Errors / Network errors
net::ERR_CERT_COMMON_NAME_INVALID
The site's certificate was made for a different address than the one being visited.
The browser refuses the connection.
Why it happens
- A certificate for
example.comserved onwww.example.com(or the other way round), or on a subdomain it does not cover. - A host serving its default certificate because the domain is not configured on it.
- An asset URL pointing at a CDN's hostname the certificate does not cover.
How to fix it
- Issue the certificate for every name the site answers on (both
wwwand the bare domain, or a wildcard). - Add the domain to the host or CDN so it serves the right certificate.
- The certificate's Subject Alternative Name list is what counts, not its common name: Chrome ignores the common name entirely. Open the certificate from the address bar and read that list;
openssl s_client -connect host:443 -servername hostshows which certificate the server picks for a given name, which is where a host serving another site's certificate shows up.
Whose problem it is
Usually the server that answers the request.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- ERR_CERT_AUTHORITY_INVALIDThe site's security certificate was not issued by anyone the browser trusts.
- ERR_CERT_DATE_INVALIDThe site's security certificate has expired.