🌐
Hqcodeshop
blog.hqcodeshop.fi › archives › 304-Fixing-curl-with-Go-Daddy-Secure-Certificate-Authority-G2-CA-root.html
Fixing curl with Go Daddy Secure Certificate Authority G2 CA root - Hacker's ramblings
$ openssl x509 -hash -noout \ -in /etc/pki/tls/certs/Go\ Daddy\ Secure\ Certificate\ Authority\ -\ G2.pem · For this particular certificate, the hash is 27eb7704. The next thing is to instruct OpenSSL that this newly downloaded certificate is trusted by our server.
🌐
Experts Exchange
experts-exchange.com › questions › 29017871 › Citrix-You-have-not-chosen-to-trust-Go-daddy-Secure-Certificate-Authority-G2.html
Solved: Citrix -You have not chosen to trust Go daddy Secure Certificate Authority - G2 | Experts Exchange
April 22, 2017 - Our moderation policy strictly prohibits the use of LLM content in our Q&A threads. ... You can catch this. copy your cert to the root drive of each mac with ard then use this command from ard certtool i /Cert.crt k=/Library/Keychains/Syste ...
🌐
Reddit
reddit.com › r/citrix › mac issue - go daddy certificate authority - g2
r/Citrix on Reddit: MAC Issue - Go Daddy Certificate Authority - G2
March 15, 2025 -

Hi everyone, my company recently updated the Citrix Storefront on their end, that has caused some issues with MAC users. I am unable to connect, it says that I chose not to trust the necessary certificate which is "Go Daddy Certificate Authority - G2". I have updated the trust policy for the certificate to always trust but no luck. Any help would be greatly appreciated

🌐
Apple Community
discussions.apple.com › thread › 250753316
Citrix error - You have chose not to trust Root Certificate ...
I am getting a "You have chosen not to trust "Go Daddy Root Certifcate Authority G2..." error when trying to connect with Citrix. I have set Keychain Access to "always trust" Go Daddy but that didn't seem to help. Is there anything else I can do at my end?
🌐
Let's Encrypt
community.letsencrypt.org › help
I don't have a certificate Go Daddy Root Certificate Authority – G2 help me find it - Help - Let's Encrypt Community Support
October 21, 2021 - Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, ...
🌐
GoDaddy
certs.godaddy.com › anonymous › repository.pki
Repository
The end result is a more robust and secure system." The WebTrust review process, sponsored by the Canadian Institute of Chartered Accountants and the American Institute of Certified Public Accountants, culminated in GoDaddy's receipt of a WebTrust Seal of Assurance for Certification Authorities.
🌐
Palo Alto Networks
knowledgebase.paloaltonetworks.com › KCSArticleDetail
Importing the Traps Management Service Go Daddy G2 Root ...
Upon checking the Agent log, you may see something like the following: 2018 Dec 10 12:58:20.154-06:00 COMPUTER-A [5004:4620 #14:14] {trapsd:Communication Heartbeat(scheduled):https://hostname.traps.paloaltonetworks.com/operations/provision/register} <Critical> Server certificate for host Go Daddy Secure Certificate Authority - G2 is not allowed: error=20, message=unable to get local issuer certificate · This error message means that your endpoint is unable to validate the Certificate being offered by the Traps Management Service, and because of this it is unable to authenticate and connect. This can happen when your endpoint does not trust the Root CA Certificate.
🌐
SSL-Tools
ssl-tools.net › subjects › b6080d5f6c6b76eb13e438a5f8660ba85233344e
Go Daddy Secure Certificate Authority - G2 · SSL-Tools
CN=Go Daddy Root­ Certificate Aut­hority - G2,O=Go­Daddy.com\, Inc.­,L=Scottsdale,ST­=Arizona,C=US
🌐
Microsoft Learn
learn.microsoft.com › en-us › answers › questions › 2315431 › go-daddy
Go Daddy? - Microsoft Q&A
The "Go Daddy" certificate you’re seeing is most likely a digital security certificate, often pre-installed on devices for secure website connections. GoDaddy is a well-known Certificate Authority (CA) that provides SSL certificates, used for verifying and encrypting connections to websites. Certificates like this one may be pre-loaded by Microsoft and included on Windows devices, including your Surface Book 3. They come as part of a trusted root certificate store, which helps your device identify and trust secure websites and connections.
Find elsewhere
🌐
Reddit
reddit.com › r/sysadmin › certificates - do i have a fundamental misunderstanding?
r/sysadmin on Reddit: Certificates - Do I have a fundamental misunderstanding?
August 29, 2024 -

Hello,
I am troubleshooting an issue where Androids cannot connect to an NPS server with PEAP for RADIUS auth. All other platforms have no issue.

There are spotty errors about the certificate chain being invalid on the devices when trying to connect.

I look on my Androids certificate store and see a "Go Daddy Root Certificate Authority - G2" cert expiring in 2037.

