_ERROR_RX_RECORD_TOO_LONG usually means plain HTTP on port 443. Fix in 3 checks: the ssl directive, the port, the proxy. Free instant check, no sign-up.
DiagnoseSSL_ERROR_UNSUPPORTED_VERSION: server offers only TLS 1.0/1.1, Firefox refuses. Fix at the server, not about:config. Free instant check, no sign-up.
DiagnoseWildcard SSL covers *.example.com but not the apex or deeper subdomains. Setup steps, limits, and renewal pitfalls. Free instant cert check, no sign-up.
Diagnose