Database access
Database access fails due to an SSL certificate error
A connection can be encrypted and still fail because the server certificate cannot be verified reliably. “Certificate verify failed” or an untrusted certificate chain concern verification of the remote endpoint. Changing a password does not automatically fix this.
- SourceClient & Driver
- Check the connectionCheck the certificate
- DestinationDatabase server
How this appears in daily operation
After a driver update, the ERP no longer connects even though the server and account appear unchanged. Microsoft ODBC Driver 18 and later enable encryption by default. This can reveal previously unnoticed certificate problems.
Distinguish typical causes
Trust chain missing
The client may not recognize the issuing certification authority or may not receive a complete chain.
Different server name
The address used may differ from the expected name in the certificate, for example after renaming or when connecting through an IP address.
Changed connection requirements
A new driver or environment may impose different encryption and certificate verification requirements.
What you can check first
Record the exact certificate error
Distinguish a chain error from a name error. Record the driver version and last change.
Compare the address with the approved configuration
Check whether the application still uses the intended server name. Passwords do not belong in the checklist.
Clarify responsibility
Who manages the server certificate and client trust? Existing certificate information and expiry dates may be inspected; production settings initially remain unchanged.
When the problem runs deeper
Skipping certificate verification does not resolve the trust issue. The appropriate approach depends on the actual server certificate, permitted names and environment. We also check which other applications require the same connection.
Encryption and trust are two separate checks
Encryption protects data in transit. Certificate verification helps identify the correct remote endpoint. Both are planned as part of a reliable connection. An unchanged error after a password change is therefore a good reason to examine the stages separately.
From an isolated error to a maintained connection
If access must be improvised after every update, documented responsibilities are often missing. We record connection requirements, certificate maintenance and an appropriate test process, making the next change more predictable.
When support makes sense
Support is useful when multiple clients are affected, the previous operator is unavailable or certificate maintenance is unclear. The exact error text and components involved are enough for an initial assessment.
The right solution pathConnect system access transparentlySources for technical assessment
Technical content reviewed on 7 October 2026. Vendor statements refer to the products named; they do not replace checking your specific configuration.
Clarify the next step together.
Your application names and a brief description of the problem are enough to start.