Use this guide when your browser warns that a connection is not private, Cedros is still preparing HTTPS, or a secure page has redirect or loading problems. HTTPS protects the connection to your website. Its certificate must be valid for the exact address visitors open.
If the browser cannot find the address at all, start with Fixing a domain that isn’t connecting. If you are connecting a new domain, keep your existing working address until the new one passes its HTTPS checks.
Choose the symptom
| What you see | What to check |
|---|---|
| A newly connected domain has pending TLS or HTTPS | Check HTTPS readiness in Cedros. |
| The browser says the certificate is expired, invalid, or for another name | Resolve a certificate warning. |
| A Cloudflare error page shows 525 or 526 | Check Cloudflare and your website host. |
| The browser reports too many redirects | Resolve a redirect loop. |
| The page opens over HTTPS, but images, forms, or other content are blocked | Fix mixed content. |
| Only one device or network shows a warning | Compare devices and networks. |
Record the exact URL and error before changing settings. Include whether the address has www, when the problem began, and whether it worked previously. Do not bypass a certificate warning to sign in or submit customer information.
Check HTTPS readiness in Cedros
Open the intended site's admin and go to Settings → Site → Domains.
Managed by Cedros Domains
Find the domain under Your domains and read its status and explanation. DNS, Routing, and TLS describe separate parts of setup: reaching the right destination, serving the right site, and establishing a secure connection.
- If the domain is Pending or Needs attention, select Check setup and read the resulting details.
- Resolve any missing or incorrect DNS records to add using the values Cedros supplies. Follow the domain troubleshooting guide if the saved records appear correct.
- Once the site is ready to receive visitors, use Test DNS in the setup walkthrough to recheck and advance the connection. A completed check is not necessarily a successful connection; read the updated result.
- If Cedros says DNS is verified. HTTPS is still being prepared; re-check shortly., leave the correct records in place and check again shortly. Changing a correct destination or reconnecting the domain is not a certificate-repair step.
- Test the exact HTTPS addresses in a browser before making the new domain primary.
For the usual managed root-domain connection, both example.com and www.example.com need HTTPS readiness. One address working does not establish that both are ready. Cedros can refuse a primary-domain change while HTTPS is incomplete; follow Choosing or changing your primary domain once setup is ready.
If a new domain remains pending after a later check, send Cedros support the status, setup message, and time of the last DNS change. If an established site has stopped working, report that promptly rather than treating it as routine new-domain preparation.
A Domain card with a server target
If your settings show Domain name, Server target, and Check website DNS, the message Website DNS verified confirms the website DNS check. It does not confirm that a certificate is installed or that HTTPS is working.
Confirm the intended hostname, then ask the person or company hosting the site to check HTTPS for that exact name. Include the server target and browser error. These fields save automatically, so do not edit them merely to refresh the status.
For Cedros-managed hosting, contact Cedros support. For independently hosted sites, the hosting administrator needs to inspect certificate installation, renewal, and the server's HTTPS configuration.
Resolve a certificate warning
Check the spelling of the address first. A certificate for example.com does not automatically prove coverage for www.example.com or another subdomain. Test each address customers use, including an old address that should redirect to the new one: HTTPS must work before an HTTPS redirect can be delivered.
Expired or not yet valid
Check the device's date and time, then compare the same URL on another device. An incorrect clock can cause a date-related certificate warning; Chrome's error guide explains this case.
If the warning persists across devices with correct clocks, ask Cedros support or your host to inspect the certificate's validity dates and renewal status. Include when the site last worked. Waiting for DNS propagation will not renew an expired certificate.
The domain's Renew or Auto-renew controls concern its registration. Renewing registration and renewing an HTTPS certificate are different tasks; buying another registration year is not a certificate fix.
Wrong hostname
A name-mismatch warning can mean the server is presenting a certificate for a different address. It can also occur when the hostname still reaches an old or incorrect server.
Compare the failing hostname with the one configured in Cedros. If you recently changed DNS, check the saved website records using the domain troubleshooting guide. If the destination is correct, ask the host to confirm that this hostname is assigned to your site and covered by the certificate it serves.
Do not change your primary domain just to match an unexpected certificate.
Untrusted certificate or secure-connection failure
If multiple up-to-date devices cannot trust the certificate, the host needs to check the certificate issuer, the complete certificate chain, and the HTTPS configuration. A chain is the set of certificates the browser uses to verify who issued the site's certificate.
Send the exact message, such as an authority, protocol, or cipher error, rather than describing all of these as “SSL broken.” If the problem only occurs on a work device or work network, compare devices and networks before changing the website.
Do not ask customers to install a certificate or disable browser protection to use your public site.
