...
- Incomplete chain is presented: servers must provide full chain up to root CA
- Wrong certificate is presented: (e.g. the certificate is for umbrellanet.ch but the actual host name from the profile update url is umbrella.ch) Servers must always present a certificate for the correct hostname
- The certificate is issued by an untrusted CA
...
Expired / Not Yet Valid Certificate
Webservers must provide a valid SSL certificate
...
SSL Handshake failure
SSL Handshake failed. Check supported TLS versions on receiver side - usually the receiver is using outdated (insecure) encryption
...
Other Issues
Connection refused
The target server is not reachable (check firewall on receiver side)
...
Connection time out
The server did not reply within our timeout of 30 seconds
...