The SSL connection could not be established 🟪 .NET

HttpRequestException: The SSL connection could not be established, see inner exception. (AuthenticationException: The remote certificate is invalid)

HttpClient couldn’t complete the TLS handshake — untrusted/self-signed certificate, name mismatch, expired certificate, or TLS version mismatch.

Seen on: .NET

Meaning

The inner exception names the reason (RemoteCertificateNameMismatch, RemoteCertificateChainErrors). Corporate proxies, internal CAs not trusted in containers (Linux), and dev certificates are common.

Common causes

  • Self-signed or internal CA certificate not trusted
  • Host name doesn’t match certificate
  • Expired certificate
  • Container missing CA certificates

⚡ Quick fix

  1. Install the CA certificate into the OS/container trust store
  2. Call the hostname on the certificate
  3. Avoid disabling validation outside development

Detailed fix by platform

Dockerfile

  1. csharp
    COPY company-ca.crt /usr/local/share/ca-certificates/
    RUN update-ca-certificates

How to diagnose

  1. Inner — Chain or name error?
  2. Certificate — openssl s_client output
  3. Environment — Container trust store

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.