Check Cloudflare and your website host
If your website traffic is proxied through Cloudflare, there are two secure connections: the visitor's browser to Cloudflare, and Cloudflare to your website server, also called the origin. A working browser-facing certificate does not prove the origin connection is healthy.
- 525 — SSL handshake failed: Cloudflare could not establish its secure connection to the origin. Ask the host to check that HTTPS is available on the server and that its certificate and TLS configuration are correct. See Cloudflare's 525 guide.
- 526 — Invalid SSL certificate: Cloudflare could not validate the origin certificate under Full (strict). Ask the host to check expiration, hostname coverage, trust, and the complete certificate chain. See Cloudflare's 526 guide.
Give the host or Cedros support the failing hostname, error number, time with time zone, and Ray ID if displayed. If you manage Cloudflare, also record the current SSL/TLS encryption mode and any recent proxy or certificate change.
Keep certificate validation enabled while the underlying issue is repaired. Switching to an unencrypted connection or weakening validation can hide the fault without restoring a properly verified connection.
Do not toggle a record to DNS only as a general certificate fix. If the origin uses a Cloudflare Origin CA certificate, sending browsers directly to it can produce an untrusted-certificate warning. Cloudflare's Origin CA guidance explains this limitation. Confirm the intended proxy setup with your host.
Resolve a redirect loop
A message such as ERR_TOO_MANY_REDIRECTS means the browser keeps being sent to another address instead of reaching the page. Record the starting URL and any addresses visible as it redirects.
Try the URL in a private browser window. If the same loop occurs there and on another device, ask your host to review the website and Cloudflare redirect settings together.
Common conflicts include HTTP being redirected to HTTPS while another rule sends HTTPS back to HTTP, or one rule sending the root domain to www while another sends it back. Cloudflare's Flexible mode can also conflict with a server that requires HTTPS. See Cloudflare's redirect-loop guide.
Confirm the intended primary domain and ask the host to make the redirect rules agree on that address and HTTPS. Preserve the page path when redirecting existing links. Avoid adding another redirect on top of the conflicting rules or disabling HTTPS to make the page open.
Fix mixed content
Mixed content occurs when an HTTPS page requests an image, script, stylesheet, or other resource over HTTP. Browsers can block insecure resources, so the page may open while part of it looks broken or does not work. See Cloudflare's mixed-content guide.
- Note the affected page and missing image, embed, form, or feature. If you or your developer can inspect the browser console, look for a mixed-content message and record the resource URL.
- Open the affected content in Cedros and find the corresponding image or embed URL. If it belongs to a shared header, footer, theme, or extension, involve whoever maintains that component.
- Obtain a working HTTPS URL from the resource provider. Test it before replacing the old URL; changing
http://tohttps://is only useful if the destination actually supports HTTPS. - Preview the correction, then publish the updated content. For a third-party widget, use the provider's current secure embed instructions.
- Reopen the public HTTPS page as a visitor and check the affected feature. If the provider does not support HTTPS, replace or remove that resource.
A secure connection with a broken image is not always mixed content. If there is no mixed-content error, check the resource URL and availability. Certificate replacement will not repair a missing file, an unpublished page, or a widget that needs separate configuration.
Compare devices and networks
Open the same exact HTTPS URL on another up-to-date device and, if possible, a different network—for example, a phone using mobile data instead of office Wi-Fi. Note which combinations work.
If only one device fails, check its date and time and install available browser and operating-system updates. If only a work network fails, send the error to your IT administrator. Network inspection or a required organization certificate can affect HTTPS; do not install an unfamiliar certificate yourself. Chrome's certificate-error guidance covers these device and network cases.
If results differ just after a DNS change, some devices may still reach the previous destination. Use Separate caching from a wrong destination to check that possibility. A private window alone does not guarantee fresh DNS.
Confirm the fix and get help
After the repair, check the customer experience:
- Open the public HTTPS address without bypassing a warning.
- Test the root domain,
www, and every alternate address you intend to keep. Confirm each reaches the intended primary address and page. - Open an important published page and use its main customer action. Check any images, embeds, or forms that were affected.
- For managed domains, recheck setup and read the current TLS result. If the browser works but Cedros still reports pending HTTPS, report that discrepancy instead of assuming both checks measure the same connection.
- If a certificate expired, ask the host to confirm that renewal and monitoring are working after the immediate repair.
For an unresolved issue, use Getting help and reporting a problem. Include the exact URL, error text or code, a cropped screenshot, the time and time zone, whether it worked before, and Cedros's current setup message. Add the affected devices/networks and any recent DNS, proxy, hosting, or primary-domain changes.
Never include passwords, Cloudflare API tokens, certificate private keys, or private preview links in a support report.