Skip to content
Troubleshooting

Guests see a certificate warning before the WiFi login

A guest should never see a certificate warning on the way to a WiFi login. When they do, the network has intercepted an encrypted request and answered it with a certificate that cannot match the site the phone asked for.

Why do guests get a certificate warning on the captive portal?
The controller is intercepting HTTPS to redirect guests, and the phone correctly rejects the substitute certificate. On UniFi, switch HTTPS Redirection off in the hotspot settings. On both vendors, let the phone’s own plain HTTP connectivity check trigger the portal, and tell guests to open any http address rather than an https one.

Causes, in the order to check them

1. HTTPS redirection is switched onUniFi

Cause

With HTTPS Redirection on, UniFi answers encrypted requests itself to redirect them. The phone sees a certificate that does not belong to the site it asked for.

Check

Hotspot settings for the guest network: look for an HTTPS Redirection toggle.

Fix

Turn it off. Phones trigger the portal through their plain HTTP connectivity check, which needs no interception.

2. The guest typed or tapped an https addressPhone

Cause

Opening an https site before signing in asks the network to answer for that site. Where the network intercepts it, the phone rightly refuses the substitute certificate; where it does not, the page simply fails to load.

Check

Ask which address the guest opened. A bookmark or a browser start page is usually https.

Fix

Open any plain http:// address, or forget the network and rejoin so the login window opens by itself.

3. The portal itself is fineOmada and UniFi

Cause

The portal at www.voqadowifi.com has a valid public certificate. A warning that names your controller or an IP address is coming from the network, not the portal.

Check

Tap the warning’s details. The certificate named there tells you which device answered.

Fix

Fix the interception on the controller as above; there is nothing to change on the portal.

4. Not the same thing: ssl in Portal HealthOmada

Cause

An ssl error in Portal Health is VoqadoWiFi failing to trust your controller’s certificate on the server side. Guests never see that certificate.

Check

If guests see no warning but Portal Health shows ssl, this is the case.

Fix

Put a trusted certificate on the Omada controller address. See portal loads but WiFi never unlocks.

Questions

Can I install a certificate so the warning goes away?
Not for intercepted HTTPS. No certificate can legitimately match every site a guest might open. The fix is to stop intercepting HTTPS and rely on the HTTP connectivity check.
Is the guest’s data at risk when they see the warning?
The warning is the phone doing its job and refusing a certificate it cannot trust. Guests should not click through it; rejoining the network is the right move.

Keep reading

UniFi setup hubCaptive portal not showing on iPhoneWalled garden domainsPortal loads but the WiFi never unlocksAll troubleshooting guides

Error kinds and codes on this page are the ones the VoqadoWiFi integration records, checked against the code on 7 October 2026.

See every authorization attempt

Portal Health in the free dashboard shows each guest login with its error kind and code. One location and 25 guest logins a month, no card.

Free forever plan. No credit card and no sales call.