SSL Certificate Issue for dolibarr.desnet.free.nf - NET::ERR_CERT_AUTHORITY_INVALID & SNI Misconfigu

Hello InfinityFree Team,

I am experiencing an SSL certificate issue with my free subdomain dolibarr.desnet.free.nf. When I try to access my site via HTTPS, browsers display the error NET::ERR_CERT_AUTHORITY_INVALID.

I understand that free subdomains now use a system-wide SSL certificate and that custom certificates are no longer supported or required. I have already deleted all previous custom certificate orders/requests several days ago, and I have also cleared my browser cache multiple times.

Despite this, the problem persists. I ran an SSL Labs test, and the report clearly indicates severe issues:
SSL Labs Report: https://www.ssllabs.com/ssltest/analyze.html?d=dolibarr.desnet.free.nf

Key findings from the SSL Labs report (and browser certificate details) include:

  1. A global rating of F.
  2. The server is presenting a certificate with:
    • Common Name (CN): *
    • Issuer: CN = *
    • Validity starting in the future: Valid from: Sun, 11 May 2025 10:37:45 UTC
  3. This certificate is (understandably) not trusted.
  4. Crucially, the SSL Labs report also indicates a Server Name Indication (SNI) misconfiguration: “This site works only in browsers with SNI support.” and later “This server does not support SNI.” This contradiction seems to be a likely cause for the default invalid certificate being served.

Could you please investigate the server configuration for my subdomain dolibarr.desnet.free.nf? It appears the system-wide SSL certificate is not being applied correctly, and there might be an issue with the SNI settings for this specific subdomain, causing the server to fall back to an invalid default certificate.

Thank you for your time and assistance in resolving this issue.

Best regards,

Unfortunately sub-sub domains on free subdomains are not supported. A bug allowed these to be created in the past, however that has since been fixed. Only free subdomains (sub.free.tld) are eligible for free auto-ssl.

Also, please note that external website checkers (Like SSL labs) will always fail as they are blocked by the free hosting security system.

7 Likes

With the sole exception of SSL checkers because those do work for whatever reasons.

2 Likes

They aren’t looking at the site. They are looking at the SSL sent from the site. And that doesn’t have the security system.

2 Likes

Some of them do have problems because they do more then just check SSL, then throw warnings that are worded quite poorly, leaving users thinking something is wrong with the certificate as that is the test they ran, when the website is actually returning a different error.

But SSL checkers that only check SSL are not blocked, correct.

6 Likes

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.