Unable to download ROCK due to unsafe site warning and expired certificate (ref#X3SE4C)

Hi! What’s not quite right with Roon?

· None of the above quite fits

None of the above quite fits

· None of these quite match

Tell us what's going on

· When I try to download ROCK the browser status not safe and certificate out of date. Tried various PCs and browsers and can’t download

Tell us about your home network

· ZYXEL full fibre but I have no internet issues

I assume that you are using the link shown in step 3 of the ROCK Install Guide:

It’s working for me, so let’s see what the support team have to say when they return after their weekend break.

Thank you and yes that’s the link I am using. It has always work until now.

The reason I need to download it is due to the ROCK not updating on the server which has always worked too. It can’t be my AV as no AV installed on the ROCK so I am assuming the issue must be with my router but all other downloads I do work fine.

Hello @Simon_Jeffrey

The link is fine. We have checked it from our side, the certificate is valid, and Geoff was able to use it too. So the problem is happening somewhere between your network and our server rather than with the download itself.

What produces exactly this symptom is something on the path inspecting HTTPS traffic. It terminates the connection, re-signs it with its own certificate, and your browser correctly reports that certificate as untrusted or expired. Router-level web filtering, an ISP security or parental-control service, or a security suite on the network will all do this. The fact that it fails on several PCs and in several browsers is the strongest clue: that pattern points at the network, not at any one machine.

This is worth pursuing rather than working around, because it probably explains the real problem too. ROCK gets its updates from our servers over the same kind of connection. If something is interfering with that, ROCK would silently fail to update, which is what sent you looking for a manual download in the first place. One cause, two symptoms.

Please do this one test first, because it settles it quickly. On your phone, turn WiFi off so you are on cellular data, and open the same download link. If it downloads without a warning, the problem is on your home network.

Then please send us:

A screenshot of the warning your browser shows, and the certificate details behind it. In Chrome or Edge, click the warning, then “Certificate is not valid”, and tell us what the Issued by field says. If it names your router, your ISP, or a security product rather than a normal certificate authority, that confirms the interception.

Whether your ZYXEL router or your ISP has any web filtering, safe browsing, or parental controls switched on. Some UK providers enable network-level filtering by default.

What the ROCK Web UI shows when you try to update. If there is an error message, please include it.

Hello @vadim

Thank you for your help and the clear details you need.

It was clear to me the link works and the issue is my network/router. I can download the file from my mobile.

Screenshots attached and hope everything is as requested.

The error in Roon UI when I try to download is “There was an error checking for an update”. I have never tried to update via the ROCK web UI and was not aware you could. All I see there is “reinstall” button.

