GoGetSSL Logo
SSL CertificatesTrust solutions
Home Wiki Problems & Issues How to Fix ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN

How to FIX ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN

  • Usage of "Public Key Pinning" may bring difficulties and your say may stop opening in Chrome browser. Usually, that happens after the renewal of an SSL certificate. In this case, the time chosen by the administrator could exceed the time of expiration of the certificate, or its renewal.

    As a result, the visitor of the website would receive error NET::ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN​ like on the screenshot below.

    err_ssl_pinned_key_not_in_cert_chain

    HSTS is HTTPS Strict Transport Security. This setting forces the browser to always use HTTPS for a particular site. This is done with special instructions from the web server that serves the site. As an additional layer of security, HPKP - HTTP Public Key Pinning can be used. This setting allows the webmaster to specify which public key associated with the SSL certificate is good. The visitor browser will save these parameters for the time specified in the web server settings.

    Sometimes something goes wrong, webmasters make mistakes when configuring servers, as a result of this, the site becomes inaccessible. In this case, you can manually delete the associated keys manually in the browser settings. This will not work if the keys are downloaded to the browser in advance (for example, Facebook). In this case, updating the browser may help.

    • 1

      Solution: Removing a fixed HSTS key

      Fortunately, possible problems can be solved quite simply, just remove the key from the HSTS database of the Google Chrome browser.

      1. Paste that text chrome://net-internals/#hsts to your browser's address bar;
      2. Submit problematic domain name to "Delete domain security policies" and click "Delete";
      3. Retry visiting the website.
      err_ssl_pinned_key_not_in_cert_chain2
    • Conclusion

      • Webmasters: Please, stop pinning your keys!
      • Visitors: Use Chrome function to remove HSTS key

Fast Issuance within 3-5 minutes

Get a Domain Validation SSL certificate within just 5 minutes using our friendly and automated system. No paperwork or company required.

ACME SSLAutomation

Say goodbye to manual installations and the hassle of expiring certificates with our automated services. We offer a range of solutions designed to suit any environment

WHMCSReseller Plugin

We offer a professional WHMCS plugin to help you quickly and easily sell and resell SSL certificates. More details on our Partner program

Money Back 30-day guarantee

Customer satisfaction is our major concern. Get a full refund within 30 days for any purchase of SSL certificates with 100% guarantee.

Boost Validation

The Legal Entity Identifier (LEI) is a robust and modern way to verify and identify companies, helping to validate OV SSL certificates

Register LEI for $62.00

Help Center

Installation issues or SSL errors? Our Knowledgebase has clear, step-by-step guides to help you install, fix, and troubleshoot fast

Check Manuals

The trust that never expires

For 15+ years, we've delivered web security and trust services worldwide. See why customers keep choosing us. From startups to enterprises, we help businesses of all sizes stay secure and build trust with their audience.

Shopper Approved reviews for GoGetSSL