SSL/TLS Certificate & HTTPS Guides

Guides for certificate errors, chain and hostname mismatches, expiry, TLS handshake failures, and HSTS. Each guide includes a free SSL check for your host.

SSL/TLS — 47 guides

495 SSL Certificate Error (nginx): Client Cert Failed

495 SSL Certificate Error: nginx got your mTLS cert and rejected it — expired, wrong CA, or bad chain. Find why in 3 checks. Free instant check, no sign-up.

Diagnose

497 HTTP Request Sent to HTTPS Port (nginx): Fix

497 HTTP Request Sent to HTTPS Port: nginx got plain HTTP on a TLS port. Fix in 3 checks — scheme, proxy, redirect. Free instant check, no sign-up.

Diagnose

525 SSL Handshake Failed (Cloudflare) Fix

Cloudflare Error 525 means the TLS handshake to your origin failed. Check the origin cert, port 443, and TLS version in 3 steps. Free instant check, no sign-up.

Diagnose

526 Invalid SSL Certificate (Cloudflare) Fix

Cloudflare Error 526 means your origin cert failed validation under Full (Strict). Fix it in 3 checks: chain, expiry, hostname. Free instant check, no sign-up.

Diagnose

CAA Records: Restrict Which CAs Can Issue Your Certificates

Set a CAA DNS record to control which certificate authorities can issue for your domain, and avoid the parent-domain and caching traps that block legitimate renewals.

Diagnose

Cloudflare SSL Modes: Flexible vs Full vs Full (Strict)

Cloudflare SSL modes compared: Off, Flexible, Full, Full (Strict), and which one stops redirect loops and 526 errors. Free instant SSL check, no sign-up.

Diagnose

ERR_BAD_SSL_CLIENT_AUTH_CERT: Client Cert Rejected

ERR_BAD_SSL_CLIENT_AUTH_CERT means a site's mTLS check rejected your client certificate — missing, expired, or untrusted. Free instant check, no sign-up.

Diagnose

ERR_SSL_BAD_RECORD_MAC_ALERT in Chrome: Fix

ERR_SSL_BAD_RECORD_MAC_ALERT means a TLS record was corrupted, not a bad certificate. Check MTU, Wi-Fi, and antivirus. Free instant check, no sign-up.

Diagnose

ERR_SSL_DECRYPT_ERROR_ALERT in Chrome: Fix

ERR_SSL_DECRYPT_ERROR_ALERT means a TLS handshake signature failed, not a bad cert. Isolate client, middlebox, or server. Free instant check, no sign-up.

Diagnose

ERR_SSL_KEY_USAGE_INCOMPATIBLE: Wrong Cert Purpose

ERR_SSL_KEY_USAGE_INCOMPATIBLE means the cert's keyUsage or EKU forbids TLS server use. Isolate it in 3 checks. Free instant check, no sign-up.

Diagnose

ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN: MITM

ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN means a pinned Google cert was re-signed in your path. Find the interceptor in 3 checks. Free instant SSL check, no sign-up.

Diagnose

ERR_SSL_PROTOCOL_ERROR Fix Guide

ERR_SSL_PROTOCOL_ERROR? Diagnose it in 3 checks: TLS handshake, port 443 reachability, redirect and proxy config. Free instant check, no sign-up.

Diagnose

ERR_SSL_UNRECOGNIZED_NAME_ALERT: Fix the SNI Alert

ERR_SSL_UNRECOGNIZED_NAME_ALERT means the server rejected your SNI hostname before any cert. Check vhost, cert names, and SNI. Free instant check, no sign-up.

Diagnose

ERR_SSL_VERSION_OR_CIPHER_MISMATCH Fix

ERR_SSL_VERSION_OR_CIPHER_MISMATCH means no shared TLS version or cipher. Fix in 3 checks: protocol, cipher, certificate. Free instant check, no sign-up.

