Key idea
A certificate error means one of the browser's checks failed: the name, the dates, or the chain of trust. The error names the check, and the check tells you the fix. Clicking past it throws away the proof that you reached the right server.
Three certificate errors
The codes above are the ones Chrome and Edge show. Firefox and Safari word them differently, and command-line tools print their own messages, but each still reports one of these three checks.
Name mismatch
You typed one name and the certificate lists others. It's common right after adding a domain: example.com works but www.example.com doesn't, because only one of them is on the certificate. Remember that a wildcard covers one level only.
Expired, or not yet valid
Usually the certificate really expired because renewal broke. Check the expiry date first.
If one visitor sees date errors on every site, their device's clock is wrong. A clock set years back makes every certificate look not yet valid, and a clock set far ahead makes them all look expired.
Not trusted
The chain doesn't reach a root the device trusts. Three causes cover most cases:
- a self-signed certificate, left over from local testing;
- a missing intermediate: the server sends only the leaf;
- a private CA that only your company's devices trust.
A missing intermediate is sneaky. Browsers often fetch it themselves and show the padlock, while many tools, apps and servers refuse the same site. If it works in your browser but fails from code, check the chain.
What the command line says
curl: (60) SSL certificate problem: unable to get local issuer certificate
curl: (60) SSL: no alternative certificate subject name matches target host name 'www.example.com'
curl: (60) SSL certificate problem: certificate has expired
The first is the chain check, the second the name, the third the dates. Wording varies with how curl was built, but code 60 always means the certificate failed a check.
Don't switch the check off
curl -k and options like verify=False skip the checks, so the error goes away and so does the proof of who you're talking to. Anyone on the path could then read and change the traffic. Fix the certificate instead; code that skips checks tends to reach production.
Why some sites have no 'continue anyway' button
Some sites send a header, HSTS, telling browsers to accept only valid HTTPS for them from then on. On those sites a certificate error can't be clicked past at all, which protects visitors from an attacker who presents a fake certificate.
Check yourself