Error [ERR_TLS_CERT_ALTNAME_INVALID]: Hostname/IP does not match certificate's altnames
The server’s certificate doesn’t cover the hostname you connected to.
Seen on:
Node.js
Meaning
Connecting by IP, to an internal alias, or to a different subdomain than the certificate lists (SAN). Wildcards cover one level only.
Common causes
- Connecting by IP address instead of hostname
- Certificate for a different domain/subdomain
- Wildcard not covering nested subdomains
- SNI not sent
⚡ Quick fix
- Use the hostname on the certificate
- Issue a certificate including the needed names
- Set servername for SNI when connecting by IP
Detailed fix by platform
Node.js
tls.connect({ host: ip, servername: 'api.example.com', port: 443 })
How to diagnose
- Names — Certificate SANs vs requested host
- Recent change — Did it start after a deploy, upgrade, or configuration change? Compare with the last working version.
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026