A browser can reject a certificate even when encryption is technically active. Common causes include a self-signed certificate, an incomplete trust chain, an expired certificate, or a certificate issued by an authority the client does not trust.
View the certificate details and identify the issuer, dates, hostname coverage, and chain. For public websites, use a certificate that chains to a certificate authority trusted by the browsers and clients that must connect.
Do not solve a public trust warning by teaching visitors to ignore it.