"Your Connection Is Not Private" on Your Own Site: Causes and Fixes
When visitors see NET::ERR_CERT_DATE_INVALID, ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_AUTHORITY_INVALID on your site, the SSL certificate is expired, for the wrong name, or incomplete. How to tell which, and how to fix each one.
You open your site and the browser shows a full-page warning: "Your connection is not private" (Chrome) or "Warning: Potential Security Risk Ahead" (Firefox). Visitors see it too, and most of them leave.
The cause is almost always your site's SSL certificate — the file that proves your site is really yourapp.com and enables HTTPS. (What is HTTPS?) The error code under the message tells you exactly what's wrong.
First: is it your site or the visitor's computer?
If it happens on every site for one person, it's their side: wrong clock, antivirus intercepting traffic, or a captive Wi-Fi portal (hotel, airport). Fixing the date and time on their device solves a surprising number of these.
If it happens on your site for everyone, keep reading.
Read the error code
Click "Advanced" or look under the message for the code:
| Code | Means |
|---|---|
NET::ERR_CERT_DATE_INVALID |
Certificate expired (or not yet valid) |
NET::ERR_CERT_COMMON_NAME_INVALID |
Certificate is for a different name |
NET::ERR_CERT_AUTHORITY_INVALID |
Not issued by a trusted authority, or chain incomplete |
ERR_SSL_PROTOCOL_ERROR / ERR_SSL_VERSION_OR_CIPHER_MISMATCH |
Server isn't speaking HTTPS correctly |
Click the "Not secure" badge in the address bar → certificate details to see the expiry date and the names it covers.
Expired certificate (ERR_CERT_DATE_INVALID)
Free certificates from Let's Encrypt last a short time (90 days, and getting shorter) and renew automatically. When renewal breaks, the certificate quietly expires.
Common reasons renewal fails:
- The domain's DNS no longer points at the server doing the renewing.
- Port 80 is blocked by a firewall — the renewal check uses it.
- A proxy in front (like Cloudflare) intercepts the check.
- The renewal job or service simply isn't running.
Fix: run your renewal manually and read the error (certbot renew --dry-run, or check your Caddy/Traefik logs), fix the cause, then make sure renewal is scheduled. How automatic SSL works explains the moving parts.
Wrong name (ERR_CERT_COMMON_NAME_INVALID)
The certificate is valid, but not for the address in the browser. Classic cases:
- Certificate covers
yourapp.combut the visitor typedwww.yourapp.com(or vice versa). Get a certificate covering both, and redirect one to the other. (www vs non-www) - You pointed a new domain at a host that is still serving its default certificate (
*.hostingprovider.com) because you haven't added the domain in the host's dashboard. - A subdomain like
api.yourapp.comisn't covered.
Untrusted authority (ERR_CERT_AUTHORITY_INVALID)
- Self-signed certificate — fine for
localhost, never for a public site. - Missing intermediate certificate — the server sends your certificate but not the chain that links it to a trusted root. Desktop browsers sometimes cope; phones and API clients often don't. Use the "full chain" file (
fullchain.pemwith certbot) in your server config.
An online SSL checker (search "SSL server test") will flag chain problems immediately.
Behind Cloudflare?
With Cloudflare proxying (orange cloud), visitors see Cloudflare's certificate, and Cloudflare connects to your server separately. Make sure:
- Your domain is active in Cloudflare and the record is proxied.
- SSL mode is Full (strict) and your server has a valid certificate (or a Cloudflare Origin certificate).
(Cloudflare proxied vs DNS only and ERR_TOO_MANY_REDIRECTS cover related traps.)
Just connected a new domain?
Certificates can only be issued once DNS points at your server. In the first minutes or hours after a DNS change, you may see a certificate error while propagation finishes and the host issues the certificate. Wait, then check again. (DNS propagation explained)
Prevent it next time
- Use a host or server that renews certificates automatically.
- Add an uptime monitor that checks certificate expiry and alerts you weeks ahead. (Know when your app is down)
The summary
- Read the code: DATE = expired, COMMON_NAME = wrong name, AUTHORITY = untrusted or broken chain.
- Expired usually means renewal broke — check DNS, port 80 and proxies.
- Wrong name usually means www vs non-www or a domain not added to the host.
- Serve the full chain, never a self-signed certificate.
EasySpawn issues and renews SSL certificates for your custom domains automatically, including www and subdomains. See how it works or join the waitlist.
Related: How Automatic SSL Actually Works · Mixed Content Errors · How to Connect a Custom Domain to Your App · What Is Cloudflare?
Keep reading
Mixed Content Errors: Why Your HTTPS Site Loads Things Over HTTP (and How to Fix It)
"Mixed Content: The page was loaded over HTTPS, but requested an insecure resource." What mixed content is, why browsers block it, how to find every http:// URL, and the fixes — including apps behind a proxy that generate http links.
What Is Cloudflare? What It Does When You Put Your Site Behind It
Cloudflare sits between your visitors and your server: DNS, a CDN, free SSL, DDoS protection and a firewall. What changes when you turn on the orange cloud, what it costs, what it can break, and whether a small app needs it.