Corporate Windows machines trust an internal inspection CA pushed by group policy. Off the corporate network — or on a personal device — that CA is missing, so every intercepted site fails authority validation.
Corporate Windows machines trust an internal inspection CA pushed by group policy. Off the corporate network — or on a personal device — that CA is missing, so every intercepted site fails authority validation.
Check whether the certificate issuer is your employer's proxy (Zscaler, Netskope, Blue Coat). If yes, connect to the corporate VPN so the CA is installed. If not, the site is serving an incomplete chain and the fix is server-side.
Windows has its own failure mode, but ERR_CERT_AUTHORITY_INVALID has a wider set of causes. The most common one overall is: The server serves only the leaf certificate and omits the intermediate bundle.
Concatenate the intermediate certificates after the leaf in the certificate file (fullchain, not cert) and reload the server. Desktop Chrome sometimes hides this via caching, so always confirm with an external check.
An external SSL check builds the chain from scratch with no local trust store shortcuts, so it shows a missing intermediate that your own browser may be silently caching around.
Corporate Windows machines trust an internal inspection CA pushed by group policy. Off the corporate network — or on a personal device — that CA is missing, so every intercepted site fails authority validation.
Check whether the certificate issuer is your employer's proxy (Zscaler, Netskope, Blue Coat). If yes, connect to the corporate VPN so the CA is installed. If not, the site is serving an incomplete chain and the fix is server-side.
The browser could not build a trust path from the certificate the server sent to a root it trusts. Usually the server is serving only the leaf certificate without its intermediates, or the certificate is self-signed.