This is the error…

net::ERR_CERT_AUTHORITY_INVALID

Subject: sad.certificate.that.cannot.be.valid.com

Issuer: sad.certificate.that.cannot.be.valid.com

Expires on: Feb 11, 2028

Current date: Aug 10, 2026

PEM encoded chain:-----BEGIN CERTIFICATE-----
MIIGCTCCA/GgAwIBAgIJAJDS6ebrdaYBMA0GCSqGSIb3DQEBCwUAMIGaMQswCQYD
VQQGEwJDWjETMBEGA1UECAwKU29tZS1TdGF0ZTENMAsGA1UEBwwEQnJubzESMBAG
A1UECgwJV2hhbGVib25lMTEwLwYDVQQDDChzYWQuY2VydGlmaWNhdGUudGhhdC5j
YW5ub3QuYmUudmFsaWQuY29tMSAwHgYJKoZIhvcNAQkBFhFpbmZvQHdoYWxlYm9u
ZS5pbzAeFw0xODAyMTMxMDIyMjhaFw0yODAyMTExMDIyMjhaMIGaMQswCQYDVQQG
EwJDWjETMBEGA1UECAwKU29tZS1TdGF0ZTENMAsGA1UEBwwEQnJubzESMBAGA1UE
CgwJV2hhbGVib25lMTEwLwYDVQQDDChzYWQuY2VydGlmaWNhdGUudGhhdC5jYW5u
b3QuYmUudmFsaWQuY29tMSAwHgYJKoZIhvcNAQkBFhFpbmZvQHdoYWxlYm9uZS5p
bzCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAM3ZzP9ipDCDQnUsrXk9
WK85wAyKJ/R29Cnj3Hya0f0RaC63lH58M+lD+KLUHY4sShLjHtELocyUIGPvgann
rpjqaMhnkstYWawtU/827RzAEFgp42SCDEawQoS6BZ/84Eh20EfUGbR1n/WuieUA
rCwBDQBtBXpRCgm5hUuipweCYA3gdhWWwDLQFlYCv9gxnd+azdeQwYRQRyhE5/cT
eKiDtu2v4JWPED7g51dKaZmfYvIABXJA51vIO6LAjsFEnK2Pf8WpHnzB73WziwM/
zXqs+83+A5PWYKJS9ofg09NjaN77WAKchjds0Bstu2QIU4UebbBdxXaDAcmte2Lw
75vROYx++TUrWvcM43KPl14qkITUCu2b/uP2pap8vMr4EgkwLg9kmpeGYCxC3mh7
gybHupT9yM1BIhI6UciKGNFyQGmGFKVq/RfSGtBAKm8DKFUjTesItK+VyGYWuqxk
PatdwpAwbcxDJRkhU9j0gvH+bPKaWl6b4c30/KgAjhYvB+npSXqcfAGc8Ec5PT53
E/Za/+xp/RHVeoQQ2wNJb0wLiuGD8SKJKBRxpWEU4sISqTUJuuANb5v/pDnh+A7t
ggiKfswhZScnUzETtshlw25FHwQJypcx6gIwDMQ4iSmfehj8skyyQ07m4hHXSDLE
rgXon6fqnYXwPzyAjMwct4BBAgMBAAGjUDBOMB0GA1UdDgQWBBQPZ/L3iMCG4yFU
ku6RRhaX23/VPDAfBgNVHSMEGDAWgBQPZ/L3iMCG4yFUku6RRhaX23/VPDAMBgNV
HRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQCaZTE005rnvbKQv+hBt9nXNlDG
kP+IkBXEdHAp3noXi1iJ7zIcrnc+a9ZyL8sIvyjjjYxJLGaAktCDq8SmimYz3ljM
CVbs2YQ203kVzhT4Nt8DNZKW4fXrB5LfGHg1kvsr7GOqdXoJdiFxfbuXkxySxdZ4
rScB/cjyiBid3/91Q+wjqQENgYO2cEEcysHTg6Ea6a24Ld4MPOnH1iPtoMxghsfP
7lzVsbItUNhQ1uIUK9hj3Wtx7wfoTUD80cRhFCYFkW38H3lY054/hDxofZqaVo9L
s1SL0sAhZd/tzPJRMJ9G/UQC5+oQhMeZX7OHuOYTbzTU4wbtw+U/+cUp8bqFo7AD
UBfiD0ebLOy9WK5hhZ3O6Tw0twVr1IjEXfgypp78ppGvzPgzgggLENWBKYlNdxwT
Jlci5VKavQgfKb3arY9bVU/qLDnQGEsPdgODJwpisMmaQ1xnoUO/CCQrP7UFhqFr
GNSYzxqVhAhpLj33i74wSn+GZdGZVnm4GiKX548yiVZAihuQJ7yxcSf4BmxptItH
mfOTaMB3gnuSv0wKTKURG6HMOcru4QCdGbA26jTVE8bhIy7TMllfkoV7gAtHhGuL
36I84c0v6y4x7djNB+voILaOtSg1JfaRqJ9+ZVrRhFFMlVjUcUWLFbKfKzIsaVN+
+YbkO0iNRD2Sa4ob/g==
-----END CERTIFICATE-----

Hi @vadim

Could you please advise next steps?

Thank you

Simon

Hi @Simon_Jeffrey,

Thanks for the screenshots, those were exactly what we needed, and they tell us pretty clearly what’s happening.

This isn’t a problem with our download server, and there’s nothing malicious going on. The certificate in your screenshot isn’t ours, and it isn’t an attacker’s either. If we decode it, it identifies itself as:

Whalebone is a DNS-based network security product that ISPs and router vendors often bundle under their own branding. When it decides to block a domain, it intercepts the connection and answers with its own certificate instead of the real one, and it uses that deliberately silly name so it’s obvious the certificate isn’t meant to be trusted. That’s what Chrome is reporting.

