HTTPS certificate-chain warning and recurring 502 on static HTML – baukompetenzzentrum.org

Website URL

https://baukompetenzzentrum.org/ratgeber-feuchte-kellerwand.html

Error Message

Visitor: 502 Bad Gateway / openresty.
Separate cloud-browser HTTPS checks: 502 — Certificate verify failed: unable to get local issuer certificate.
Google Ads destination rejection: Unknown DNS error, platform iOS (Google test time unknown).

Other Information

Website: https://baukompetenzzentrum.org/ratgeber-feuchte-kellerwand.html
Server IP shown in the hosting panel: 185.27.134.153

On 6 October 2026, a visitor using Firefox Private Mode observed:

  • Around 17:59 UTC (19:59 Vienna): the page loaded successfully; the address ended in ?i=1.
  • Around 18:01 UTC (20:01 Vienna): the original URL without a query parameter returned “502 Bad Gateway” / “openresty”.
    We cannot establish that the parameter caused this difference. We also cannot establish that the browser and external test failures share the same cause.

Checks in the hosting panel:

  • Account Active; domain directory baukompetenzzentrum.org/htdocs; Health Check reports “No issues found”.
  • The exact static HTML target exists (14.49 KB). No PHP execution is required for this HTML page.
  • Disk usage 146 MB / 5 GB; inode usage 9829 / 80000; today’s hits 402 / 50000. Available daily charts do not cover the incident time and cannot rule out a temporary resource spike.
  • SSL is Active and installed: Let’s Encrypt, expires 30 December 2026.
  • The root .htaccess has HTTPS forwarding and W3 Total Cache rules. However, wp-content/cache/page_enhanced contains only a .htaccess and no cached pages. The WordPress fallback excludes existing files.
  • An independent SSLShopper check resolves the domain to the correct IP and confirms the hostname, but warns that the certificate is not trusted by all browsers / may require an intermediate chain. A separate external HTTPS request reports “Certificate verify failed: unable to get local issuer certificate”.
  • Google Ads rejected this landing page with “Unknown DNS error”, platform iOS. Google’s test time is unknown, so we cannot correlate it with the browser failure.

Could you investigate the recurring openresty 502 for this static page and advise whether an upstream/server issue, a temporary account limit, or HTTPS-chain compatibility is involved? Which diagnostics should we collect at the next occurrence? No DNS, SSL or .htaccess changes were made during this investigation.

Thank you.

Update, 7 October 2026:

  • Hosting SSL/TLS panel freshly confirms Live: Active and Installed: SSL certificate is installed; Let’s Encrypt, expiry 2026-12-30.
  • SSLShopper again reports IP 185.27.134.153, server openresty, correct hostname, validity 2026-10-01 to 2026-12-30, issuer YR2, and an untrusted-chain warning. SSLShopper may cache results for up to a day.
  • Seven additional static guides, index and sitemap have now been uploaded and all nine files independently downloaded and byte-compared: identical.
  • Cloud-browser checks of the homepage and a newly uploaded guide still return 502 with the explicit message: Certificate verify failed: unable to get local issuer certificate. We do not assume that this is the same failure as the visitor’s plain openresty 502.
  • Your documentation states that CA-chain installation is unsupported on Free Hosting. What supported solution can provide a verifiable HTTPS chain for automated visitors and Google Ads destination checks on this existing account? Please distinguish this from the recurring visitor-facing 502.
  • No certificate replacement, DNS change, security bypass or Ads modification was performed.

Welcome to the InfinityFree community forum! Good to have you here.

  • Most people answering here are volunteers. They’re often the fastest source of help. Admin (the only staff member) checks in about once a day for issues on our end.
  • Volunteers can’t see your account or website. Share what you actually see, like error messages and what happens when you try something. That’s more useful than your theory of what’s wrong.
  • AI tools often get InfinityFree wrong. If a volunteer’s advice differs from what an AI told you, please try the volunteer’s suggestion first.
  • Solving an issue is a joint effort. Try the suggestions you get and report back what happened.

Beep boop, I’m a bot! I dug through the forum to get you started. I sometimes get things wrong though, so do with this what you will until a human has a look.

I couldn’t find an article or answered topic that says what causes an intermittent openresty 502 on a static page, or how to get a verifiable certificate chain on an existing account. So I can’t tell you which of the three causes you list is involved. I also didn’t find the documentation passage you mention about CA-chain installation.

One check would help separate the two problems. Does the 502 also happen on the free subdomain on the same account (the one under free.nf), or only on baukompetenzzentrum.org? If it only happens on the custom domain, that points toward the domain or its certificate. If it happens on both, it’s more likely not specific to your HTTPS setup.

It would also help to know what a normal desktop browser shows when you open the HTTPS site. Does it show a certificate warning, or does the page just load or 502? That tells us whether the “unable to get local issuer certificate” message comes from those checking tools or from real browsers too.

Another recent topic describes the same openresty 502 symptom on a different site, but it has no answer yet, so I can’t say whether the cause is the same:

Your account and files look fine from your checks. If the 502 shows up on both domains, it probably needs a person on the InfinityFree side to look at it, because nothing you can change in the account would affect it.

My best guess at this time for 502 errors is that it’s caused by an account resource limit. A simple HTML page doesn’t use much, but by your own admission, the same account has a WordPress site as well which, depending on how it’s setup, could be using up your account’s resources.

The resource usage graphs don’t show this, they show daily usage, not burst usage, so a short burst of account usage doesn’t show up there.

However, this is my best guess at this time. We don’t have any logs or metrics that we could use to verify this.