# SSL issues (one resolved, one not)

**URL:** <https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235>\
**Category:** Application Support\
**Created:** [April 2, 2024, 3:26pm UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235 "2024-04-02T15:26:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaun\_Dishman](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/shaun_dishman/32/3150_2.png) [@Shaun\_Dishman](https://community.kinsta.com/u/Shaun_Dishman)\
**Post date:** [April 2, 2024, 3:26pm UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/1 "2024-04-02T15:26:16Z")

</div>

I’m having trouble running my local DevKinsta store with SSL enabled. This is on an Ubuntu 22.04 machine.

At first, I was unable to toggle the “HTTPS” switch; it would say “SSL update failed”. By searching through the community, I did discover a workaround to this problem. The issue was that I had no “~/.mozilla/firefox/” directory. Creating this directory by hand, then toggling the switch, worked. Everything was working great, until…

… some time later (either a few hours or next day), I tried to open the site in Chrome, and received a “NET:ERR\_CERT\_INVALID” error. Unlike most such errors from Chrome, I don’t have the option to click “Advanced” and then select “Proceed anyways”. I am stuck on the error screen and cannot access the store. The message says: “You cannot visit [local-store.example.com](http://local-store.example.com) right now because the website sent scrambled credentials that Chrome cannot process. Network errors and attacks are usually temporary, so this page will probably work later.”

I have tried toggling the HTTPS switch, and have tried turning the store off and on again. I did confirm that I can still access the site from other browsers, including firefox and curl. But Chrome appears to be stuck.

---

<div class="post-metadata">

**Author:** ![Agus](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/agus/32/1515_2.png) [@Agus](https://community.kinsta.com/u/Agus)\
**Post date:** [April 3, 2024, 3:19am UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/3 "2024-04-03T03:19:09Z")

</div>

Hello @Shaun_Dishman 👋

Thank you for reaching us out here!

I had this similar issue in the past on the same Ubuntu 22.04 machine and shared a workaround in another [thread here](https://community.kinsta.com/t/issue-with-ssl-net-err-cert-invalid-ubuntu/2248/2) (that’s for the SSL/HTTPS issue related to “_.mozilla/firefox_” ),  
and bellow that thread I also shared [a solution](https://community.kinsta.com/t/issue-with-ssl-net-err-cert-invalid-ubuntu/2248/3) related to the “ **NET::ERR\_CERT\_INVALID** ” error in the Chrome browser only (which seemed to happen on Chrome browser above version _ **111.0.5563.146-1** _ - and it’s not something that DevKinsta could control though) - while the HTTPS/SSL for the local sites worked fine on other browsers (like FireFox, even for the current/newest FireFox browser version).

You may want to check my previous replies there and see if that would help you too hopefully! 🙏

Best regards,  
Agus Utomo

---

<div class="post-metadata">

**Author:** ![Shaun\_Dishman](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/shaun_dishman/32/3150_2.png) [@Shaun\_Dishman](https://community.kinsta.com/u/Shaun_Dishman)\
**Post date:** [April 3, 2024, 6:09pm UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/4 "2024-04-03T18:09:06Z")

</div>

Agus,

Thanks for the response! I should have stated at the outset that I had already seen your other thread. But there are a couple of reasons why I didn’t pursue your workaround:

1. My situation sounded a bit different from yours, in that yours seemed to be caused by a Chrome upgrade. I can confirm that no upgrade occurred between when my cert was working, and when it wasn’t. I had it working just fine in Chrome, and then a few hours later, it stopped working, with no change in-between.

2. Downgrading Chrome is just not a viable option. Disconnecting from receiving auto-updates is a bad security posture and is not sustainable as a real solution. It works OK for a one-time hack/workaround, but not long-term. There needs to be a way to access my DevKinsta store using the latest versions of Chrome.

---

<div class="post-metadata">

**Author:** ![Shaun\_Dishman](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/shaun_dishman/32/3150_2.png) [@Shaun\_Dishman](https://community.kinsta.com/u/Shaun_Dishman)\
**Post date:** [April 3, 2024, 6:11pm UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/5 "2024-04-03T18:11:47Z")

</div>

To the above point: I checked the Chrome release history, and versions prior to v111 were released over a year ago!

