Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date
Kestrel was told to listen on HTTPS but has no certificate — the ASP.NET Core dev certificate is missing/expired, or production didn’t configure one.
Seen on:
.NET
Meaning
In development run dotnet dev-certs https --trust. In containers/production, either terminate TLS at a proxy and listen on HTTP, or configure a certificate (Kestrel:Certificates or ASPNETCORE_Kestrel__Certificates__Default__Path).
Common causes
- Dev certificate not created/trusted or expired
- Docker container with https URLs but no certificate
- Production config expecting a certificate path that doesn’t exist
⚡ Quick fix
- dotnet dev-certs https --clean && dotnet dev-certs https --trust
- In containers listen on http (ASPNETCORE_URLS=http://+:8080) behind a proxy
- Mount and configure a certificate for Kestrel
Detailed fix by platform
Shell
- csharp
dotnet dev-certs https --clean dotnet dev-certs https --trust export ASPNETCORE_URLS=http://+:8080
How to diagnose
- URLs — ASPNETCORE_URLS / launchSettings
- Cert — dev-certs check
- Environment — Dev or container?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026