Blog
4 min read

"Your Connection Is Not Private" on Your Own Site: Causes and Fixes

When visitors see NET::ERR_CERT_DATE_INVALID, ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_AUTHORITY_INVALID on your site, the SSL certificate is expired, for the wrong name, or incomplete. How to tell which, and how to fix each one.

You open your site and the browser shows a full-page warning: "Your connection is not private" (Chrome) or "Warning: Potential Security Risk Ahead" (Firefox). Visitors see it too, and most of them leave.

The cause is almost always your site's SSL certificate — the file that proves your site is really yourapp.com and enables HTTPS. (What is HTTPS?) The error code under the message tells you exactly what's wrong.

First: is it your site or the visitor's computer?

If it happens on every site for one person, it's their side: wrong clock, antivirus intercepting traffic, or a captive Wi-Fi portal (hotel, airport). Fixing the date and time on their device solves a surprising number of these.

If it happens on your site for everyone, keep reading.

Read the error code

Click "Advanced" or look under the message for the code:

Code Means
NET::ERR_CERT_DATE_INVALID Certificate expired (or not yet valid)
NET::ERR_CERT_COMMON_NAME_INVALID Certificate is for a different name
NET::ERR_CERT_AUTHORITY_INVALID Not issued by a trusted authority, or chain incomplete
ERR_SSL_PROTOCOL_ERROR / ERR_SSL_VERSION_OR_CIPHER_MISMATCH Server isn't speaking HTTPS correctly

Click the "Not secure" badge in the address bar → certificate details to see the expiry date and the names it covers.

Expired certificate (ERR_CERT_DATE_INVALID)

Free certificates from Let's Encrypt last a short time (90 days, and getting shorter) and renew automatically. When renewal breaks, the certificate quietly expires.

Common reasons renewal fails:

  • The domain's DNS no longer points at the server doing the renewing.
  • Port 80 is blocked by a firewall — the renewal check uses it.
  • A proxy in front (like Cloudflare) intercepts the check.
  • The renewal job or service simply isn't running.

Fix: run your renewal manually and read the error (certbot renew --dry-run, or check your Caddy/Traefik logs), fix the cause, then make sure renewal is scheduled. How automatic SSL works explains the moving parts.

Wrong name (ERR_CERT_COMMON_NAME_INVALID)

The certificate is valid, but not for the address in the browser. Classic cases:

  • Certificate covers yourapp.com but the visitor typed www.yourapp.com (or vice versa). Get a certificate covering both, and redirect one to the other. (www vs non-www)
  • You pointed a new domain at a host that is still serving its default certificate (*.hostingprovider.com) because you haven't added the domain in the host's dashboard.
  • A subdomain like api.yourapp.com isn't covered.

Untrusted authority (ERR_CERT_AUTHORITY_INVALID)

  • Self-signed certificate — fine for localhost, never for a public site.
  • Missing intermediate certificate — the server sends your certificate but not the chain that links it to a trusted root. Desktop browsers sometimes cope; phones and API clients often don't. Use the "full chain" file (fullchain.pem with certbot) in your server config.

An online SSL checker (search "SSL server test") will flag chain problems immediately.

Behind Cloudflare?

With Cloudflare proxying (orange cloud), visitors see Cloudflare's certificate, and Cloudflare connects to your server separately. Make sure:

  • Your domain is active in Cloudflare and the record is proxied.
  • SSL mode is Full (strict) and your server has a valid certificate (or a Cloudflare Origin certificate).

(Cloudflare proxied vs DNS only and ERR_TOO_MANY_REDIRECTS cover related traps.)

Just connected a new domain?

Certificates can only be issued once DNS points at your server. In the first minutes or hours after a DNS change, you may see a certificate error while propagation finishes and the host issues the certificate. Wait, then check again. (DNS propagation explained)

Prevent it next time

  • Use a host or server that renews certificates automatically.
  • Add an uptime monitor that checks certificate expiry and alerts you weeks ahead. (Know when your app is down)

The summary

  • Read the code: DATE = expired, COMMON_NAME = wrong name, AUTHORITY = untrusted or broken chain.
  • Expired usually means renewal broke — check DNS, port 80 and proxies.
  • Wrong name usually means www vs non-www or a domain not added to the host.
  • Serve the full chain, never a self-signed certificate.

EasySpawn issues and renews SSL certificates for your custom domains automatically, including www and subdomains. See how it works or join the waitlist.

Related: How Automatic SSL Actually Works · Mixed Content Errors · How to Connect a Custom Domain to Your App · What Is Cloudflare?

Keep reading