Ffile2fix
Sign in Get started

Fix SSL certificate name mismatch (NET::ERR_CERT_COMMON_NAME_INVALID)

Your connection is not private
This server could not prove that it is www.example.com; its security certificate is from example.com.
NET::ERR_CERT_COMMON_NAME_INVALID

The certificate the server presented is valid, but the hostname in the address bar is not in its Subject Alternative Name (SAN) list. Either issue a certificate that covers every hostname you use (for example both example.com and www.example.com) or fix the server so the right certificate is sent for that name.

Also appears as: Warning: Potential Security Risk Ahead. SSL_ERROR_BAD_CERT_DOMAIN · curl: (60) SSL: no alternative certificate subject name matches target host name 'www.example.com' · Hostname/IP does not match certificate's altnames: Host: www.example.com. is not in the cert's altnames: DNS:example.com · certificate verify failed: Hostname mismatch, certificate is not valid for 'www.example.com'

Common causes

  • The certificate covers example.com but not www.example.com, or the reverse
  • The request hits the default virtual host, which serves another site's certificate
  • DNS points the hostname at a server or CDN that has no certificate for it
  • A wildcard *.example.com is used for the bare domain or a deeper level like a.b.example.com
  • Visiting the server by IP address or an internal hostname not on the certificate
  • Shared hosting serving the host's own certificate because SSL was never installed for the domain

How to fix it

  1. See which names the certificate covers. Run echo | openssl s_client -connect example.com:443 -servername www.example.com 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName. The hostname you visit must appear in the DNS: list.
  2. Issue a certificate for all names. With Certbot run sudo certbot --nginx -d example.com -d www.example.com (or --apache). On cPanel, make sure both names are included and run AutoSSL.
  3. Make sure the right vhost answers. Check that server_name (Nginx) or ServerName/ServerAlias (Apache) on the port 443 block includes the hostname. Otherwise the default server's certificate is sent.
  4. Check DNS and CDN. Confirm with dig +short www.example.com that the name points where the certificate is installed. On a CDN, add the hostname to the edge certificate.
  5. Redirect extra names after HTTPS works. A redirect from www to non-www over HTTPS still needs a certificate for www, because the TLS handshake happens before the redirect.

Shell (Certbot + inspection)

echo | openssl s_client -connect example.com:443 -servername www.example.com 2>/dev/null \
  | openssl x509 -noout -subject -ext subjectAltName

sudo certbot --nginx -d example.com -d www.example.com

How to stop it happening again

  • Always include both bare and www names when issuing certificates
  • Add new subdomains to the certificate before pointing DNS at the server
  • Give each site an explicit server_name or ServerAlias on port 443
  • Monitor every public hostname with a certificate check, not just the main one

Frequently asked questions

Does the Common Name still matter?

Browsers ignore the CN and check only the Subject Alternative Name list. A certificate with the right CN but missing SAN entry will still fail.

Does *.example.com cover example.com?

No. A wildcard covers exactly one label, such as www.example.com or shop.example.com, but not the bare domain or a.b.example.com. Add the bare domain as a separate name.

Can I fix it with a redirect?

No. The browser validates the certificate before it receives any redirect, so the hostname being redirected must also be covered by a certificate.