Skip to content

How to fix "Your connection is not private" on a WordPress site

The browser could not verify your site's security certificate, so it stopped before loading the page. A code on the warning says why. The certificate has expired, was issued for a different name, or comes from an issuer the browser does not trust. Most cases are fixed in your hosting panel.

By
WP Ministry
Published

In short

  • The warning is about the site's certificate, not about WordPress. Your content and settings are untouched.
  • Check from a second device on another network first. If the site loads there, the fault is on the first device.
  • The code on the warning page names the cause, and each cause has its own fix.
  • Certificates are renewed and reissued at your host, not inside WordPress.

"Your connection is not private" is Chrome's wording for a warning every browser has. Firefox says "Be careful. Something doesn't look right." Whatever the words, the meaning is the same: the browser asked your site for its security certificate, could not verify it, and stopped before loading anything.

WordPress is not involved. Your posts, pages, orders and settings are untouched, and the site itself is running. What is at risk is every visit. A visitor is stopped at the warning before seeing anything of yours, and until it is fixed nobody can be sure that what they send to the site stays private.

Is it your device or the site?

Open the site on a phone that is using mobile data, not the same Wi-Fi.

  • If it loads there, the certificate is fine and the problem is on the first device or its network. Go to the first fix.
  • If the warning appears there too, the certificate is at fault. Read the code.

Read the code on the warning

Chrome prints a code on the warning page. In Firefox, select Advanced to see it.

ChromeFirefoxWhat it meansFix
NET::ERR_CERT_DATE_INVALIDSEC_ERROR_EXPIRED_CERTIFICATEThe certificate is outside its dates, or the device's clock is wrong.Renew the certificate
NET::ERR_CERT_COMMON_NAME_INVALIDSSL_ERROR_BAD_CERT_DOMAINThe certificate was issued for a different name.Cover every name
NET::ERR_CERT_AUTHORITY_INVALIDSEC_ERROR_UNKNOWN_ISSUERThe browser does not trust the issuer.Install a trusted certificate

Where it goes wrong

A page request passes through each of these in turn. This one comes from the secure connection (HTTPS).

  1. Browser
  2. DNS
  3. HTTPS (this error comes from here)
  4. CDN or firewall
  5. Web server
  6. PHP
  7. WordPress
  8. Database and files

What causes it

  • The certificate has expired

    Common

    Every certificate has an end date. Most are renewed by an automatic job at the host, and when that job fails nothing looks wrong until the day the certificate runs out.

    Fix: Renew the certificate

  • The certificate does not cover the address being visited

    Common

    A certificate is valid only for the names written in it. The address with www and the one without are two names, and a subdomain is a third. A moved site can also be answered by a server that holds a certificate for some other name.

    Fix: Reissue the certificate to cover every name

  • The browser does not trust who issued the certificate

    Sometimes

    The server is presenting a certificate it made for itself, or a real one without the intermediate certificates that link it to an authority browsers know.

    Fix: Install a certificate browsers trust, with its full chain

  • The fault is on the visitor's device or network

    Sometimes

    A wrong date and time on the device, security software that inspects encrypted traffic, or a public Wi-Fi network that wants a sign-in first can each produce the warning on a site whose certificate is sound.

    Fix: Rule out your own device and network

How to fix it

Rule out your own device and network

  • Easy
  • No risk
  • About 5 minutes

Do this when the site loads on other devices, or when Chrome says "Your clock is behind" or "Your clock is ahead".

  1. Step 1: Check the date and time

    Open the device's clock settings and correct the date, time and time zone. A certificate is valid between two dates, so a device with the wrong date judges it wrongly.

  2. Step 2: Sign in to the Wi-Fi network

    On public Wi-Fi, such as in a cafe or an airport, the network may be holding every request until you sign in. Open its sign-in page, sign in, and try again.

  3. Step 3: Open the site in a private window

    If it loads there, a browser extension is interfering. Turn extensions off one at a time to find it.