---

<div class="post-metadata">

**Author:** ![Dumitru\_Galit](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/dumitru_galit/32/3258_2.png) [@Dumitru\_Galit](https://community.kinsta.com/u/Dumitru_Galit)\
**Post date:** [April 17, 2024, 9:25am UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/7 "2024-04-17T09:25:34Z")

</div>

Hi there, I’m currently experiencing the same issue - any fixes on that side maybe?  
Downgrading to 12 versions above is kind’a weird to be honest.

---

<div class="post-metadata">

**Author:** ![Dumitru\_Galit](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/dumitru_galit/32/3258_2.png) [@Dumitru\_Galit](https://community.kinsta.com/u/Dumitru_Galit)\
**Post date:** [April 17, 2024, 9:58am UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/8 "2024-04-17T09:58:50Z")

</div>

So one of the best solutions I found (and probably there is) would be to generate your own Certificate Authority (CA) and a signed certificate for your `.local` domain than authorize it in your chrome.

**NOTE: BE SURE TO REPLACE _yourdomain.local_ WITH YOUR ACTUAL DOMAIN**

**Steps** :

1. **Backup Existing Certificates** :

- Execute: `cp -r ~/DevKinsta/ssl ~/DevKinsta/ssl_backup`

1. **Generate CA Key and Certificate** :

- Navigate to SSL directory: `cd ~/DevKinsta/ssl`
- Generate CA key: `openssl genrsa -out myCA.key 2048`
- Create CA certificate: `openssl req -x509 -new -nodes -key myCA.key -sha256 -days 1825 -out myCA.pem`

1. **Generate Domain Key and CSR** :

- Generate domain key: `openssl genrsa -out yourdomain.local.key 2048`
- Create CSR: `openssl req -new -key yourdomain.local.key -out yourdomain.local.csr`

1. **Sign CSR with Your CA** :

- Sign CSR: `openssl x509 -req -in yourdomain.local.csr -CA myCA.pem -CAkey myCA.key -CAcreateserial -out yourdomain.local.crt -days 825 -sha256`

1. **Import CA to Chrome** :

- Open Chrome and go to `chrome://settings/certificates`
- Navigate to `Authorities`, click `Import`, and select `myCA.pem`
- Follow prompts to trust the CA for identifying websites.

1. **Restart DevKinsta Docker** :

- Restart Chrome DevKinsta and Docker container to apply the new certificate.

Hope that’s useful

---

<div class="post-metadata">

**Author:** ![Shaun\_Dishman](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/shaun_dishman/32/3150_2.png) [@Shaun\_Dishman](https://community.kinsta.com/u/Shaun_Dishman)\
**Post date:** [April 17, 2024, 2:16pm UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/9 "2024-04-17T14:16:08Z")

</div>

After I posted this, a teammate pointed out that Chrome has a hidden feature where you can key in “`thisisunsafe`” while focused on the `ERR_CERT_INVALID` page, and it will allow you to proceed.

Obviously we would never use this in a real environment, but I found this acceptable for our development/local systems as a workaround. So that’s what we’re doing for now.

Good idea about the local CA though; that’s definitely a more “correct” fix.

Though I am curious what the difference is between Chrome and the other browsers, in terms of considering the DevKinsta cert to be valid or not. It seems like the “best” fix is for DevKinsta to figure that out, and adjust their cert creation.

---

<div class="post-metadata">

**Author:** ![Joe](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/joe/32/3266_2.png) [@Joe](https://community.kinsta.com/u/Joe)\
**Post date:** [April 18, 2024, 9:33am UTC](https://community.kinsta.com/t/ssl-issues-one-resolved-one-not/3235/10 "2024-04-18T09:33:29Z")

</div>

We recently migrated to Kinsta, with one of the drawing factors being DevKinsta, but since day one I’ve been plagued by this issue.

The “solution” is really not a solution at all, as our IT dept manages our Chrome version, to keep it in line with security patches, we’re therefore unable to downgrade.

Kinsta need to fix this issue properly, rather than providing a workaround and calling it a solution.

From what I can see, this has been around as an issue for some time now, which isn’t particularly promising.