I look on the NPS server and see the following certificate path:
GoDaddy Class 2 Certification Authority - Expires 2034
GoDaddy Root Certification Authority - G2 - Expires 2031
GoDaddy Secure Certificate Authority - Expires 2031
nps.publicname.com - expires next year

I figured oh, ok. This must be the issue. I will try to bundle the 2037 root cert into the chain and see if then the Android will trust it. I export the cert onto my laptop and am surprised to see the following in its certificate path:
GoDaddy Root Certification Authority - G2 - expires 2037 (the one I think we need)
GoDaddy Secure Certificate Authority - Expires 2031
nps.publicname.com - expires next year

Why would the certificate paths appear different for the same cert, with the same thumbprint, on two different Windows machines? I seem to have a fundamental misunderstanding I am just unable to find the answer to. Is it logical that this is the issue preventing the Androids from connecting?

I truly appreciate anyones time in helping me understand..

🌐
GoDaddy
certs.godaddy.com › repository › webtrust › en › WebTrustPrinciplesAndCriteriaEV.pdf pdf
STARFIELD TECHNOLOGIES, LLC, A SUBSIDIARY OF GODADDY, INC.
throughout the period July 01, 2024 to June 30, 2025, based on the WebTrust Principles and Criteria for Certification · Authorities – Extended Validation SSL v1.8.
Top answer
1 of 16
1

UPDATE:

Per tech support, this is a result of FBX-8221. The 12.0 release web server changed and does not provide the intermediate certificate during a TLS negotiation. It is supposed to be fixed in the 12.0.1 release.

Gregg

2 of 16
3

Hello!

I have installed a GoDaddy SSL cert into my firewall (T50 running 12.0) and it works fine for the authentication page on port 4100 as well as for the SSLVPN. I just re-keyed it using a CSR from the T50.

However, when I test it using multiple external sites such as https://sslanalyzer.comodoca.com , it shows a problem with the trust chain. That site says “Trusted by Microsoft? No (unable to get local issuer certificate) UNTRUSTED” and “Trusted by Mozilla? No (unable to get local issuer certificate) UNTRUSTED.” Others have similar wording and they look like the problem is the “Go Daddy Secure Certificate Authority - G2” cert.

Does anyone else have a Firebox with a GoDaddy SSL cert that they can test? I think it is a red herring and would like to see what results others get.

There were four certs in the GoDaddy download, and reviewing each one showed this order:
Go Daddy Class 2 Certification Authority
Go Daddy Root Certificate Authority - G2
Go Daddy Secure Certificate Authority - G2
mail.greggspublicdomain.net

There were three certs in the bundle, plus my actual cert, and I installed them from bottom of the bundle cert file to top (opened using Notepad++), then installed my cert:

“Go Daddy Class 2 Certification Authority” as IPSEC/Webserver/Other
“Go Daddy Root Certificate Authority - G2” as IPSEC/Webserver/Other
“Go Daddy Secure Certificate Authority - G2” as IPSEC/Webserver/Other
“mail.greggspublicdomain.net” as IPSEC/Webserver/Other

When connecting with Chrome to mail.greggspublicdomain.net either internally or externally, Chrome shows the complete path trusted.

Thank you for your time!

Gregg

🌐
Mozilla Bugzilla
bugzilla.mozilla.org › show_bug.cgi
926163 - Missing "Go Daddy Secure Certificate Authority - G2" certificate authority
2. NSS team should add that intermediate certificate to NSS without any trust bits set (trust inherited from the root). This will work around the problem for sites that are sending the older, wrong, intermediate. ... Brian - your statements 1-3 are correct. 4 - sort of. To maximize the browser recognition of GoDaddy SHA-2 certificates, we have cross-signed the new root with the old one. This results in two possible certificate chains: (1) end-entity --> Go Daddy Secure Certificate Authority - G2 --> Go Daddy Root Certificate Authority - G2 (self-signed root already shipped with Firefox) (2) end-entity --> Go Daddy Secure Certificate Authority - G2 --> Go Daddy Root Certificate Authority - G2 ("cross certificate" signed by SHA-1 root) --> Go Daddy Class 2 Certification Authority (SHA-1 root shipped with Firefox) 5 - no, not many.
🌐
GoDaddy
certs.godaddy.com › repository › gd_evcs-g2.crt
gd_evcs-g2.crt
Certificate: Data: Version: 3 (0x2) Serial Number: 641321477951396359 (0x8e66e7c801f1a07) Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2 Validity Not Before: May 1 07:00:00 2015 GMT Not After ...
🌐
Google Groups
groups.google.com › g › mozilla.dev.security.policy › c › jnp-TvHtkCw
Go Daddy Root Inclusion Request
After I have confirmed that the action items have been satisfactorily completed, I plan to recommend approval of Go Daddy's request to add three root certificates, enable the Websites and Code Signing trust bits for all three, and enable EV for the “Go Daddy Root Certificate · Authority - G2” and “Starfield Root Certificate Authority - G2” roots.
🌐
About SSL
aboutssl.org › go-daddy-root-certificates
Client Challenge
JavaScript is disabled in your browser · Please enable JavaScript to proceed · A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser