# Https - certificate is not valid

**URL:** <https://community.kinsta.com/t/https-certificate-is-not-valid/1173>\
**Category:** Community Guides\
**Created:** [December 9, 2021, 8:35pm UTC](https://community.kinsta.com/t/https-certificate-is-not-valid/1173 "2021-12-09T20:35:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marsux](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/marsux/32/821_2.png) [@Marsux](https://community.kinsta.com/u/Marsux)\
**Post date:** [December 9, 2021, 8:35pm UTC](https://community.kinsta.com/t/https-certificate-is-not-valid/1173/1 "2021-12-09T20:35:23Z")

</div>

Hello,

I read some posts but couldn’t find a fix to my issue.

I installed the latest version of DevKinsta (great thing!), dowloaded my live website successfully, but I still get a red warning in Chrome “Not Secure”, and the “https://” is double stroked in red.  
Message: “Certificate is not valid”.  
I tried to edit the certificate to make it “always trust” =\> not better.  
My computer is a MacBook pro running Big Sur.

Anyone to help me?

Thanks ! 🙂

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)\
**Post date:** [December 9, 2021, 9:03pm UTC](https://community.kinsta.com/t/https-certificate-is-not-valid/1173/2 "2021-12-09T21:03:53Z")

</div>

Hi @Marsux, thanks for reaching out. It’s honestly better to just ignore this warning since it’s expected. If you absolutely want to add the local certificate to Chrome’s trusted authorities, the instructions here (starting from the user’s “EDIT”) might get this working for you: [ssl - Getting Chrome to accept self-signed localhost certificate - Stack Overflow](https://stackoverflow.com/a/15076602)

I was able to get a secure certificate Incognito by following those instructions. But again, it’s not really a warning that you need to worry about.  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/1X/e91c749f4ed6673e63aacded943445f65360e5e3.png)

---

<div class="post-metadata">

**Author:** ![Marsux](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/marsux/32/821_2.png) [@Marsux](https://community.kinsta.com/u/Marsux)\
**Post date:** [December 10, 2021, 8:54am UTC](https://community.kinsta.com/t/https-certificate-is-not-valid/1173/3 "2021-12-10T08:54:59Z")

</div>

Hi @Kevin , thank you for your answer.

I followed the instructions that you mentioned without success… The strange thing is that I don’t have this issue on my iMac but only on my MacBook. Both use the same OS, same Chrome, etc.

Maybe it’s not a big deal, but I read here and there that you can get “bad surprises” with your code when you push it in prod, if your dev environment is not ssl-secured… Not correct?

Thank you ! 🙂

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)\
**Post date:** [December 10, 2021, 7:10pm UTC](https://community.kinsta.com/t/https-certificate-is-not-valid/1173/4 "2021-12-10T19:10:13Z")

</div>

Sorry to hear that @Marsux!  
So what’s important is that your website is using https:// URLs. When you move back to Production, Chrome will show everything as “Secure” as long as your Production environment has a valid SSL certificate Installed.

It only shows “Not Secure” now because the local SSL Certificate added by DevKinsta isn’t trusted by your browser; there’s no issue with the website.

For a brand new website, all you really need to do is go to your WordPress settings and make sure your Home/Site URLs are using https. This will carry over into Production when you replace the .local URL with your Production URL.  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/1X/160bac116ba3579b0fd6f65def727a77c38eab0c.png)

So since your Dev environment is based on your Production site, there’s nothing to worry about when it comes to SSL. You can just ignore the red “Not Secure” and do your developing like normal. This is just Chrome being strict with SSL on your MacBook.

Problem would happen if you changed your URLs from http **s** :// to http:// in Development then forgot to change them back before pushing your changes to Production.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/2X/8/80f8c4e56fecc02327a0964e6bf63a716483529f.png) [@system](https://community.kinsta.com/u/system)\
**Post date:** [March 10, 2022, 7:10pm UTC](https://community.kinsta.com/t/https-certificate-is-not-valid/1173/5 "2022-03-10T19:10:21Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
