Skip to content

TLS and HTTPS

TLS certificate errors: expired, untrusted or for the wrong name

Whether the certificate the server presents is in date, chains to a publicly trusted certificate authority and covers the hostname that was requested.

Part of the External Security Check. Free during the preview.

What it checks

Whether the certificate the server presents is in date, chains to a publicly trusted certificate authority and covers the hostname that was requested.

A pass means: The certificate is trusted, in date and covers the hostname.

Possible findings

Certificate has expired

Severity: HighConfidence: ConfirmedKind: Security issue

What we found

The certificate presented has passed its expiry date.

Why it matters

Browsers show a full-page warning and most visitors leave. Automated clients refuse to connect.

How to fix it

Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.

Certificate is not yet valid

Severity: HighConfidence: ConfirmedKind: Security issue

What we found

The certificate presented has a start date in the future.

Why it matters

Browsers reject the certificate until its start date, so visitors see a warning.

How to fix it

Check the server's clock and the certificate's validity dates, and install a certificate that is valid now.

Certificate is not trusted

Severity: HighConfidence: ConfirmedKind: Security issue

What we found

The certificate chain does not lead to a publicly trusted certificate authority.

Why it matters

Browsers show a warning, and visitors cannot tell your site from an impostor. A common cause is a self-signed certificate or a missing intermediate certificate.

How to fix it

Install a certificate from a public certificate authority, and configure the server to send the full chain (your certificate plus intermediates).

Certificate does not cover this hostname

Severity: HighConfidence: ConfirmedKind: Security issue

What we found

The certificate presented is not valid for the hostname that was requested.

Why it matters

Browsers show a warning because the certificate was issued for a different name.

How to fix it

Issue a certificate whose subject alternative names include this hostname, or a wildcard that covers it, and install it.

References