🌐
GoDaddy
certs.godaddy.com › anonymous › repository.pki
Repository
The end result is a more robust and secure system." The WebTrust review process, sponsored by the Canadian Institute of Chartered Accountants and the American Institute of Certified Public Accountants, culminated in GoDaddy's receipt of a WebTrust Seal of Assurance for Certification Authorities.
🌐
GoDaddy
certs.godaddy.com › repository › gd_evcs-g2.crt
gd_evcs-g2.crt
Certificate: Data: Version: 3 (0x2) Serial Number: 641321477951396359 (0x8e66e7c801f1a07) Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2 Validity Not Before: May 1 07:00:00 2015 GMT Not After : May 1 07:00:00 2035 GMT Subject: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy Inc., CN=Go Daddy Secure Extended Validation Code Signing CA - G2 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:db:57:9a:8f:fb:21:e2:ab:a9:2f:10:d7:a8:c0: d9:87:f3:cc:d3:7a:b6:d5
🌐
GoDaddy
certs.godaddy.com › repository › gdroot-g2.crt
gdroot-g2.crt
-----BEGIN CERTIFICATE----- MIIDxTCCAq2gAwIBAgIBADANBgkqhkiG9w0BAQsFADCBgzELMAkGA1UEBhMCVVMx EDAOBgNVBAgTB0FyaXpvbmExEzARBgNVBAcTClNjb3R0c2RhbGUxGjAYBgNVBAoT EUdvRGFkZHkuY29tLCBJbmMuMTEwLwYDVQQDEyhHbyBEYWRkeSBSb290IENlcnRp ZmljYXRlIEF1dGhvcml0eSAtIEcyMB4XDTA5MDkwMTAwMDAwMFoXDTM3MTIzMTIz NTk1OVowgYMxCzAJBgNVBAYTAlVTMRAwDgYDVQQIEwdBcml6b25hMRMwEQYDVQQH EwpTY290dHNkYWxlMRowGAYDVQQKExFHb0RhZGR5LmNvbSwgSW5jLjExMC8GA1UE AxMoR28gRGFkZHkgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgLSBHMjCCASIw DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL9xYgjx+lk09xvJGKP3gElY6SKD E6bFIEMBO4Tx5oVJnyfq9oQbTqC023CYxzIBsQU+B07u9PpPL1kw
🌐
SSL-Tools
ssl-tools.net › subjects › b6080d5f6c6b76eb13e438a5f8660ba85233344e
Go Daddy Secure Certificate Authority - G2 · SSL-Tools
CN=Go Daddy Secure Certificate Authority - G2 · Fingerprints: 338dae5370 305cc017d8 27ac9369fa · Issuer: CN=Go Daddy Secu­re Certificate A­uthority - G2,OU­=http://certs.go­daddy.com/reposi­tory/,O=GoDaddy.­com\, Inc.,L=Sco­ttsdale,ST=Arizo­na,C=US ·
🌐
About SSL
aboutssl.org › go-daddy-root-certificates
Client Challenge
JavaScript is disabled in your browser · Please enable JavaScript to proceed · A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser
🌐
Apple Community
discussions.apple.com › thread › 250631969
Go Daddy Secure Certificate Authority - G2 - Apple Community
For some reason I've been getting Go Daddy Secure Certificate Authority - G2. I have no idea where this came from or how to get rid of it. I don't want to put in my password to continue since I have no idea if it's a phishing scam or what. It's affecting my browsing experience and blocking ...
🌐
Fyicenter
certificate.fyicenter.com › 3352_Go_Daddy_Secure_Certificate_Authority-G2_Certificate-40C2BD278ECC348330A233D7FB6CB3F0B42C80CE.html
Go Daddy Secure Certificate Authority - G2 Certificate - 40C2BD278ECC348330A233D7FB6CB3F0B42C80CE
Go Daddy Secure Certificate Authority - G2 Certificate - 40C2BD278ECC348330A233D7FB6CB3F0B42C80CE Certificate Summary: Subject: Go Daddy Secure Certificate Authority - G2 Issuer: Go Daddy Root Certificate Authority - G2 Expiration: 2031-05-03 07:00:00 UTC Key Identifier: 40:C2:BD:27:8E:CC:34:83:30:A2: 33:D7:FB:6C:B3:F0:B4:2C:80:CEReceived at FYIcenter.com on: 2018-10-24 2021-04-02, ≈11🔥, 0💬
Find elsewhere
🌐
Palo Alto Networks
knowledgebase.paloaltonetworks.com › KCSArticleDetail
Importing the Traps Management Service Go Daddy G2 Root ...
Once the mmc console is open, goto ... Click “Next” and then “Finish” and “OK”. Expand the Certificates drop down in the left pane and expand the folder “Trusted Root Certification Authorities”....
🌐
GitHub
gist.github.com › TheCakeIsNaOH › 57254dc7f99b528d495e4f4e52de7f03
Go Daddy Secure Certificate Authority - G2.crt · GitHub
Go Daddy Secure Certificate Authority - G2.crt · This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode ...
🌐
Fyicenter
certificate.fyicenter.com › 1249_Intermediate_CA_Go_Daddy_Secure_Certificate_Authority_G2_.html
Go Daddy Secure Certificate Authority - G2, http://certs.goda...
Issuer: Go Daddy Root Certificate Authority - G2, "GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, US ... Owner: CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US Issuer: CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US Serial number: 7 Valid from: Tue May 03 03:00:00 EDT 2011 until: Sat May 03 03:00:00 EDT 2031 Certificate fingerprints: MD5: 96:C2:50:31:BC:0D:C3:5C:FB:A7:23:73:1E:1B:41:40 SHA1: 27:AC:93:69:FA:F2:52:07:BB:26:27:CE:FA:CC:BE:4E:F9:C3:19:B8 S
🌐
Reddit
reddit.com › r/sysadmin › certificates - do i have a fundamental misunderstanding?
r/sysadmin on Reddit: Certificates - Do I have a fundamental misunderstanding?
August 29, 2024 -

