How to identify which SSL certificate is being used on a site
GoDaddy SSL Cert Problem - Firefox and Edge
Are GoDaddy SSL Certificates Necessary with Cloudflare?
GoDaddy SSL and domain issues
Videos
I’m dealing with a GoDaddy SSL cert issue that GoDaddy is unable to solve themselves. I have an SSL cert I purchased from GoDaddy and because of how they handled another problem for me part of the certificate has been revoked and they can’t seem to understand this even though it’s easy to see and get verified by a 3rd party SSL checker.
The site won’t load in Firefox or Edge because of this problem. It does load in Chrome currently.
Here’s the part that is broken even after I’ve rekeyed the cert 3 times at GoDaddys request:
SSL Certificate is revoked
The certificate has been revoked. You should replace it with a new certificate as soon as possible.
OCSP Staple:
Not Enabled
OCSP Origin:
Revoked
CRL Status:
Revoked
One of the checkers that GoDaddy uses when I contact their support doesn’t show them this detail so they aren’t aware of it even though I’ve told multiple support people that this is the case.
How do I fix this?
Thanks!
Why not re-issue the cert? Create a new CSR, get a new cert, install the new cert. It should be free to do so.
Gregg
You shouldn't put an intermediate certificate in the CA Certificate field, that'll break your certificate trust chain.
The intermediate certificate should be appended in the .crt file for your cert BEFORE your actual certificate in order to respect the chain, so both should be in one file and show in order.
Check the site at http://www.sslshopper.com/ssl-checker.html to make sure it is giving out the Intermediate certificates. If it is not, try following the guide for installing SSL certs in Plesk: http://download1.swsoft.com/Plesk/Plesk8.1/Doc/plesk-8.1-unix-administrators-guide/
Verify that the correct intermediate certificates are being given out by the server at http://www.sslshopper.com/ssl-checker.html
As martona suggested, you may need to use a different bundle.
You may be using the wrong cert chain. I assume your "gd_bundle2.crt" is the same as "gd_bundle.crt" on this page: https://certs.godaddy.com/anonymous/repository.seam
That gd_bundle.crt chain has a "Go Daddy Class 2 Certification Authority" that verifies up to a Valicert root. I don't think this is valid anymore - GoDaddy seems to issue certs that are signed by "Go Daddy Secure Certification Authority" that is in turn signed by a different, self-signed "Go Daddy Class 2 Certification Authority" - not the Valicert-issued one in your chain, so it has nothing to do with your actual certificate.
Go to the page referenced above, download "gd-class2-root.crt" then download "gd_intermediate.crt". Concatenate the two files (they're just plain text files) into "mybundle.crt" and specify this new file in SSLCertificateChainFile. See if that makes a difference.