NET::ERR_CERT_AUTHORITY_INVALID: untrusted certificate fixes
Self-signed certificates, private CAs, and the sneaky one: a missing intermediate that works in your browser and fails everywhere else.
· 4 min read · By the Spot Downtime team
NET::ERR_CERT_AUTHORITY_INVALID means your browser couldn't trace the site's certificate back to a certificate authority it trusts. The certificate may be perfectly fine otherwise, with the right name and dates, but nothing vouches for it. Firefox shows SEC_ERROR_UNKNOWN_ISSUER; curl says unable to get local issuer certificate.
Common causes
A missing intermediate certificate
The most common cause on real websites, and the most confusing. Certificates are signed by an intermediate, which is signed by a trusted root. Your server has to send the intermediate along with its own certificate. If it doesn't, some browsers find it anyway (they cached it, or fetch it themselves) and others fail. So the site works on your laptop and fails on Android, in curl, or for an API client.
Fix: configure the full chain. With Let's Encrypt, point the server at fullchain.pem, not cert.pem:
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;A self-signed certificate
Self-signed certificates are fine for local development and internal tools where you control the trust, but browsers reject them on public sites. Use a free certificate from Let's Encrypt or ZeroSSL instead.
A private or internal CA
Company-issued certificates work on company devices that trust the company's root, and fail everywhere else. Public services need a publicly trusted certificate.
Something is intercepting the connection
If many sites show this error on one device or network, something in between is replacing certificates: antivirus HTTPS scanning, a corporate proxy, or a captive portal on public Wi-Fi. Don't click through; check the network first.
Check the chain
SSL certificate checkerSee the certificate's issuer and whether it's trusted, from outside your network.openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null
# "Verify return code: 0 (ok)" means the chain is complete and trusted.
# Code 21 (unable to verify the first certificate) usually means a missing intermediate.Tested in one browser? Test in a strict one
- Wrong name instead of wrong issuer? See ERR_CERT_COMMON_NAME_INVALID.
- Expired? See ERR_CERT_DATE_INVALID.
Spot Downtime checks certificates the strict way: an untrusted chain fails the check, so a missing intermediate is caught on the first check after a renewal.
Keep reading
- SSL · Browser errorsNET::ERR_CERT_DATE_INVALID: expired certificate or wrong clock?How to tell whether the certificate expired or the device clock is wrong, how to renew and reload properly, and how to never be surprised by it again.October 5, 2026 · 3 min read
- SSL · Browser errorsNET::ERR_CERT_COMMON_NAME_INVALID: certificate doesn't match the domainThe certificate is for a different name. www vs bare domain, wildcard limits, default certificates and DNS pointing elsewhere.October 5, 2026 · 3 min read