HttpRequestException: The SSL connection could not be established, see inner exception. (AuthenticationException: The remote certificate is invalid)
HttpClient couldn’t complete the TLS handshake — untrusted/self-signed certificate, name mismatch, expired certificate, or TLS version mismatch.
Seen on:
.NET
Meaning
The inner exception names the reason (RemoteCertificateNameMismatch, RemoteCertificateChainErrors). Corporate proxies, internal CAs not trusted in containers (Linux), and dev certificates are common.
Common causes
- Self-signed or internal CA certificate not trusted
- Host name doesn’t match certificate
- Expired certificate
- Container missing CA certificates
⚡ Quick fix
- Install the CA certificate into the OS/container trust store
- Call the hostname on the certificate
- Avoid disabling validation outside development
Detailed fix by platform
Dockerfile
- csharp
COPY company-ca.crt /usr/local/share/ca-certificates/ RUN update-ca-certificates
How to diagnose
- Inner — Chain or name error?
- Certificate — openssl s_client output
- Environment — Container trust store
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 8 Oct 2026