Most Common SSL Errors and Their Solutions

· Troubleshooting

SSL errors drive visitors away and damage site reputation. Here are the most common ones and how to fix them.

ERR_CERT_AUTHORITY_INVALID

The browser doesn't trust the signing CA. Usually caused by self-signed certificates or a missing intermediate chain. Fix: Use a trusted CA and install the complete certificate chain.

NET::ERR_CERT_DATE_INVALID

Certificate is expired or server clock is wrong. Fix: Renew the certificate and ensure the server time is NTP-synchronized.

NET::ERR_CERT_COMMON_NAME_INVALID

The certificate doesn't cover the accessed domain. Fix: Use a SAN certificate that includes both www and non-www variants.

SSL_ERROR_RX_RECORD_TOO_LONG

The server is sending plain HTTP to an HTTPS port. Fix: Check your virtual host config and ensure SSL directives are active on port 443.

Mixed Content

An HTTPS page loads resources over HTTP. Fix: Update all internal links and media URLs to use HTTPS, or use protocol-relative URLs (//). Chrome DevTools Console lists the offending resources.

Incomplete Certificate Chain

Some browsers (especially older Android) reject the cert. Fix: Use the full chain file (fullchain.pem) provided by your CA. SSL Labs catches this.

Always run ssllabs.com/ssltest after installation. An A or A+ rating confirms correct configuration.

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts