NET::ERR_CERT_SYMANTEC_LEGACY — Chrome 70+ (October 2018) automatically distrusts certificates from Symantec, VeriSign, Thawte, GeoTrust and RapidSSL issued before December 1, 2017. Cause: Symantec violated Baseline Requirements and the CA was distrusted. Fix: reissue via DigiCert (which acquired Symantec's business) or any other CA such as Let's Encrypt.
This error blocks HTTPS access. Below: causes, fixes, working config, FAQ.
certbot --nginx -d example.comopenssl x509 -in cert.pem -issuer — look for "Symantec"/"VeriSign"server {
listen 443 ssl http2;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
ssl_prefer_server_ciphers off;
ssl_stapling on;
ssl_stapling_verify on;
}SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freeSymantec issued thousands of mis-issued certs in 2015–2017 (including for google.com without permission). Chrome announced the distrust in 2017 and enforced it in Chrome 70 (October 2018).
Yes. DigiCert acquired Symantec's website security business in August 2017. New certs from the DigiCert CA are valid in Chrome.
No Chrome flags to bypass. The only path is a cert reissue.
Mozilla and Apple applied similar distrust. In 2026 it basically does not work anywhere.