Some clients work; others get handshake failures or "certificate unknown".
Full chain not served (only the leaf cert), or SNI/TLS version mismatch.
ssl_certificate /etc/letsencrypt/live/d/fullchain.pem;openssl s_client -connect host:443 -servername d < /dev/null 2>/dev/null | headcurl -vI https://d 2>&1 | grep -E "SSL|issuer|subject"Automated renewal + external chain validation monitoring.
Spinning up a fresh box to reproduce or escape this error?
Managed cloud hostingNinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.
Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog