NET::ERR_CERT_AUTHORITY_INVALID: untrusted certificate fixes

Self-signed certificates, private CAs, and the sneaky one: a missing intermediate that works in your browser and fails everywhere else.

· 4 min read · By the Spot Downtime team

NET::ERR_CERT_AUTHORITY_INVALID means your browser couldn't trace the site's certificate back to a certificate authority it trusts. The certificate may be perfectly fine otherwise, with the right name and dates, but nothing vouches for it. Firefox shows SEC_ERROR_UNKNOWN_ISSUER; curl says unable to get local issuer certificate.

Common causes

A missing intermediate certificate

The most common cause on real websites, and the most confusing. Certificates are signed by an intermediate, which is signed by a trusted root. Your server has to send the intermediate along with its own certificate. If it doesn't, some browsers find it anyway (they cached it, or fetch it themselves) and others fail. So the site works on your laptop and fails on Android, in curl, or for an API client.

Fix: configure the full chain. With Let's Encrypt, point the server at fullchain.pem, not cert.pem:

nginx
ssl_certificate     /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;

A self-signed certificate

Self-signed certificates are fine for local development and internal tools where you control the trust, but browsers reject them on public sites. Use a free certificate from Let's Encrypt or ZeroSSL instead.

A private or internal CA

Company-issued certificates work on company devices that trust the company's root, and fail everywhere else. Public services need a publicly trusted certificate.

Something is intercepting the connection

If many sites show this error on one device or network, something in between is replacing certificates: antivirus HTTPS scanning, a corporate proxy, or a captive portal on public Wi-Fi. Don't click through; check the network first.

Check the chain

SSL certificate checkerSee the certificate's issuer and whether it's trusted, from outside your network.
bash
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null
# "Verify return code: 0 (ok)" means the chain is complete and trusted.
# Code 21 (unable to verify the first certificate) usually means a missing intermediate.

Tested in one browser? Test in a strict one

Desktop browsers hide chain problems more than other clients do. Check with a tool that doesn't cache intermediates (curl, openssl or the checker above) after every certificate change.

Spot Downtime checks certificates the strict way: an untrusted chain fails the check, so a missing intermediate is caught on the first check after a renewal.

Keep reading