Learning paths / Cloud foundations / TLS and certificates

Reading certificate errors

Reading · 5 min · Module 7, lesson 3 of 410 min left in this module

Module 7 · TLS and certificatesLesson 3 of 4

Goal: Tell which certificate check failed from the error a browser or client shows, and pick the fix.

Key idea

A certificate error means one of the browser's checks failed: the name, the dates, or the chain of trust. The error names the check, and the check tells you the fix. Clicking past it throws away the proof that you reached the right server.

The codes above are the ones Chrome and Edge show. Firefox and Safari word them differently, and command-line tools print their own messages, but each still reports one of these three checks.

Name mismatch

You typed one name and the certificate lists others. It's common right after adding a domain: example.com works but www.example.com doesn't, because only one of them is on the certificate. Remember that a wildcard covers one level only.

Expired, or not yet valid

Usually the certificate really expired because renewal broke. Check the expiry date first.

If one visitor sees date errors on every site, their device's clock is wrong. A clock set years back makes every certificate look not yet valid, and a clock set far ahead makes them all look expired.

Not trusted

The chain doesn't reach a root the device trusts. Three causes cover most cases:

  • a self-signed certificate, left over from local testing;
  • a missing intermediate: the server sends only the leaf;
  • a private CA that only your company's devices trust.

A missing intermediate is sneaky. Browsers often fetch it themselves and show the padlock, while many tools, apps and servers refuse the same site. If it works in your browser but fails from code, check the chain.

What the command line says

curl: (60) SSL certificate problem: unable to get local issuer certificate
curl: (60) SSL: no alternative certificate subject name matches target host name 'www.example.com'
curl: (60) SSL certificate problem: certificate has expired

The first is the chain check, the second the name, the third the dates. Wording varies with how curl was built, but code 60 always means the certificate failed a check.

Don't switch the check off

curl -k and options like verify=False skip the checks, so the error goes away and so does the proof of who you're talking to. Anyone on the path could then read and change the traffic. Fix the certificate instead; code that skips checks tends to reach production.

Why some sites have no 'continue anyway' button

Some sites send a header, HSTS, telling browsers to accept only valid HTTPS for them from then on. On those sites a certificate error can't be clicked past at all, which protects visitors from an attacker who presents a fake certificate.

Check yourself

Your API works in the browser, but a server calling it gets 'unable to get local issuer certificate'. What's the likely cause?
A colleague sees certificate errors on every HTTPS site they visit. Everyone else is fine. First thing to check?

In the docs