ERR_SSL_CLIENT_AUTH_SIGNATURE_FAILED appears in mTLS (mutual TLS) when the server requests a client cert but the client cannot sign the challenge. Causes: smart card/eToken locked, private key corrupted, Chrome can not find the cert in the OS store, expired cert. Fix: verify cert in OS store, unlock smart card, reinstall cert.
This error blocks HTTPS access. Below: causes, fixes, working config, FAQ.
server {
listen 443 ssl http2;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
ssl_prefer_server_ciphers off;
ssl_stapling on;
ssl_stapling_verify on;
}SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freeMutual TLS — two-way authentication. The server verifies the client certificate before returning a response. Used in banking, enterprise APIs, gov services.
If there is a single matching cert — Chrome uses it automatically. If multiple or none — a dialog appears. Tunable in chrome://policy.
Firefox has its own cert store (NSS), independent of the OS. Chrome uses the system store. Different stores → different access.
chrome://settings/certificates → Your certificates → Import. Enter the p12 password. The cert appears in the list and becomes available for mTLS.