SnapshotThis is a frozen record of the check as it ran — the live certificate may have changed since. Re-check this domain now

Works on modern platforms — breaks on Android 2.3.1 – 5.0.0, iOS 5 – 9, webOS 3.0 · XS2D – 3.2 · 86TR3D/TC3D/TR3E

github.com · snapshot taken Aug 29, 2026, 03:25 PM · chain of 4 · 78 trust stores

Re-check

Coverage

share of version-pinned trust stores
78
Trust stores checked
41
Trusted
37
Rejected
Not verifiable
iOS
16 / 21
Android
13 / 25
webOS
8 / 28
Tizen / Fire OS
4 / 4

Why it fails — 1 root cause behind 37 rejections

grouped, not 37 rows of openssl output
Root cause 1

"USERTrust ECC Certification Authority" is not in these platforms' trust stores

The chain reaches USERTrust ECC Certification Authority, but these platform versions don't include it — verification stops with no path to a trusted root ("unable to get local issuer certificate" / "self-signed certificate in chain"). Usually the anchor root is newer than the platform, or the server is not sending a required intermediate.

37 platforms
Android 2.3.1Android 3.2.4Android 4.0.1Android 4.0.2Android 4.0.3Android 4.0.4Android 4.1.1Android 4.2Android 4.3Android 4.4Android 5.0.0Android 5.0.2iOS 5iOS 6iOS 7iOS 8iOS 9webOS 3.0 · 55EF5C/55EV5CwebOS 3.0 · 55TC3CDwebOS 3.0 · 65EE5PCwebOS 3.0 · 65EV5CwebOS 3.0 · EH5CwebOS 3.0 · EJ5CwebOS 3.0 · SM3C/SM5C/SM5KC/UH5C/75XS2CwebOS 3.0 · XEB3E/XF1EwebOS 3.0 · XS2DwebOS 3.2 · 55EF5EwebOS 3.2 · 55EG5CEwebOS 3.2 · 55EJ5EwebOS 3.2 · 55SVH7EwebOS 3.2 · 55VX1DwebOS 3.2 · 65EV5E/EJ5EwebOS 3.2 · 86TR3D/TC3D/TR3EwebOS 3.2 · SM5D/EJ5D/EG5CDwebOS 3.2 · TA3EwebOS 3.2 · VL5D/VL5PFwebOS 3.2 · wp320

Who is affected

Devices on Android 2.3.1 – 5.0.0, iOS 5 – 9, webOS 3.0 · XS2D – 3.2 · 86TR3D/TC3D/TR3E.

Fix

First confirm the server sends the full intermediate chain. If it does and these versions still matter, re-issue with a CA whose root has shipped since the oldest version you need to support.

The certificate

as captured at check time
Subject
CN=github.com
Issuer
C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV E36
Serial
72:01:0e:03:f4:a0:67:fe:4e:79:62:66:43:07:18:f6
Valid from
Jul 3 00:00:00 2026 GMT
Valid until
Sep 30 23:59:59 2026 GMT33 days
Signature
ecdsa-with-SHA256 · id-ecPublicKey 256 bits
SHA-256 fingerprint
17:f8:fd:2e:3f:d2:c1:13:fc:b9:77:2d:8a:4b:ab:b8:52:2d:d0:6d:d0:79:49:15:a4:ff:98:b1:b6:86:3a:00
Subject alternative names
DNS:github.comDNS:www.github.com
End entity
github.com
Jul 3 00:00:00 2026 GMT → Sep 30 23:59:59 2026 GMT · id-ecPublicKey 256 bits
Valid
Intermediate #1
Sectigo Public Server Authentication CA DV E36
Mar 22 00:00:00 2021 GMT → Mar 21 23:59:59 2036 GMT · id-ecPublicKey 256 bits
Served
Intermediate #2
Sectigo Public Server Authentication Root E46
Mar 22 00:00:00 2021 GMT → Jan 18 23:59:59 2038 GMT · id-ecPublicKey 384 bits
Served
Chain top
USERTrust ECC Certification Authority
Feb 1 00:00:00 2010 GMT → Jan 18 23:59:59 2038 GMT · id-ecPublicKey 384 bits
Served

Every store, one by one

iOS 10Trustedchain verified to USERTrust ECC Certification Authority
iOS 11Trustedchain verified to USERTrust ECC Certification Authority
iOS 12Trustedchain verified to USERTrust ECC Certification Authority
iOS 12.1.3Trustedchain verified to USERTrust ECC Certification Authority
iOS 13Trustedchain verified to USERTrust ECC Certification Authority
iOS 13.4Trustedchain verified to USERTrust ECC Certification Authority
iOS 14Trustedchain verified to USERTrust ECC Certification Authority
iOS 14.2Trustedchain verified to USERTrust ECC Certification Authority
iOS 15Trustedchain verified to USERTrust ECC Certification Authority
iOS 15.1Trustedchain verified to USERTrust ECC Certification Authority
iOS 16Trustedchain verified to USERTrust ECC Certification Authority
iOS 16.5Trustedchain verified to USERTrust ECC Certification Authority
iOS 17Trustedchain verified to USERTrust ECC Certification Authority
iOS 17.4Trustedchain verified to Sectigo Public Server Authentication Root E46
iOS 18Trustedchain verified to Sectigo Public Server Authentication Root E46
iOS 26Trustedchain verified to Sectigo Public Server Authentication Root E46
iOS 5Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
iOS 6Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
iOS 7Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
iOS 8Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
iOS 9Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 10Trustedchain verified to USERTrust ECC Certification Authority
Android 11Trustedchain verified to USERTrust ECC Certification Authority
Android 12Trustedchain verified to USERTrust ECC Certification Authority
Android 13Trustedchain verified to USERTrust ECC Certification Authority
Android 13 (eng build)Trustedchain verified to USERTrust ECC Certification Authority
Android 14Trustedchain verified to USERTrust ECC Certification Authority
Android 15Trustedchain verified to Sectigo Public Server Authentication Root E46
Android 16Trustedchain verified to Sectigo Public Server Authentication Root E46
Android 2.3.1Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 3.2.4Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.0.1Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.0.2Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.0.3Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.0.4Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.1.1Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.2Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.3Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 4.4Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 5.0.0Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 5.0.2Rejectedcertificate at depth 3 (intermediate #3): Self-signed certificate in chain — a self-signed cert was encountered that is not trusted
Android 5.1Trustedchain verified to USERTrust ECC Certification Authority
Android 6.0Trustedchain verified to USERTrust ECC Certification Authority
Android 7.1Trustedchain verified to USERTrust ECC Certification Authority
Android 8.1Trustedchain verified to USERTrust ECC Certification Authority
Android 9Trustedchain verified to USERTrust ECC Certification Authority

Trust stores rebuilt from vendor-published root lists: Apple (iOS 5–26), AOSP (Android 2.3–16), LG webOS, Samsung Tizen, Amazon Fire OS. Verification: OpenSSL chain build against each store, anchored only at that store's roots.