← Back to Articles
Troubleshooting2026-08-15•4 min read

NET::ERR_CERT_AUTHORITY_INVALID: Complete Fix Guide

· CSR.plus Team

NET::ERR_CERT_AUTHORITY_INVALID: Complete Fix Guide
  • •This error means no trusted CA in the client’s store issued the certificate presented by the server.
  • •The most common real cause is a missing intermediate certificate, not a malicious site.
  • •Fix the server chain, or if you are a visitor, check the date and trust store before assuming the worst.
Chain
Top cause
intermediate not sent
Check date
Visitor fix
clock skew breaks trust
Fullchain
Site owner fix
deploy leaf + intermediate
Self-signed
Also caused by
internal CA, expired root

What the browser is telling you

When Chrome shows NET::ERR_CERT_AUTHORITY_INVALID it could not chain the server’s certificate back to a root in its trust store. The page may still be reachable through "Advanced > Proceed", which is only safe when you are sure the error is a configuration issue, not an attack.

For site owners: fix the server

Fetch the full chain and deploy leaf + intermediates in order (see the incomplete chain guide). Replace any certificate whose root has expired (older SHA-1 era roots still chain-fail on some clients). If you use an internal CA, install its root into the client trust stores and keep the root’s CRL reachable. Never serve a self-signed leaf on a public site.

For visitors: quick checks

Check your system clock (a wrong date breaks every certificate check), try another network, and try a different browser. If the error disappears elsewhere, the issue is local. If it persists everywhere, the site itself is misconfigured — report it to the owner.

FAQ

Is it safe to click "Proceed anyway"?

Only if you are certain the site is legitimate and the certificate problem is a server configuration issue (e.g., you manage the site). On any public site you did not initiate, treat it as a warning and leave.

Does antivirus software cause this error?

Yes. TLS-inspecting antivirus or corporate proxies present their own CA. If the error appears on many sites at once, your AV/proxy certificate or clock is the likely cause.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles