SnapshotThis is a frozen record of the check as it ran — the live certificate may have changed since. Re-check this domain now
Trusted nowhere — anchored at a private, self-signed CA
self-signed.badssl.com · snapshot taken Aug 29, 2026, 03:25 PM · chain of 1 · 78 trust stores
Coverage
share of version-pinned trust stores78
Trust stores checked
0
Trusted
78
Rejected
0
Not verifiable
Why it fails — 1 root cause behind 78 rejections
grouped, not 78 rows of openssl outputRoot cause 178 platforms
The chain ends at a self-signed certificate ("*.badssl.com") that no public store trusts
The chain's top certificate is signed by itself and is not present in any public trust store. Stores report "self-signed certificate in chain".
Android 10Android 11Android 12Android 13Android 13 (eng build)Android 14Android 15Android 16Android 2.3.1Android 3.2.4Android 4.0.1Android 4.0.2Android 4.0.3Android 4.0.4Android 4.1.1Android 4.2Android 4.3Android 4.4Android 5.0.0Android 5.0.2Android 5.1Android 6.0Android 7.1Android 8.1Android 9Fire OS Signage StickiOS 10iOS 11iOS 12iOS 12.1.3iOS 13iOS 13.4iOS 14iOS 14.2iOS 15iOS 15.1iOS 16iOS 16.5iOS 17iOS 17.4iOS 18iOS 26iOS 5iOS 6iOS 7iOS 8iOS 9Tizen S · 1130.2Tizen T · 2140.2Tizen T · 2170.0webOS 3.0 · 55EF5C/55EV5CwebOS 3.0 · 55TC3CDwebOS 3.0 · 65EE5PCwebOS 3.0 · 65EV5CwebOS 3.0 · 75XF3ESwebOS 3.0 · EH5CwebOS 3.0 · EJ5CwebOS 3.0 · SM3C/SM5C/SM5KC/UH5C/75XS2CwebOS 3.0 · SM5C/SM5KC/UH5C/LS73C/LS73D/LS75CwebOS 3.0 · XEB3E/XF1EwebOS 3.0 · XS2C/XF3C/XE3E/XE3CwebOS 3.0 · XS2DwebOS 3.0 · XS4F/XF3E/XS2EwebOS 3.2 · 55EF5EwebOS 3.2 · 55EG5CEwebOS 3.2 · 55EJ5EwebOS 3.2 · 55SVH7EwebOS 3.2 · 55VX1DwebOS 3.2 · 65EV5E/EJ5EwebOS 3.2 · 86TR3D/TC3D/TR3EwebOS 3.2 · SM5D/EJ5D/EG5CDwebOS 3.2 · SM5D/SM5KDwebOS 3.2 · TA3EwebOS 3.2 · VL5D/VL5PFwebOS 3.2 · wp320webOS 4.0 · EF5G/EF5K/EJ5G/EJ5K/EW5G/EW5PG/EW5TF/EW5TKwebOS 4.0 · SH7E/SM5KE/UH5E/WP400webOS 4.0 · wp400
The certificate
as captured at check timeSubject
C=US, ST=California, L=San Francisco, O=BadSSL, CN=*.badssl.com
Issuer
C=US, ST=California, L=San Francisco, O=BadSSL, CN=*.badssl.com
Serial
f4:a9:84:f3:1c:49:0d:43
Valid from
Aug 25 21:00:32 2026 GMT
Valid until
Aug 24 21:00:32 2028 GMT727 days
Signature
sha256WithRSAEncryption · rsaEncryption 2048 bits
SHA-256 fingerprint
61:0e:8c:70:05:ed:7a:87:30:48:03:81:60:65:21:02:2d:f6:91:b1:ae:a4:76:56:6f:51:bb:a1:78:d6:7b:5b
Subject alternative names
DNS:*.badssl.comDNS:badssl.com
leaf
End entity
*.badssl.com
Aug 25 21:00:32 2026 GMT → Aug 24 21:00:32 2028 GMT · rsaEncryption 2048 bits
Every store, one by one
Trust stores rebuilt from vendor-published root lists: Apple (iOS 5–26), AOSP (Android 2.3–16), LG webOS, Samsung Tizen, Amazon Fire OS. Verification: OpenSSL chain build against each store, anchored only at that store's roots.