Most Common SSL Errors and Their Solutions
· Troubleshooting
SSL errors drive visitors away and damage site reputation. Here are the most common ones and how to fix them.
ERR_CERT_AUTHORITY_INVALID
The browser doesn't trust the signing CA. Usually caused by self-signed certificates or a missing intermediate chain. Fix: Use a trusted CA and install the complete certificate chain.
NET::ERR_CERT_DATE_INVALID
Certificate is expired or server clock is wrong. Fix: Renew the certificate and ensure the server time is NTP-synchronized.
NET::ERR_CERT_COMMON_NAME_INVALID
The certificate doesn't cover the accessed domain. Fix: Use a SAN certificate that includes both www and non-www variants.
SSL_ERROR_RX_RECORD_TOO_LONG
The server is sending plain HTTP to an HTTPS port. Fix: Check your virtual host config and ensure SSL directives are active on port 443.
Mixed Content
An HTTPS page loads resources over HTTP. Fix: Update all internal links and media URLs to use HTTPS, or use protocol-relative URLs (//). Chrome DevTools Console lists the offending resources.
Incomplete Certificate Chain
Some browsers (especially older Android) reject the cert. Fix: Use the full chain file (fullchain.pem) provided by your CA. SSL Labs catches this.
Always run ssllabs.com/ssltest after installation. An A or A+ rating confirms correct configuration.
Visit the PekiSSL product page to find the right certificate for your needs.