# The certificate is not trusted because it is self-signed

**URL:** <https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421>\
**Category:** Help\
**Created:** [December 12, 2020, 10:20pm UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421 "2020-12-12T22:20:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![arashout](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/arashout/32/45345_2.png) [@arashout](https://community.letsencrypt.org/u/arashout)\
**Post date:** [December 12, 2020, 10:20pm UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/1 "2020-12-12T22:20:51Z")

</div>

My domain is:  
fitpets.app

> **[crt.sh | fitpets.app](https://crt.sh/?q=fitpets.app)**
>
> Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)

I ran this command:  
Tried to connect to fitpets.app from browser

It produced this output:

> fitpets.app uses an invalid security certificate.
> 
> The certificate is not trusted because it is self-signed.
> 
> Error code: MOZILLA\_PKIX\_ERROR\_SELF\_SIGNED\_CERT

My web server is (include version):  
nginx version: nginx/1.18.0

The operating system my web server runs on is (include version):  
Ubuntu 20

My hosting provider, if applicable, is:  
google domains

I can login to a root shell on my machine (yes or no, or I don't know):  
Yes, I use AWS EC2

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):  
certbot 1.10.1

Google Domains detects my certificates and so do other certificate checking sites.  
Apparently \*.app sites have some extra protection from Google HSTS, but I don't really know how to fix the error.  
I thought using Let's Encrypt to generate a certificate would fix it but maybe I need to also register the certificate somehow?

Thanks for any help!

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [December 12, 2020, 10:30pm UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/2 "2020-12-12T22:30:01Z")

</div>

Hello @arashout,

I see no problem, well, there is a nginx bad gateway error but nginx is serving the right (and valid) certificate for your domain.

 ![imagen](https://global.discourse-cdn.com/letsencrypt/original/3X/4/4/44d49dce67bd28baf093708647db36be5bf5ded5.png)

Maybe it is a browser's cache issue.

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 12, 2020, 10:39pm UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/3 "2020-12-12T22:39:21Z")

</div>

Which port are you getting that error from?  
Also, I don't see a "www" DNS A record - was that on purpose?

---

<div class="post-metadata">

**Author:** ![arashout](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/arashout/32/45345_2.png) [@arashout](https://community.letsencrypt.org/u/arashout)\
**Post date:** [December 12, 2020, 10:44pm UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/4 "2020-12-12T22:44:07Z")

</div>

omg you are right!  
It's working now!

I used incognito and no longer getting the cert error. Maybe it just took some time.

What do I need a "www" DNS A record for?

I only have an A Record for fitpets.app to my ec2 ip

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [December 12, 2020, 10:58pm UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/5 "2020-12-12T22:58:04Z")

</div>

> [@arashout](#):
>
> What do I need a "www" DNS A record for?

Some people will type `www` in front of any URL, just because they're not used to URLs without it.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [December 13, 2020, 1:02am UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/6 "2020-12-13T01:02:12Z")

</div>

Imagine how much time and effort could be saved if the useless `www` subdomain custom were eliminated.

Consider:  
`http://apex` -\> `https://apex` -\> `https://www.apex`

Eliminating the `www` subdomain eliminates 100% of redirects for sites using HSTS and 50% of redirects for sites not using HSTS. No need for a `www` serveralias or CNAME/A record. Never need to remember to include `www` in certificate. Greatly simplifies address canonicalization.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 13, 2020, 3:42am UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/7 "2020-12-13T03:42:42Z")

</div>

> [@griffin](#):
>
> `www` subdomain custom

_too late_ it is already an ingrained custom (for too many)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 12, 2021, 3:42am UTC](https://community.letsencrypt.org/t/the-certificate-is-not-trusted-because-it-is-self-signed/140421/8 "2021-01-12T03:42:55Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
