What is ERR_CERT_COMMON_NAME_INVALID?
ERR_CERT_COMMON_NAME_INVALID is an error that occurs when the domain name (Common Name or Subject Alternative Name) specified in the SSL certificate does not match the domain name that the browser is trying to connect to.
For example, if your certificate is issued for www.example.com and users try to access example.com, this error occurs. In 2026, modern certificates generally use the SAN (Subject Alternative Name) domain and can cover more than one domain address.
Common Scenarios
Scenario 1: www and non-www Incompatibility
The most common situation. While the certificate is issued for www.example.com, example.com is out of scope.
Solution
- Add both
example.comandwww.example.comas SANs when obtaining the certificate - Most CAs automatically include both in DV certificates
- Redirect non-www → www (or vice versa) in Nginx/Apache
# Nginx: non-www → www redirect
server {
listen 80;
listen 443 ssl;
server_name example.com;
return 301 https://www.example.com$request_uri;
}
# Apache (.htaccess)
RewriteEngine On
RewriteCond %{HTTP_HOST} ^example\.com [NC]
RewriteRule ^(.*)$ https://www.example.com/$1 [L,R=301]
Scenario 2: Subdomain Out of Scope
Standard SSL certificate only covers a specific domain. Subdomains such as api.example.com, mail.example.com are excluded.
Solution
- Wildcard SSL: Cover all first-level subdomains with
*.example.com - Multi-Domain (SAN) SSL: Add specific subdomains as SAN
- Separate certificate:Separate DV certificate for each subdomain (free with Let's Encrypt)
Scenario 3: Wrong Certificate Installed
The wrong domain's certificate may have been uploaded to the server. It is especially common on servers hosting multiple sites.
Verification
# Check the certificate returned by the server
openssl s_client -connect yourdomain.com:443 -servername yourdomain.com | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"
# Your domain name should appear in the output:
# DNS:yourdomain.com, DNS:www.yourdomain.com
Scenario 4: Access by IP Address
SSL certificates are issued to domain names. Access by IP address (https://192.168.1.1) does not work with regular certificates.
Solution
- Use domain name instead of IP
- If a private certificate is required for the IP address, obtain a Public IP SAN certificate
Scenario 5: Old Redirect Rules
Old redirect rules may redirect to a different domain and an invalid certificate may be encountered there.
What is SAN (Subject Alternative Name)?
In modern SSL certificates, domain names are listed in the SAN field. Common Name (CN) is no longer checked by browsers — only SAN matters.
| Certificate Type | SAN Content | Area of Use |
|---|---|---|
| Single Domain | example.com, www.example.com | Single site |
| Wildcard | *.example.com | All subdomains |
| Multi-Domain (SAN/UCC) | site1.com, site2.com, site3.com | Multiple domains |
| Multi-Domain Wildcard | *.site1.com, *.site2.com | Multiple wildcard |
Certificate Checking in cPanel
- cPanel → SSL/TLS → "Manage SSL Sites"
- Select Domain and click "View Certificate"
- Check the SAN (Subject Alternative Names) field
- Make sure the correct domain is listed
Conclusion
ERR_CERT_COMMON_NAME_INVALID error is caused by incompatibility between the certificate and the accessed domain. When purchasing a certificate, do not forget to add all domain variations (www, non-www, subdomain) to the SAN area. Wildcard SSL covers all subdomains, while Multi-Domain SSL protects different domains with a single certificate.