Common SSL Errors
· CSR.plus Team

- •Certificate expired, hostname mismatch and incomplete chains cause the majority of browser warnings.
- •Mixed content is a page-level problem: resources loaded over HTTP inside an HTTPS page.
- •Use our SSL Checker to see exactly which error your certificate triggers before you change anything.
Expired certificate
The most common error. Check the dates with our Certificate Inspector, then renew and install the new certificate. With 90-day certificates, automate renewal through an ACME client — manual renewals are the main reason certificates expire.
Hostname mismatch
"Certificate name does not match" appears when the certificate covers a different domain than the one requested. Fix it by issuing a certificate for the exact hostname, or add the name as a SAN. A wildcard certificate can also cover several subdomains at once.
Incomplete chain / untrusted issuer
The server sent only the leaf certificate, or an intermediate is missing, so clients cannot build a path to a trusted root. Install the full chain: leaf plus intermediate, in the correct order. Our SSL Checker validates the chain and tells you exactly which link is broken.
Mixed content
An HTTPS page that loads scripts, styles or images over HTTP triggers the padlock warning. Browsers may block the request entirely. Audit the page for http:// references, switch them to https:// or protocol-relative URLs, and re-test with the browser console.
Handshake and protocol errors
TLS handshake failures usually come from mismatched protocol versions or cipher suites: an old client negotiating against a strict modern server, or vice versa. Keep TLS 1.2 and TLS 1.3 enabled with modern ciphers, and use the SSL/TLS Tracer to see the exact negotiation failure.
FAQ
Why does my site show an error on some devices but not others?
Different clients support different TLS versions and ciphers. Old devices often fail against modern-only configurations — check the handshake with the SSL/TLS Tracer.
How do I fix mixed content quickly?
Search the HTML for http:// resource URLs and change them to https://. Content Security Policy upgrade-insecure-requests can also auto-upgrade them in modern browsers.
Will our SSL Checker detect all these problems?
It checks expiry, chain completeness, hostname coverage, protocol versions and key match — the common causes of warnings — and points you to the exact failure.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.