Diagnose

ERR_SSL_WEAK_EPHEMERAL_DH_KEY: It's the Server

ERR_SSL_WEAK_EPHEMERAL_DH_KEY: a server's Diffie-Hellman key is too small to trust. Fix it with strong DH params or ECDHE. Free instant check, no sign-up.

Diagnose

MOZILLA_PKIX_ERROR_INADEQUATE_KEY_SIZE: Fix

MOZILLA_PKIX_ERROR_INADEQUATE_KEY_SIZE: Firefox blocked a sub-2048-bit RSA key. Find the cert in 3 checks — leaf, chain, proxy. Free instant check, no sign-up.

Diagnose

MOZILLA_PKIX_ERROR_MITM_DETECTED (Firefox) Fix

MOZILLA_PKIX_ERROR_MITM_DETECTED: something is intercepting your TLS. Tell antivirus scanning from a real attack in 3 checks. Free instant check, no sign-up.

Diagnose

MOZILLA_PKIX_ERROR_NOT_YET_VALID_CERTIFICATE (Firefox)

MOZILLA_PKIX_ERROR_NOT_YET_VALID_CERTIFICATE means a cert isn't valid yet — usually a wrong clock. Check in 3 steps. Free instant check, no sign-up.

Diagnose

MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT: Fix in Firefox

MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT: Firefox rejected a self-signed cert. Fix in 3 checks — chain, issuer, trust store. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_AUTHORITY_INVALID Fix

NET::ERR_CERT_AUTHORITY_INVALID: the cert won't trace to a trusted root. Fix in 3 checks: chain, self-signed, private CA. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_COMMON_NAME_INVALID: Fix Certificate Mismatch

NET::ERR_CERT_COMMON_NAME_INVALID means the cert doesn't cover the hostname. Check SAN list, DNS target, and endpoint. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_DATE_INVALID Fix

NET::ERR_CERT_DATE_INVALID means the cert is expired, not yet valid, or your clock is wrong. Tell the three apart in 3 checks. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_INVALID Fix (No Proceed Link)

NET::ERR_CERT_INVALID blocks a malformed cert, no bypass. 3 checks find it: all sites vs one, middlebox, or broken cert. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_KNOWN_INTERCEPTION_BLOCKED: MITM

NET::ERR_CERT_KNOWN_INTERCEPTION_BLOCKED means Chrome flagged an interception cert in your TLS chain. See who is intercepting in 3 checks. Free instant SSL check, no sign-up.

Diagnose

NET::ERR_CERT_NAME_CONSTRAINT_VIOLATION Fix

NET::ERR_CERT_NAME_CONSTRAINT_VIOLATION: a trusted CA can't issue this name. Fix in 3 checks: chain, constraints, SANs. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_NON_UNIQUE_NAME: Internal Name Cert

NET::ERR_CERT_NON_UNIQUE_NAME means the cert covers an internal name or private IP no public CA may certify. Fix in 3 checks. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_REVOKED: Fix a Revoked Certificate

NET::ERR_CERT_REVOKED means a CA revoked the certificate. Check if it's truly revoked, which cert you serve, then reissue. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_SYMANTEC_LEGACY: Fix in Chrome

NET::ERR_CERT_SYMANTEC_LEGACY means Chrome distrusts a legacy Symantec cert. Check the issuer, then reissue from a modern CA. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_VALIDITY_TOO_LONG: Fix the 398-Day Cap

NET::ERR_CERT_VALIDITY_TOO_LONG means your cert exceeds the 398-day limit. Check the validity span, then reissue a shorter cert. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_WEAK_KEY in Chrome: Fix

NET::ERR_CERT_WEAK_KEY: a cert's RSA key is too small for Chrome. Find the weak cert in the chain and reissue at 2048-bit. Free instant check, no sign-up.

Diagnose

NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM: SHA-1 Cert Fix

NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM means a SHA-1 signature is in the chain — leaf or intermediate, never the root. Find which cert in 3 checks. Free instant check, no sign-up.

