Troubleshooting

Common SSL Errors and How to Fix Them

Understand common HTTPS certificate errors including hostname mismatch, expiration, chain problems and mixed content.

Most SSL errors fall into a small number of categories. Start by identifying whether the problem is the certificate itself, the chain served by the server, the hostname being requested or insecure resources loaded by the page.

Expired certificate

Replace the expired certificate and verify that the renewed certificate is deployed to the production endpoint. Automate expiry monitoring wherever possible.

Hostname mismatch

The requested hostname must be covered by the certificate. A certificate for example.com does not automatically cover every possible subdomain unless the appropriate names or wildcard coverage are included.

Incomplete certificate chain

The server may need to present intermediate certificates so the browser can build a chain to a trusted root. Use an SSL checker to confirm the chain.

Mixed content

A page can use HTTPS while still requesting scripts, images or other resources over HTTP. Update resource URLs and application configuration so the entire page loads securely.

Common SSL Errors and How to Fix Them — FAQs

Why does my browser say the connection is not private?

The browser may be seeing an expired certificate, hostname mismatch, untrusted issuer or chain problem. Inspect the live certificate details to identify the cause.

Can a valid certificate still have mixed-content errors?

Yes. The certificate can be valid while the page itself loads some resources over HTTP. Those resource URLs must be updated.

Need the right SSL certificate?

Compare validation levels, domain coverage and trusted brands before you buy.

Compare SSL certificates

Frequently asked questions

Why does my browser say the connection is not private?

The browser may be seeing an expired certificate, hostname mismatch, untrusted issuer or chain problem. Inspect the live certificate details to identify the cause.

Can a valid certificate still have mixed-content errors?

Yes. The certificate can be valid while the page itself loads some resources over HTTP. Those resource URLs must be updated.