Failed to verify certificate for target URL

User Eugeniu Spatari has sent us the following question:

After SSL certificate renewal, the Android application refuses to connect, … After reinstallation of the App, the error is cannot find the server … We are using a NGINX proxy server and Windows IIS 2016. SSL certificate we dispose an wildcard and an ZeroSSL certificate. Please have you any suggestion ? Any specific configuration while using NGINX proxyserve ? Survey Solution is compatible with the double redirection ? It worked before with a previous certificate which expired, and locally with Intranet is working and accessible.

Assuming the simplest case, it is likely that the Interviewer App is reporting a genuine problem with the certificate use. In particular, Eugeniu should check for the so-called “chain problems” in the certification path.

Eugeniu should use a tool that would inspect the certificate chain from the Android viewpoint and report if any certificates in the chain are invalid, revoked, or require additional downloads. In the latter case the Interviewer App will not be able to communicate with such a server and it is in agreement with the described symptoms.

A search in Google for: validate certificate yields a variety of tools that could be used for this purpose.

This is aking to the problem described here:

Hy everyone, still not found the solution. Intranet works fine, from Internet not. My Android is 10.1.0.181 APK version is 20.09.1, so is not the issue of old tablet. Server Healthy Diagnostic is Good. We use Nginx as proxy server. Some special parameter for Android flow ? anybody met this issue before?

Survey Solutions is working fine, but the tablets don’t trust the server based on the certificate that it presents.

I have written earlier:

use a tool that would inspect the certificate chain from the Android viewpoint and report if any certificates in the chain are invalid, revoked, or require additional downloads.

Below is the diagnostics output for your site (obtained with a 3rd party tool), clearly indicating that there is a problem with an intermediate certificate:

1 Like

Thank you Sergyi, that was the problem, and it’s working now.