OneLinersCommand workbench
Verified diagnostic signature

The client could not build a trusted certificate chain.

Match output from tls, understand the likely cause, then continue with sourced, read-only checks.

Confidence
high
Platforms
linux · macos · windows
Verified
2026-07-24
Recognized output

Signature matched locally

certificate signed by unknown authority

OneLiners matches this pattern in your browser. Your pasted output is not stored or indexed.

Likely causes

What usually produces this signal

  1. Missing intermediate certificate
  2. Private CA not trusted
  3. Incorrect server chain
  4. Intercepting proxy
Safe next checks

Collect evidence before changing the system

01

Inspect a remote TLS certificate

openssl s_client -connect <host>:<port> -servername <host> </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

The output matches the expected target and exits without an error.

02

Print subjects, issuers, and validity dates for a TLS chain

openssl s_client -showcerts -connect <host>:<port> -servername <host> </dev/null 2>/dev/null | openssl crl2pkcs7 -nocrl -certfile /dev/stdin | openssl pkcs7 -print_certs -noout

The output matches the expected target and exits without an error.