"Your connection is not private" on your own website: how to fix it

Your visitors see a full red warning page instead of your site. The browser checked your site's security certificate and did not trust it. Most people leave at this point. The fix is almost always on your side, and it is usually quick.

Read the code under the message

Click "Advanced" on the warning. A short code tells you which problem you have.

  1. NET::ERR_CERT_DATE_INVALID. The certificate expired. Renew it in your hosting panel (look for SSL or Let's Encrypt). On a VPS with certbot, run sudo certbot renew and reload the web server.
  2. NET::ERR_CERT_COMMON_NAME_INVALID. The certificate is for a different name. Common case: it covers example.com but not www.example.com. Reissue it for both names.
  3. NET::ERR_CERT_AUTHORITY_INVALID. The certificate is self-signed or missing its chain. Install a real one from your host or Let's Encrypt, and include the full chain file, not only the certificate.
  4. Just moved the domain? If you changed hosts or pointed the domain somewhere new in the last day, the new host may not have issued a certificate yet. Most hosts do it automatically once DNS points at them. Wait an hour, then ask their support.

If only you see it

Try another network or your phone on mobile data. If the warning only appears on one network, a work firewall, an antivirus "web shield", or a wrong clock on your computer is the cause, not your site.

Check it yourself

Run echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null | openssl x509 -noout -dates -subject. It prints the expiry date and the name the certificate covers.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.