Error Reference › SSL / DNS
SSL / DNS
Certificate authority invalid / self-signed
The browser/client doesn't trust the certificate's issuer — it's self-signed or the chain is incomplete.
What it looks like
NET::ERR_CERT_AUTHORITY_INVALID
curl: (60) SSL certificate problem: unable to get local issuer certificate
What does "Certificate authority invalid / self-signed" mean?
Shown when the client cannot build a chain from the site’s certificate to a certificate authority it trusts. Browsers show a full-page warning; curl, Node and other clients refuse the connection outright.
What causes "Certificate authority invalid / self-signed"?
- A self-signed certificate in production.
- The intermediate/chain certificate isn't served.
- An internal CA not trusted by the client.
How do I confirm the cause?
- Run openssl s_client -connect example.com:443 -servername example.com -showcerts and count the certificates sent — one usually means the intermediate is missing.
- Check whether the certificate is self-signed: its issuer is the same as its subject.
- If it fails in one client only (a server-side script, an old phone), that client’s trusted CA list may be out of date.
How do I fix "Certificate authority invalid / self-signed"?
- Use a cert from a trusted CA (e.g. Let's Encrypt).
- Serve the full chain (cert + intermediates).
- For internal CAs, install the CA on clients.
How do I stop it happening again?
- Install the full chain file (fullchain.pem for Let’s Encrypt), not just the site certificate.
- Use certificates from a public CA on anything visitors reach; keep self-signed ones for local development.