Common SSL errors and fixes
| Browser error | Cause | Fix |
|---|---|---|
| NET::ERR_CERT_DATE_INVALID | Certificate expired (or the device clock is wrong) | Renew the certificate; check the computer's date |
| ERR_CERT_COMMON_NAME_INVALID | The domain is not in the certificate's SANs | Reissue the certificate including every hostname, incl. www |
| ERR_CERT_AUTHORITY_INVALID | Self-signed certificate or missing intermediate | Install the full chain from your certificate provider |
| Mixed content warning | An HTTPS page loads images or scripts over HTTP | Change those URLs to https:// |
The padlock is not a safety badge
Encryption protects data in transit - nothing more.
Most phishing sites now use HTTPS, because certificates are free. Always check the domain name itself, its age in the WHOIS Lookup, and its reputation in the URL Scanner.
Frequently asked questions
What does the SSL Checker test?
It connects to the site on port 443 and reads its certificate: who issued it, which domains it covers, when it expires and which signature algorithm it uses.
Does a padlock mean a website is safe?
No. The padlock only means the connection is encrypted. Phishing sites get free certificates too. Check the site itself with the URL Scanner.
What happens when a certificate expires?
Browsers show a full-page "Your connection is not private" warning and most visitors leave. Automate renewal (for example with Let's Encrypt or cPanel AutoSSL) and monitor expiry dates.
What are SANs?
Subject Alternative Names are the list of domain names a certificate is valid for. If the name you visit is not on the list, browsers show a name-mismatch error.
How often should I check my certificate?
Free certificates last 90 days or less. Check after every renewal and set a reminder about two weeks before the expiry date shown here.