Error Reference › SSL / DNS
SSL / DNS

Certificate hostname mismatch

The certificate is valid but isn't issued for the hostname you're visiting.

What it looks like

NET::ERR_CERT_COMMON_NAME_INVALID
curl: (60) SSL: no alternative certificate subject name matches target host name 'www.example.com'

What does "Certificate hostname mismatch" mean?

Shown when the certificate is valid and trusted but was not issued for the name in the address bar. Browsers check the certificate’s Subject Alternative Names (SANs) — www and non-www count as different names.

What causes "Certificate hostname mismatch"?

  • Cert is for a different domain/subdomain.
  • Missing www / wrong SAN entry.
  • Wrong cert installed on the vhost.

How do I confirm the cause?

  1. List the names the certificate covers: openssl s_client -connect host:443 -servername host | openssl x509 -noout -ext subjectAltName.
  2. Check which virtual host answered — a server hosting several sites may be sending another site’s certificate.
  3. Remember a wildcard (*.example.com) covers one level only: it matches www.example.com but not example.com or a.b.example.com.

How do I fix "Certificate hostname mismatch"?

  • Issue/replace the cert to include the exact hostname (SAN).
  • Use a wildcard or add the subdomain.
  • Confirm the right cert is on the right virtual host.

How do I stop it happening again?

  • Request certificates that list every name you serve (example.com and www.example.com).
  • Redirect the names you do not want to the main one — after the TLS handshake, which the certificate must still cover.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors