> ## Documentation Index
> Fetch the complete documentation index at: https://help.enrolweb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SSL Troubleshooting

> Diagnose common SSL errors including certificate warnings, mixed content, expired certificates, and installation problems on your EnrolWeb site.

Most SSL problems come from a handful of common causes: expired certificates, wrong installation, or mismatched hostnames. This guide walks you through the fastest ways to diagnose and fix them.

## Browser shows "Not Secure" or certificate warning

<Steps>
  <Step title="Check expiration">
    Visit the site in a browser and click the padlock (or warning icon) to view certificate details. If expired, \[renew immediately]\(/SSL & Website Security/contact-2-2-3).
  </Step>

  <Step title="Verify hostname match">
    The certificate must cover the exact hostname (`www.yourdomain.com` vs. `yourdomain.com`). Wildcards cover only one level of subdomain.
  </Step>

  <Step title="Confirm installation">
    Re-run installation in cPanel or on your server. Ensure the CA bundle is included.
  </Step>

  <Step title="Test with SSL Labs">
    Run [ssllabs.com/ssltest](https://www.ssllabs.com/ssltest) for a full diagnosis and grade.
  </Step>
</Steps>

## Mixed content warnings

Your page loads over HTTPS but includes HTTP resources (images, scripts, styles).

<Steps>
  <Step title="Open browser console">
    Open Developer Tools > Console. Look for `Mixed Content` warnings.
  </Step>

  <Step title="Update resource URLs">
    Change all `http://` references in your HTML, CSS, and JS to `https://` (or use protocol-relative `//`).
  </Step>

  <Step title="Fix CMS URLs">
    In WordPress, update Site URL in **Settings > General** and use a plugin like Better Search Replace to update database URLs.
  </Step>
</Steps>

## "Your connection is not private" (NET::ERR\_CERT errors)

<CardGroup cols={2}>
  <Card title="ERR_CERT_DATE_INVALID" icon="calendar">
    Certificate is expired or the system clock is wrong.
  </Card>

  <Card title="ERR_CERT_COMMON_NAME_INVALID" icon="globe">
    Certificate doesn't match the hostname. Reissue with correct domain.
  </Card>

  <Card title="ERR_CERT_AUTHORITY_INVALID" icon="shield">
    Missing or wrong CA bundle. Reinstall with the full chain.
  </Card>

  <Card title="ERR_SSL_PROTOCOL_ERROR" icon="triangle-exclamation">
    Server misconfigured or unsupported protocol. Update server config.
  </Card>
</CardGroup>

## HTTPS redirect not working

<Steps>
  <Step title="Verify certificate is installed">
    Visit `https://yourdomain.com` directly. If it works, the certificate is installed.
  </Step>

  <Step title="Enable Force HTTPS in cPanel">
    Under **Domains**, toggle **Force HTTPS Redirect** on.
  </Step>

  <Step title="Check .htaccess">
    Confirm the rewrite rules haven't been overwritten or commented out. See \[Installing SSL]\(/SSL & Website Security/contact-2-2) for examples.
  </Step>
</Steps>

## CA bundle or intermediate certificate missing

Symptom: the site works in desktop browsers but fails on mobile or older devices.

<Steps>
  <Step title="Reinstall with the CA bundle">
    In cPanel SSL/TLS Manager, paste the CA bundle in the correct field.
  </Step>

  <Step title="Concatenate for Nginx">
    Combine your certificate and intermediates into one file: `cat yourdomain.crt ca-bundle.crt > fullchain.crt`
  </Step>

  <Step title="Restart web server">
    Reload Nginx or restart Apache to pick up the change.
  </Step>
</Steps>

## Validation email not received

<Steps>
  <Step title="Check spam folder">
    Approval emails sometimes land in junk.
  </Step>

  <Step title="Use an approved address">
    Only certain addresses can receive validation (admin@, webmaster@, hostmaster@, or the WHOIS admin email).
  </Step>

  <Step title="Switch to DNS validation">
    In your order, change the validation method to DNS if email fails.
  </Step>
</Steps>

## Still stuck?

<Warning>
  If none of the above resolves the issue, contact [support@enrolweb.com](mailto:support@enrolweb.com) with your domain, the exact error message, a link to an SSL Labs test result, and a screenshot of the certificate details.
</Warning>
