How to fix "Your connection is not private" on a WordPress site
The browser could not verify your site's security certificate, so it stopped before loading the page. A code on the warning says why. The certificate has expired, was issued for a different name, or comes from an issuer the browser does not trust. Most cases are fixed in your hosting panel.
- By
- WP Ministry
- Published
In short
- The warning is about the site's certificate, not about WordPress. Your content and settings are untouched.
- Check from a second device on another network first. If the site loads there, the fault is on the first device.
- The code on the warning page names the cause, and each cause has its own fix.
- Certificates are renewed and reissued at your host, not inside WordPress.
"Your connection is not private" is Chrome's wording for a warning every browser has. Firefox says "Be careful. Something doesn't look right." Whatever the words, the meaning is the same: the browser asked your site for its security certificate, could not verify it, and stopped before loading anything.
WordPress is not involved. Your posts, pages, orders and settings are untouched, and the site itself is running. What is at risk is every visit. A visitor is stopped at the warning before seeing anything of yours, and until it is fixed nobody can be sure that what they send to the site stays private.
Is it your device or the site?
Open the site on a phone that is using mobile data, not the same Wi-Fi.
- If it loads there, the certificate is fine and the problem is on the first device or its network. Go to the first fix.
- If the warning appears there too, the certificate is at fault. Read the code.
Read the code on the warning
Chrome prints a code on the warning page. In Firefox, select Advanced to see it.
| Chrome | Firefox | What it means | Fix |
|---|---|---|---|
NET::ERR_CERT_DATE_INVALID | SEC_ERROR_EXPIRED_CERTIFICATE | The certificate is outside its dates, or the device's clock is wrong. | Renew the certificate |
NET::ERR_CERT_COMMON_NAME_INVALID | SSL_ERROR_BAD_CERT_DOMAIN | The certificate was issued for a different name. | Cover every name |
NET::ERR_CERT_AUTHORITY_INVALID | SEC_ERROR_UNKNOWN_ISSUER | The browser does not trust the issuer. | Install a trusted certificate |
Where it goes wrong
A page request passes through each of these in turn. This one comes from the secure connection (HTTPS).
- Browser
- DNS
- HTTPS (this error comes from here)
- CDN or firewall
- Web server
- PHP
- WordPress
- Database and files
What causes it
The certificate has expired
CommonEvery certificate has an end date. Most are renewed by an automatic job at the host, and when that job fails nothing looks wrong until the day the certificate runs out.
The certificate does not cover the address being visited
CommonA certificate is valid only for the names written in it. The address with www and the one without are two names, and a subdomain is a third. A moved site can also be answered by a server that holds a certificate for some other name.
The browser does not trust who issued the certificate
SometimesThe server is presenting a certificate it made for itself, or a real one without the intermediate certificates that link it to an authority browsers know.
Fix: Install a certificate browsers trust, with its full chain
The fault is on the visitor's device or network
SometimesA wrong date and time on the device, security software that inspects encrypted traffic, or a public Wi-Fi network that wants a sign-in first can each produce the warning on a site whose certificate is sound.
How to fix it
Rule out your own device and network
- Easy
- No risk
- About 5 minutes
Do this when the site loads on other devices, or when Chrome says "Your clock is behind" or "Your clock is ahead".
Step 1: Check the date and time
Open the device's clock settings and correct the date, time and time zone. A certificate is valid between two dates, so a device with the wrong date judges it wrongly.
Step 2: Sign in to the Wi-Fi network
On public Wi-Fi, such as in a cafe or an airport, the network may be holding every request until you sign in. Open its sign-in page, sign in, and try again.
Step 3: Open the site in a private window
If it loads there, a browser extension is interfering. Turn extensions off one at a time to find it.
Step 4: Look at your security software
Antivirus software that scans encrypted traffic, a feature often named HTTPS scanning, puts its own certificate in place of the site's. Turn that feature off for a moment and reload. On a work computer, ask the administrator instead.
