Unable to Verify the First Certificate

The server sends its own certificate but not the intermediate that links it to a trusted root. Browsers sometimes fill the gap; curl, Node.js and APIs do not. Check the site below to confirm what is wrong.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

SSL Certificate Checker

The error, and the fix

Error CodesUNABLE_TO_VERIFY_LEAF_SIGNATURE
Usual CauseThe server sends its own certificate but not the intermediate that links it to a trusted root
Check From a Terminalopenssl s_client -connect example.com:443 -servername example.com

The server sends its own certificate but not the intermediate that links it to a trusted root. Browsers sometimes fill the gap; curl, Node.js and APIs do not.

How to fix it: Configure the full chain: fullchain.pem with Let's Encrypt (not cert.pem), or append the CA's intermediate to your certificate file.

Questions

What does "unable to verify the first certificate" mean?
The server sends its own certificate but not the intermediate that links it to a trusted root. Browsers sometimes fill the gap; curl, Node.js and APIs do not.
How do I fix it?
Configure the full chain: fullchain.pem with Let's Encrypt (not cert.pem), or append the CA's intermediate to your certificate file.
Is it safe to click through the warning?
Not on a site where you enter passwords or payment details: the connection may not be private. Fix the certificate instead.

Stop abuse leaving your servers

Frabs watches every VM's outbound traffic and stops spam, scans and floods before the abuse report arrives.