Hostname errors · Practical guide
How to troubleshoot an SSL certificate name mismatch
A name mismatch means the certificate cannot establish the identity of the hostname being requested. Start with the exact name in the URL and the certificate served for it. Reissuing a certificate is only helpful after you know whether the problem is coverage, routing or certificate selection.
Check the exact hostname
Modern TLS identity checks use subject alternative names in the certificate. example.com and www.example.com are distinct names. A wildcard such as *.example.com covers a single label, such as shop.example.com, but not the bare domain or a deeper name such as api.shop.example.com.
Do not infer coverage from a similar-looking name or the certificate’s display label in a control panel. Compare the requested hostname with the intended names and the actual verification result.
Reference: RFC 9525: Service Identity in TLS
Check where the hostname points
If the certificate names belong to another site, inspect the hostname’s DNS and hosting assignment. A recently moved domain may reach an old server, or the new endpoint may not yet have the intended certificate attached. Check the listener or virtual host that receives the connection.
Use the hostname for the test instead of substituting an IP address. Shared hosting can select a certificate based on the server name supplied during TLS. An IP-only test may therefore exercise a different configuration from a normal visitor request.
Fix TLS before relying on an HTTPS redirect
The TLS connection is established before an HTTP redirect can be read. If https://www.example.com redirects to https://example.com, the www endpoint still needs to present a certificate suitable for www.example.com.
CheckSSL verifies the originally supplied hostname on port 443. Certificate names visible in a diagnostic result do not override a failed or unknown verification status. Use that distinction when sharing evidence with the person who manages your certificate deployment.
Correct the matching layer and retest
Keep the original failing hostname in your test case. Switching to a working hostname only avoids the symptom.
- Check the exact hostname users enter and note the certificate names returned.
- Verify DNS and the hostname assignment at the CDN, load balancer or web server.
- Install or select a certificate that covers the required name on that endpoint.
- Run the check again for every public alias, then test any redirects between them.
Keep reading
Related guides
How to check SSL certificate expiry and renewal
Read certificate dates, verify a renewal on the public endpoint and investigate why a server still presents an old certificate.
Read guide Certificate trustSSL certificate chain errors: what to investigate
Understand leaf, intermediate and root certificates, and investigate a failed trust check without guessing the cause.
Read guide