So the sequence is: something between your PCs and the internet has download.roonlabs.net on a blocklist, so it’s substituting that certificate. Because our site uses HSTS, Chrome won’t even give you the option to click through, which is why it looks like a hard failure. And it’s the same reason ROCK reports “There was an error checking for an update”, the updater reaches for the same server, gets a certificate it can’t verify, and gives up. Two symptoms, one cause.

It works on your phone over cellular because that traffic doesn’t pass through the filtering, which fits perfectly.

A few things to check, roughly in order of likelihood:

  1. Your ISP account or app. Look for a bundled service with a name like “network protection,” “secure internet,” “safe browsing,” or similar. That’s usually where this lives. Turning it off, or asking them to allow roonlabs.net and roonlabs.com, should resolve it.
  2. Your DNS servers. In your router’s WAN/Internet settings, see what DNS servers are in use. As a quick test, set them to 1.1.1.1 and 8.8.8.8, reboot the router, and try the download again. If it works, we’ve confirmed the cause.
  3. Your ZYXEL router’s own security features. Any built-in content filtering or threat protection subscription is worth checking too.
  4. If you’re in the EU and your DNS happens to be a DNS4EU address (something like 86.54.11.1), that service is also Whalebone-operated, which would explain this directly.

Once the interception is out of the way, both the download and ROCK’s normal update check should start working again, you may not even need the reinstall.

If it turns out to be your ISP, it’d be worth letting them know they’re blocking our download host by mistake, since it’ll be affecting any of their customers running Roon. Happy to help you word that if it’s useful.

Hi @benjamin ,

Super helpful and all clear and understood.

So I have made progress but not 100% solved.

In reply to what you suggested…

  1. Your ISP account or app. Look for a bundled service with a name like “network protection,” “secure internet,” “safe browsing,” or similar. That’s usually where this lives. Turning it off, or asking them to allow roonlabs.net and roonlabs.com, should resolve it.

Simon - I have no account or app where I can alter setting but checking with my ISP they apply no blocks or filters and everything is controlled by the router

  1. Your DNS servers. In your router’s WAN/Internet settings, see what DNS servers are in use. As a quick test, set them to 1.1.1.1 and 8.8.8.8, reboot the router, and try the download again. If it works, we’ve confirmed the cause.

Simon - I changed the routers DNS to Google, Pri - 8.8.8.8 Sec - 8.8.4.4, saved and rebooted the router. This now allows my Windows PC to download Roon ROCK .IMG file so progess! This is where the “blocking” was happing".

After rebooting the Roon ROCK server I am still unable to download the update and still errors in the Roon app “There was an error checking for an update”.

Maybe the ROCK software is still retaining the old DNS settings? Is there a command prompt I can use to clear the DNS cache? I can connect a keyboard, mouse etc to the ROCK server.

Or is this something else?

  1. Your ZYXEL router’s own security features. Any built-in content filtering or threat protection subscription is worth checking too.

Simon - I have checked every page and setting and nothing is switched or filtering rules, aprental controls have always been off. Only thing I set up is the port forwarding to allow Roon ARC to work.

  1. If you’re in the EU and your DNS happens to be a DNS4EU address (something like 86.54.11.1), that service is also Whalebone-operated, which would explain this directly.

Simon - This point I feel is now not relevate as I am using Google DNS

Thanks again,

Simon

To add the Roon ROCK is set with a static IP which is out of the routers DHCP range.

I have been able to auto update the Roon ROCK for year FYI too but nothing has changed as I have reviewed this in my mind.

This is the servers network settings if this helps…

Hello,

After some research I can confirmed I have solved my problem.

I read on your support you recommend reserved DHCP IP address rather than static. I therefore set this up on my router, selected DHCP on the ROCK web UI, rebooted and now fully worked and updated to latest release.

I want to thank the support team for assisting me to getting this resolved.

In summary I needed to…

  1. In the router use a different DNS as my ISP DNS was blocking Roon, I now use Google DNS
  2. In the router setup a reserved DHCP IP address for ROCK. Set ROCK for DHCP IP and rebooted.

Thanks all!