Hello,
I am troubleshooting an issue where Androids cannot connect to an NPS server with PEAP for RADIUS auth. All other platforms have no issue.

There are spotty errors about the certificate chain being invalid on the devices when trying to connect.

I look on my Androids certificate store and see a "Go Daddy Root Certificate Authority - G2" cert expiring in 2037.

I look on the NPS server and see the following certificate path:
GoDaddy Class 2 Certification Authority - Expires 2034
GoDaddy Root Certification Authority - G2 - Expires 2031
GoDaddy Secure Certificate Authority - Expires 2031
nps.publicname.com - expires next year

I figured oh, ok. This must be the issue. I will try to bundle the 2037 root cert into the chain and see if then the Android will trust it. I export the cert onto my laptop and am surprised to see the following in its certificate path:
GoDaddy Root Certification Authority - G2 - expires 2037 (the one I think we need)
GoDaddy Secure Certificate Authority - Expires 2031
nps.publicname.com - expires next year

Why would the certificate paths appear different for the same cert, with the same thumbprint, on two different Windows machines? I seem to have a fundamental misunderstanding I am just unable to find the answer to. Is it logical that this is the issue preventing the Androids from connecting?

I truly appreciate anyones time in helping me understand..

Top answer
1 of 16
1

UPDATE:

Per tech support, this is a result of FBX-8221. The 12.0 release web server changed and does not provide the intermediate certificate during a TLS negotiation. It is supposed to be fixed in the 12.0.1 release.

Gregg

2 of 16
3

Hello!

I have installed a GoDaddy SSL cert into my firewall (T50 running 12.0) and it works fine for the authentication page on port 4100 as well as for the SSLVPN. I just re-keyed it using a CSR from the T50.

However, when I test it using multiple external sites such as https://sslanalyzer.comodoca.com , it shows a problem with the trust chain. That site says “Trusted by Microsoft? No (unable to get local issuer certificate) UNTRUSTED” and “Trusted by Mozilla? No (unable to get local issuer certificate) UNTRUSTED.” Others have similar wording and they look like the problem is the “Go Daddy Secure Certificate Authority - G2” cert.

Does anyone else have a Firebox with a GoDaddy SSL cert that they can test? I think it is a red herring and would like to see what results others get.

There were four certs in the GoDaddy download, and reviewing each one showed this order:
Go Daddy Class 2 Certification Authority
Go Daddy Root Certificate Authority - G2
Go Daddy Secure Certificate Authority - G2
mail.greggspublicdomain.net

There were three certs in the bundle, plus my actual cert, and I installed them from bottom of the bundle cert file to top (opened using Notepad++), then installed my cert:

“Go Daddy Class 2 Certification Authority” as IPSEC/Webserver/Other
“Go Daddy Root Certificate Authority - G2” as IPSEC/Webserver/Other
“Go Daddy Secure Certificate Authority - G2” as IPSEC/Webserver/Other
“mail.greggspublicdomain.net” as IPSEC/Webserver/Other

When connecting with Chrome to mail.greggspublicdomain.net either internally or externally, Chrome shows the complete path trusted.

Thank you for your time!

Gregg

🌐
Let's Encrypt
community.letsencrypt.org › help
I don't have a certificate Go Daddy Root Certificate Authority – G2 help me find it - Help - Let's Encrypt Community Support
October 21, 2021 - Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, ...