Windows 10+Ampps本地站点出现ERR_SSL_SERVER_CERT_BAD_FORMAT错误求助
Let’s walk through some more targeted fixes to get your SSL-enabled tps.local domain working smoothly in Chrome, since you’ve already knocked out the common troubleshooting steps:
Verify certificate file integrity and format
Head to your Ampps installation folder (typicallyC:\Program Files\Ampps) and locate the SSL files for tps.local (check the Ampps panel’s SSL settings for the exact path). Open the certificate file (.crt or .pem) in Notepad—you should see a clean block starting with-----BEGIN CERTIFICATE-----and ending with-----END CERTIFICATE-----, no random characters or broken line breaks outside those markers. If it’s a .pfx file, double-check you imported it into the Local Computer > Trusted Root Certification Authorities store (not just your user account) when adding it to Windows.Confirm certificate and private key match
Mismatched cert and key pairs are a frequent hidden cause of this error. If you have OpenSSL installed (use Git’s bundled version if you don’t), run these commands in Command Prompt:openssl x509 -noout -modulus -in tps.local.crt | openssl md5 openssl rsa -noout -modulus -in tps.local.key | openssl md5The output hashes must be identical. If not, delete the existing SSL setup in Ampps and regenerate a new cert-key pair for tps.local.
Double-check Chrome’s certificate store
Openchrome://settings/certificates, switch to the Trusted Root Certification Authorities tab, and search for tps.local or its issuer (self-signed certs will have the same issuer and subject as the domain). If it’s missing, re-import the cert into Windows’ Local Computer store (not current user) and restart Chrome fully. Also, head tochrome://net-internals/#ssland click Clear cache to wipe any stale SSL data.Test with a fresh Chrome profile
Corrupted user profiles can cause odd SSL glitches. Create a new profile viachrome://settings/createProfile, then try accessing tps.local with that clean profile. If it works, your original profile has a problem—you can either migrate your data to the new one or reset the old profile viachrome://settings/reset.Check Windows certificate permissions
Open the Manage Computer Certificates tool (search for "Certificates" in Control Panel), find your tps.local cert under Trusted Root Certification Authorities > Certificates. Right-click it > All Tasks > Manage Private Keys, and make sure your user account (orEveryone) has Read permissions. Apply any changes and restart Chrome.Regenerate the SSL certificate in Ampps
Sometimes Ampps’ auto-generated certs have subtle formatting issues. Delete the existing SSL configuration for tps.local in the Ampps panel, then re-enable SSL for the domain. Make sure you enter the domain exactly astps.local(no spaces, uppercase letters) during generation.Validate Hosts file and DNS resolution
OpenC:\Windows\System32\drivers\etc\hostsin Notepad (run as admin) and confirm there’s an entry like127.0.0.1 tps.localwith no extra characters or conflicting entries. Runping tps.localin Command Prompt—you should get a response from127.0.0.1. If not, fix the Hosts file entry.Tweak Chrome’s experimental TLS settings
If all else fails, try adjusting these flags:- Open
chrome://flags/#allow-insecure-localhostand ensure it’s set to Enabled (fully close Chrome after changing, not just restart viachrome://restart). - Try setting
chrome://flags/#tls13-variantto Default or Disabled—sometimes TLS 1.3 variants can trigger false format errors with self-signed certs.
- Open
内容的提问来源于stack exchange,提问作者Eduardo

