Proxy troubleshooting

Fix Self-signed certificate in certificate chain

Ranked causes, ordered diagnostics, and a verified remedy for self-signed certificate in certificate chain - ending with a final connection check.

Quick answer

Fix: TLS interception or wrong proxy protocol detected. Confirm endpoint values, test with curl through the endpoint, apply the matched remedy, then re-verify the exit IP is your assigned endpoint.

Exact symptom text
Causes ranked by likelihood
Ordered diagnostics
Final connection check

When this is the right fit

  • Exact symptom text
  • Causes ranked by likelihood
  • Ordered diagnostics

Who this page is for

Ranked causes, ordered diagnostics, and a verified remedy for self-signed certificate in certificate chain - ending with a final connection check.

Fix: TLS interception or wrong proxy protocol detected. Confirm endpoint values, test with curl through the endpoint, apply the matched remedy, then re-verify the exit IP is your assigned endpoint.

Diagnosis tree

Happens on every HTTPS site

Likely causes

  • - A TLS-intercepting proxy or antivirus in the path
  • - System clock far off

Verified remedy

Disable HTTPS scanning temporarily and retest; fix the system clock if the certificate dates are wrong.

Happens only through the proxy

Likely causes

  • - The endpoint is an HTTP MITM, not a tunnel
  • - Wrong port maps to a non-proxy service

Verified remedy

Confirm you are using the NobleProxy endpoint values exactly; a genuine SOCKS/HTTP tunnel never rewrites certificates.

Final connection check

  1. 1Apply the remedy for the matched symptom
  2. 2Test the endpoint directly with curl -x or --socks5-hostname
  3. 3Repeat the original action in the tool
  4. 4Confirm the exit IP is the assigned endpoint

Working connection

The original action completes and the exit IP matches the endpoint.

Broken connection

If curl through the endpoint also fails, the problem is endpoint-level: check dashboard status or swap to a spare endpoint.

Sources

Facts last reviewed 2026-09-01.

Prevent it recurring

A tunnel proxy forwards TLS untouched; certificate rewriting means something in the path is intercepting.

195+ countries
99.9% uptime guarantee
Unlimited bandwidth
4.9/5 from 127 ratings

Frequently asked questions

How do I fix Self-signed certificate in certificate chain?

Work the diagnosis tree top to bottom: confirm endpoint values, test with curl through the endpoint, apply the remedy, then run the final connection check.

Why does this keep coming back?

Recurring proxy failures usually trace to an unstable mapping - rotating endpoints or shared addresses. A dedicated static endpoint per profile makes behavior predictable.

Choose one stable proxy for every active profile

Buy self-serve now, or talk with us about a larger agency inventory.