NET::ERR_CERT_COMMON_NAME_INVALID: Your connection is not private (certificate is for a different domain)
The certificate presented doesn’t include the hostname you visited — e.g. visiting www.example.com with a certificate only for example.com, or hitting the wrong virtual host.
Seen on:
OpenSSL
Meaning
Browsers check the certificate’s Subject Alternative Names. Missing www/subdomains, default vhost certificates being served (SNI misconfiguration), or IP-based access cause this.
Common causes
- Certificate lacks the hostname (www, subdomain)
- Server serves the default vhost’s certificate (SNI/vhost config)
- Visiting by IP or internal name
- CDN/hosting custom domain not added
⚡ Quick fix
- Reissue the certificate including all names (-d example.com -d www.example.com)
- Fix the vhost server_name/ServerName for this host
- Redirect alternate names to a covered host
Detailed fix by platform
Shell
openssl s_client -connect example.com:443 -servername www.example.com </dev/null 2>/dev/null | openssl x509 -noout -ext subjectAltName
How to diagnose
- SAN — Names in the certificate
- Vhost — Which server block answers
- Host — Exact hostname used
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 526 Cloudflare Error 526: Invalid SSL Certificate
- Challenge failed for domain Let’s Encrypt / Certbot: Challenge failed for domain example.com — Invalid response from http://example.com/.well-known/acme-challenge/x: 404
- doesn't include signing certificate Provisioning profile "x" doesn't include signing certificate "Apple Development: Name (ID)"
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026