  4. Step 4: Look at your security software

    Antivirus software that scans encrypted traffic, a feature often named HTTPS scanning, puts its own certificate in place of the site's. Turn that feature off for a moment and reload. On a work computer, ask the administrator instead.

Renew the certificate

  • Easy
  • No risk
  • About 15 minutes
  1. Step 1: Open the certificate section of your hosting panel

    It is usually named SSL, SSL/TLS or Security. Find your domain and read the date its certificate expires.

  2. Step 2: Renew or reissue it

    If the host issued the certificate, the same page has a button to renew or reissue it. Use it and wait a few minutes. A certificate you bought elsewhere is renewed where you bought it, and the new files are then installed on this page.

  3. Step 3: If the renewal fails, check what the issuer needs

    Free certificates from Let's Encrypt, which many hosts use and which last 90 days by default, are usually issued after the issuer fetches a file from http://example.com/.well-known/acme-challenge/ on your site, with your own domain in place of example.com. The renewal fails when:

    • the domain's DNS points somewhere other than this hosting account, for example after a move;
    • a rule in .htaccess, a security plugin or a password on the whole site blocks that folder;
    • the site does not answer over plain http on port 80.

    Fix what applies and renew again. If you cannot see why it fails, send your host the error the panel shows.

  4. Step 4: Reload the site in a private window

    The warning goes as soon as the new certificate is in place.

Reissue the certificate to cover every name

  • Takes care
  • No risk
  • About 20 minutes
  1. Step 1: Note the exact address that shows the warning

    Try https://example.com and https://www.example.com with your own domain, and any subdomain you use, such as shop.example.com.

  2. Step 2: See which names the certificate lists

    The certificate section of your hosting panel shows them. A name that warns and is not on the list is the cause.

  3. Step 3: Reissue the certificate with every name on it

    One certificate can hold several names. Reissue it with both the plain domain and the www form, and each subdomain visitors use.

  4. Step 4: If the right names are already listed

    Then the visitor is not reaching this server. Check that the DNS records for every one of those names point at this hosting account. A name that still points at an old host is answered with the old host's certificate.

Install a certificate browsers trust, with its full chain

  • Takes care
  • No risk
  • About 20 minutes
  1. Step 1: Find out who issued the certificate

    Your hosting panel shows the issuer. If the certificate is described as self-signed, or the issuer is the server itself, no certificate authority has ever vouched for it.

  2. Step 2: Replace a self-signed certificate

    Issue a certificate for the domain from the same page. Until one has been issued, the server answers with a stand-in that no browser trusts.

  3. Step 3: Complete the chain of a certificate you installed by hand

    A certificate authority supplies your certificate together with one or more intermediate certificates, often in a file called a CA bundle or chain. Install the certificate again with the intermediates included. Firefox's own explanation of SEC_ERROR_UNKNOWN_ISSUER names this case: the server might not be sending the appropriate intermediate certificates.

When to get help

If your hosting panel shows a valid certificate that lists the exact name you are visiting and the warning is still there, something else is answering for your domain, such as a proxy or content delivery network in front of the site, or DNS that still points at an old server. Finding which takes access to DNS and the server.

Common questions

Can visitors click past the warning?

Most browsers offer a way to continue, behind the Advanced button. A visitor should not have to, and many will not. Treat the warning as the site being down.

Why did it appear overnight when nothing changed?

Because a date passed. A certificate that was valid yesterday is refused the moment it expires, and an automatic renewal that fails does so quietly.

The page loads but the padlock is missing. Is that the same thing?

No. A full-page warning is about the certificate. A page that loads without its padlock is fetching something over plain http. See how to fix mixed content.

Does this affect payments in my store?

It can. Customers are stopped at the warning, and a payment provider may refuse to send your store its payment confirmations while the certificate is invalid, which leaves paid orders marked unpaid. See WooCommerce payment gateway errors.

More on this subject

Would you rather we fixed it?

Emergency Fix is $99. Site down or checkout broken. Goes to the front of the queue. No fix, no fee. 30-day warranty. It starts with a free diagnosis.