Error Reference › SSL / DNS
SSL / DNS

Certificate authority invalid / self-signed

The browser/client doesn't trust the certificate's issuer — it's self-signed or the chain is incomplete.

What it looks like

NET::ERR_CERT_AUTHORITY_INVALID
curl: (60) SSL certificate problem: unable to get local issuer certificate

What does "Certificate authority invalid / self-signed" mean?

Shown when the client cannot build a chain from the site’s certificate to a certificate authority it trusts. Browsers show a full-page warning; curl, Node and other clients refuse the connection outright.

What causes "Certificate authority invalid / self-signed"?

  • A self-signed certificate in production.
  • The intermediate/chain certificate isn't served.
  • An internal CA not trusted by the client.

How do I confirm the cause?

  1. Run openssl s_client -connect example.com:443 -servername example.com -showcerts and count the certificates sent — one usually means the intermediate is missing.
  2. Check whether the certificate is self-signed: its issuer is the same as its subject.
  3. If it fails in one client only (a server-side script, an old phone), that client’s trusted CA list may be out of date.

How do I fix "Certificate authority invalid / self-signed"?

  • Use a cert from a trusted CA (e.g. Let's Encrypt).
  • Serve the full chain (cert + intermediates).
  • For internal CAs, install the CA on clients.

How do I stop it happening again?

  • Install the full chain file (fullchain.pem for Let’s Encrypt), not just the site certificate.
  • Use certificates from a public CA on anything visitors reach; keep self-signed ones for local development.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors