In firefox, I tried to load with a letsencrypt certificate unsuccessfully. Firefox reports : SEC_ERROR_UNKNOWN_ISSUER

After I refreshed, the issue went away on Firefox, but then I tested it with the latest Tor Browser based off Firefox, where this issue came up again. The issue never exhibits on Chrome, Safari, or Opera. My normal Firefox install never exhibits this issue again.

Something similar to this :

The owner of has configured their website improperly. To protect your information from being stolen, Tor Browser has not connected to this website.

macOS 10.12.3 (16D32)

Google AppEngine instance.
App Engine version: 1.9.48

Google AppEngine

Yes - Google Cloud App Engine

Narrowed down to the SSL Certificate, when I try to visit my website at (the underlying App Engine application that redirects too) there are no issues with the SSL Certificate for the version of my site)

While I wait for analysis to finish, I’ll go with my hunch: Incomplete chain.

You’ve got some configuration somewhere that either needs to be fed the complete chain (fullchain.pem instead of cert.pem) from Let’s Encrypt, or it needs a separate configuration entry for a chain of “additional” or “intermediate” certificates which will be in chain.pem in addition to the cert.pem setting you have already. Most likely the former.

Some browsers will patch up the difference, from other sites they’ve visited, or by going off to fetch the missing certificates. But if you fix your configuration it will Just Work™ so that’s what you need to do.

Thanks, thats what my research was leading me to as well. Copy/Paste of
Custom Certs on Google Appengine seems perhaps lose the intermediate cert
when there are multiple certs pasted in according to anacadotal evidence on
various threads, even though the Google Appengine Custom SSL docs don’t
mention that you have to upload the file versus pasting in the cert.

