NET::ERR_CERT_AUTHORITY_INVALID with a Cloudflare Origin Certificate (record not proxied)
Cloudflare Origin CA certificates are only trusted by Cloudflare — visitors reaching the origin directly (grey-cloud record, direct IP, another CDN) see an untrusted certificate.
Seen on:
Cloudflare
Meaning
Origin certificates are designed for the Cloudflare → origin hop. If the DNS record is DNS-only, or a monitoring tool/API client hits the origin directly, browsers and SDKs reject the certificate.
Common causes
- DNS record set to DNS only (grey cloud)
- Clients connecting to the origin IP/hostname directly
- Subdomain not proxied but using the origin cert
- Another CDN in front instead of Cloudflare
⚡ Quick fix
- Turn the record’s proxy on (orange cloud)
- Use a publicly trusted certificate (Let’s Encrypt) for directly accessed hosts
- Point clients to the proxied hostname
Detailed fix by platform
Shell
- bash
openssl s_client -connect origin.example.com:443 -servername origin.example.com </dev/null 2>/dev/null | openssl x509 -noout -issuer # issuer "CloudFlare Origin SSL Certificate Authority" = only trusted by Cloudflare
How to diagnose
- Proxy — Orange or grey cloud?
- Issuer — Origin CA?
- Client — Direct to origin?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Cloudflare
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026