Renew the certificate
- Easy
- No risk
- About 15 minutes
Step 1: Open the certificate section of your hosting panel
It is usually named SSL, SSL/TLS or Security. Find your domain and read the date its certificate expires.
Step 2: Renew or reissue it
If the host issued the certificate, the same page has a button to renew or reissue it. Use it and wait a few minutes. A certificate you bought elsewhere is renewed where you bought it, and the new files are then installed on this page.
Step 3: If the renewal fails, check what the issuer needs
Free certificates from Let's Encrypt, which many hosts use and which last 90 days by default, are usually issued after the issuer fetches a file from
http://example.com/.well-known/acme-challenge/on your site, with your own domain in place ofexample.com. The renewal fails when:- the domain's DNS points somewhere other than this hosting account, for example after a move;
- a rule in
.htaccess, a security plugin or a password on the whole site blocks that folder; - the site does not answer over plain http on port 80.
Fix what applies and renew again. If you cannot see why it fails, send your host the error the panel shows.
Step 4: Reload the site in a private window
The warning goes as soon as the new certificate is in place.
Reissue the certificate to cover every name
- Takes care
- No risk
- About 20 minutes
Step 1: Note the exact address that shows the warning
Try
https://example.comandhttps://www.example.comwith your own domain, and any subdomain you use, such asshop.example.com.Step 2: See which names the certificate lists
The certificate section of your hosting panel shows them. A name that warns and is not on the list is the cause.
Step 3: Reissue the certificate with every name on it
One certificate can hold several names. Reissue it with both the plain domain and the www form, and each subdomain visitors use.
Step 4: If the right names are already listed
Then the visitor is not reaching this server. Check that the DNS records for every one of those names point at this hosting account. A name that still points at an old host is answered with the old host's certificate.
Install a certificate browsers trust, with its full chain
- Takes care
- No risk
- About 20 minutes
Step 1: Find out who issued the certificate
Your hosting panel shows the issuer. If the certificate is described as self-signed, or the issuer is the server itself, no certificate authority has ever vouched for it.
Step 2: Replace a self-signed certificate
Issue a certificate for the domain from the same page. Until one has been issued, the server answers with a stand-in that no browser trusts.
Step 3: Complete the chain of a certificate you installed by hand
A certificate authority supplies your certificate together with one or more intermediate certificates, often in a file called a CA bundle or chain. Install the certificate again with the intermediates included. Firefox's own explanation of
SEC_ERROR_UNKNOWN_ISSUERnames this case: the server might not be sending the appropriate intermediate certificates.
When to get help
If your hosting panel shows a valid certificate that lists the exact name you are visiting and the warning is still there, something else is answering for your domain, such as a proxy or content delivery network in front of the site, or DNS that still points at an old server. Finding which takes access to DNS and the server.
Common questions
Can visitors click past the warning?
Most browsers offer a way to continue, behind the Advanced button. A visitor should not have to, and many will not. Treat the warning as the site being down.
Why did it appear overnight when nothing changed?
Because a date passed. A certificate that was valid yesterday is refused the moment it expires, and an automatic renewal that fails does so quietly.
The page loads but the padlock is missing. Is that the same thing?
No. A full-page warning is about the certificate. A page that loads without its padlock is fetching something over plain http. See how to fix mixed content.
Does this affect payments in my store?
It can. Customers are stopped at the warning, and a payment provider may refuse to send your store its payment confirmations while the certificate is invalid, which leaves paid orders marked unpaid. See WooCommerce payment gateway errors.
- GuideLocked out of WordPress admin: find which lockout you have and get back in
- GuideSlow WordPress admin: how to find the cause and fix it
- ResourceWooCommerce checkout is down: a runbook
- GuideWordPress site not showing up on Google: what to check, in order
- Guideadmin-ajax.php high CPU usage in WordPress: how to find what is calling it
- GuideHow to change WordPress permalinks without breaking your old links

