Intermittent NET::ERR_CERT_AUTHORITY_INVALID on working site

Answer these questions to help the Community help you with Security questions.

What is the domain name?
uohousehunters (dot) com

Have you searched for an answer?
Yes, the included tips about resolving it have been followed and are unhelpful to my circumstances.

Please share your search results url:
google search: q=cloudflare+ERR_CERT_AUTHORITY_INVALID&oq=cloudflare+ERR_CERT_AUTHORITY_INVALID

When you tested your domain using the Cloudflare Diagnostic Center, what were the results?
That link redirects to the generic help page?

Describe the issue you are having:
My site intermitantly gives the above SSL error. The site serves traffic via HTTPS 80% of the time (which my cloudflare stats support), but randomly it stops working without any change from me. Server logs give no errors.

What error message or number are you receiving?
ERR_CERT_AUTHORITY_INVALID

What steps have you taken to resolve the issue?

  1. I’ve made sure I have the origin cert installed on my web server
  2. I’ve made sure to turn on (and back off) the proxying in the DNS settings
  3. I’ve waited 24+ hours now (as the docs suggest) but no difference

Was the site working with SSL prior to adding it to Cloudflare?
Yes. And it works with SSL as well, but only 80% of the time.

What are the steps to reproduce the error:

  1. Unknown. I can’t make it reproduce. It’s happening now, but I’m sure it will be working later today.

Have you tried from another browser and/or incognito mode?
Yes.

Please attach a screenshot of the error:
Generic Chrome error “NET::ERR_CERT_AUTHORITY_INVALID

As an additional note to anyone from CF reading this: this entire exercise was very frustrating. You ask me to open the diagnostic center (which doesn’t exist), and you won’t let me submit my post until i format and remove all the urls. But the one it’s complaining about is the one YOU included in the template. I get that I’m a free customer, but I’m never going to pay if this is what I can expect.

I accidentally edited this.

Yup, the site wasn’t functioning on this device when I typed the message, but by the time I was ready to submit, it’s resolved again. Again, with 0 action from my end.

I’ve seen this happen on my computer and phone both:
Computer: Mac Studio - 13.3.1 - Brave Browser: [
Version 1.48.164 Chromium: 110.0.5481.100 (Official Build) (arm64)

Phone: iPhone 14 Pro Max - 16.1 - Mobile Safari

I want to stress that the site does generally work, but not all the time. It continues to randomly break with no changes being made by me.

Additionally, the intended consumer for my website in general is a small python script that runs on a completely different Windows 10 machine. It also experiences SSL errors when the site is acting up. This leads me to believe that when it’s acting up, it’s affecting everyone, not just me/some devices.

The devices shouldn’t be a problem then.

Do you maybe have any integrations that have access to your Cloudflare DNS settings? ERR_CERT_AUTHORITY_INVALID would also happen if the Cloudflare proxy to your domain was disabled, as Cloudflare is indeed not a valid certificate authority. Can you check on Network Tools: DNS,IP,Email that it still shows the Cloudflare IPs while this error is happening?

Yup. It typically happens a couple of times a day that I notice. Next time it’s happening, I’ll check that and verify.

You can also login to Cloudflare, go to “Manage Account” → “Audit Log” and check if the DNS settings have been changed recently.

Nothing in the audit logs I don’t expect to see. Only change from today was turning DNS proxying off and back on (which did not resolve the issue).

Hello, this issue is not caused by disabling the proxy. We are experiencing a GTS root certificate problem, and on Android 9 or earlier devices, we are receiving the ‘ERR_CERT_AUTHORITY_INVALID’ error. When will this issue be resolved?"

No, this site does not have a certificate signed by a GTS root.

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.