Diagnose

NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED Fix

NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED: no proof the cert was CT-logged. Tell a real cert from TLS interception in 3 checks. Free instant SSL check.

Diagnose

No Required SSL Certificate Was Sent (nginx 496)

No required SSL certificate was sent means nginx wanted an mTLS client cert and got none. Isolate client vs server in 3 steps. Free instant check, no sign-up.

Diagnose

SEC_ERROR_EXPIRED_CERTIFICATE (Firefox)

SEC_ERROR_EXPIRED_CERTIFICATE means Firefox sees an expired certificate, or your clock is wrong. Tell them apart in 3 checks. Free instant check, no sign-up.

Diagnose

SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE (Firefox)

SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE means a root or intermediate in your chain expired, not the leaf. Find it in 3 checks. Free instant check, no sign-up.

Diagnose

SEC_ERROR_REVOKED_CERTIFICATE in Firefox: Fix

SEC_ERROR_REVOKED_CERTIFICATE: Firefox found the cert on a revocation list. Server serving a revoked cert, or a local proxy? Free instant check, no sign-up.

Diagnose

SEC_ERROR_UNKNOWN_ISSUER (Firefox) Fix

SEC_ERROR_UNKNOWN_ISSUER: Firefox can't chain your certificate to a trusted root. Check for a missing intermediate or antivirus HTTPS scanning. Free instant check, no sign-up.

Diagnose

SSL Certificate Expired: Renewal and Recovery Checklist

SSL certificate expired or expiring? Recover in 4 steps: renew, deploy to every endpoint, verify the chain, automate. Free instant check, no sign-up.

Diagnose

SSL Chain Missing / Domain Mismatch Fix

SSL chain missing or domain mismatch? Tell the two apart in 2 checks, then fix the SAN or install the intermediate chain. Free instant check, no sign-up.

Diagnose

SSL_ERROR_BAD_CERT_ALERT in Firefox: Fix

SSL_ERROR_BAD_CERT_ALERT: the server rejected your client certificate, not its own. Check the cert, its CA, and expiry. Free instant check, no sign-up.

Diagnose

SSL_ERROR_BAD_CERT_DOMAIN in Firefox: Fix It

SSL_ERROR_BAD_CERT_DOMAIN means the cert doesn't cover this hostname. Check the SAN list, www vs apex, and wildcard scope. Free instant check, no sign-up.

Diagnose

SSL_ERROR_HANDSHAKE_FAILURE_ALERT in Firefox: Fix

SSL_ERROR_HANDSHAKE_FAILURE_ALERT: the server refused the handshake, not the cert. Check TLS version, ciphers, client certs. Free instant check, no sign-up.

Diagnose

SSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT: Firefox Fix

SSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT is a rejected TLS downgrade, not a cert error. Check antivirus HTTPS scanning, proxies. Free instant check, no sign-up.

Diagnose

SSL_ERROR_NO_CYPHER_OVERLAP in Firefox: Fix

SSL_ERROR_NO_CYPHER_OVERLAP: Firefox and the server share no TLS version or cipher. Fix in 3 checks: protocol, cipher, SNI. Free instant check, no sign-up.

Diagnose

SSL_ERROR_RX_RECORD_TOO_LONG in Firefox: Fix

SSL_ERROR_RX_RECORD_TOO_LONG usually means plain HTTP on port 443. Fix in 3 checks: the ssl directive, the port, the proxy. Free instant check, no sign-up.

Diagnose

SSL_ERROR_UNSUPPORTED_VERSION Fix (Firefox)

SSL_ERROR_UNSUPPORTED_VERSION: server offers only TLS 1.0/1.1, Firefox refuses. Fix at the server, not about:config. Free instant check, no sign-up.

Diagnose

Wildcard SSL Certificates — Setup and Pitfalls

Wildcard SSL covers *.example.com but not the apex or deeper subdomains. Setup steps, limits, and renewal pitfalls. Free instant cert check, no sign-up.

Diagnose
[Ad] Guide Cluster Inline
All guides