"Your connection is not private": certificate errors explained
The browser could not verify the site's security certificate, so it stopped before loading the page. Check the code underneath: a date error often means your device clock is wrong, while an authority error often points to public Wi-Fi sign-in, antivirus scanning or a work proxy.
A "Your connection is not private" page means your browser could not confirm that the site is who it claims to be, so it stopped before loading anything. Google's Chrome help says the cause can be the site, the network or your device. The short code under the message, such as NET::ERR_CERT_DATE_INVALID, tells you which is most likely.
What a certificate does
When you open a page starting with https://, the site presents a digital certificate. Your browser checks three things: that a trusted authority issued it, that it was issued for the exact name in the address bar, and that it is within its valid dates. If any check fails, the browser shows a warning instead of the page. The warning is there because, without those checks, someone on the same network could pretend to be the site and read what you send.
The common error codes and what they point to
Chrome groups these under certificate errors. The code tells you which check failed:
NET::ERR_CERT_DATE_INVALID, "Your clock is behind" or "Your clock is ahead": Chrome's help says this can happen if your device's date and time are inaccurate. It can also mean the site's certificate has expired.
NET::ERR_CERT_AUTHORITY_INVALID: the certificate was not issued by an authority your device trusts. Common causes are a site using a self-made certificate, a public Wi-Fi sign-in page, security software that inspects secure traffic, or a work network proxy.
ERR_CERT_COMMON_NAME_INVALID: the certificate is for a different name than the one you typed, for example one that covers www.northgate.example but not shop.northgate.example.
Other browsers use different wording for the same checks, but the categories match: who issued it, which name it covers and whether it is in date.
Fixes that are on your side
Chrome's help page suggests these steps. Work through them in order:
Check your clock. Open your device's date and time settings and make sure the date, time and time zone are correct. Turning on automatic time usually does this.
Sign in to the Wi-Fi portal. At cafes, hotels or airports, you may need to sign in first. Chrome suggests going to any page that starts with http://, such as http://example.com, to bring up the sign-in page.
Try an Incognito window. If the page opens there, an extension may be the cause. Turn extensions off one at a time to find it.
Update your operating system, whether Windows, macOS or your phone's system.
Check your antivirus. Chrome notes that antivirus software with "HTTPS protection" or "HTTPS scanning" can cause these errors. You can test by turning that feature off briefly, and remember to turn it back on.
On a work computer, Chrome says proxies that inspect secure traffic can trigger NET::ERR_CERT_AUTHORITY_INVALID when a needed certificate is missing. Contact your IT team. Chrome advises against installing certificates yourself, calling it usually a security risk.
When the problem is the site
If the error appears on every device and network you try, and your clock is right, the site's certificate is probably expired, misconfigured or issued for another name. Only the site owner can fix that. Contact them through another channel, such as a phone number from a bill or an email you already have, and tell them the exact error code and the address.
Should you click through the warning?
Browsers usually offer an option to continue anyway. Chrome's help on site security says that when a connection is marked not secure, you should not enter private or personal information, and, if possible, not use the site. Never type passwords, card numbers or account details on a page reached this way. Bank, government, health or shopping sites should not show certificate errors; if one does, stop and contact the organization directly.
For developers and command-line tools
Command-line tools report the same failures in their own words. These samples are synthetic, from a fictional Northgate API:
curl: (60) SSL certificate problem: certificate has expired
Error: unable to verify the first certificate
SSLCertVerificationError: certificate verify failed: unable to get local issuer certificate
curl's documentation says error 60 means "the remote server's SSL certificate or SSH fingerprint was deemed not OK", and error 35 means a problem somewhere in the TLS handshake. "Unable to get local issuer certificate" means the tool could not trace the certificate back to an authority it trusts. The fix is in the server's certificate setup or the tool's trust settings. Turning verification off removes the protection the check exists for.
Information to collect before you ask for help
The full error code and the exact address.
Your device's date, time and time zone.
Which network you were on, and whether a VPN or antivirus was running.
Whether it happens in another browser, on another device or on mobile data.
For a server you run, the output of the failing command, with any keys or tokens removed. Our guide on sharing logs safely covers that.
If you saw a status number such as 502 instead, the connection worked and the server failed; our guide to HTTP status codes explains those.
Get the warning explained in plain English
EasyToDecode is launching soon. You will be able to upload a screenshot of the warning or paste the error from a tool, and it will quote the code that matters, explain which check failed, flag what is missing and list what to try first and what to ask the site owner or IT team. See how it works or join the waitlist to hear when it opens.
Questions
Why does every site say "Your connection is not private"?
If it happens everywhere, look at your side first: a wrong device clock, a Wi-Fi network waiting for sign-in, or antivirus software that scans secure traffic.
How do I fix NET::ERR_CERT_DATE_INVALID?
Chrome's help says to check that your device's date and time are correct. If they are, the site's certificate may have expired, and only the owner can renew it.
Is it safe to proceed past a certificate warning?
Chrome advises not entering private or personal information on a connection marked not secure. Never enter passwords or payment details on a page reached past a warning.
What does curl error 60 mean?
curl's documentation says the remote server's certificate was "deemed not OK", for example because it expired or its issuer is not trusted.
Sources
- Google Chrome Help: Get help with common error messages in Chrome (checked October 10, 2026)
- Google Chrome Help: Check if a site's connection is secure (checked October 10, 2026)
- curl: libcurl error codes (checked October 10, 2026)
About this guide. Prepared by the EasyToDecode editorial team. Facts were checked against the official sources listed above (last checked October 10, 2026).
How we prepare and check our guides
General information, not legal, financial or tax advice. Rules differ by state, province and territory and change over time; check the sources and, for decisions with legal or financial consequences, a qualified professional.