GoDaddy R1 Certificate Works in Edge but Fails in Chrome

0
4
Asked By MellowCactus47 On

I'm troubleshooting an internal IIS website that uses a GoDaddy SSL certificate. Edge considers the site secure and builds a chain through "GoDaddy TLS Root CA - R1," but Chrome stops at "GoDaddy TLS Intermediate CA DV - R1v1" and reports ERR_CERT_AUTHORITY_INVALID. I've downloaded the newer intermediate and cross-signed certificates, tried several certificate combinations, restarted IIS, and tested in Incognito mode. The site cannot be tested externally because it is internal. What is the correct certificate chain and store configuration for IIS so Chrome trusts it?

3 Answers

Answered By QuietHarbor22 On

There may be another cross-over certificate involved in the newer chain, depending on the exact GoDaddy certificate type. In one case, the missing link was the cross-certificate between the newer E1 chain and the DV certificate. Once that certificate was included in the served chain, the browser error disappeared. If TLS is terminated by a load balancer or another proxy, install the complete chain there too—not only on the IIS server. Also verify that the intermediate certificates are included in the exported PFX or explicitly configured as part of the server’s certificate chain.

Answered By AmberOtter6 On

Check every server that participates in the TLS path. The new intermediate certificates may be missing from another IIS host, proxy, or load balancer. Older certificate export workflows often omitted intermediates, so rebuild or re-export the PFX with the correct chain and confirm that the endpoint is actually presenting the updated intermediate rather than a cached or older one.

Answered By SilverMaple9 On

On the IIS server, install the certificates in the Local Computer stores rather than the Current User stores. Use the GoDaddy intermediate that matches your certificate, plus the cross-signed GoDaddy TLS Root CA - R1 whose issuer is “Go Daddy Root Certificate Authority - G2.” Make sure you do not confuse it with the self-signed R1 root, where the subject and issuer are identical. Import the chain through certlm.msc, placing the certificates under Local Computer → Intermediate Certification Authorities → Certificates. Also remove the self-signed R1 root from Local Computer → Trusted Root Certification Authorities. If Windows trusts that root locally, it may terminate the chain there instead of sending the cross-certificate, which can cause Chrome to reject the site. The older G2 root should remain trusted. If the issue returns, check whether Windows has automatically added the self-signed root again.

MellowCactus47 -

I tried that arrangement: the DV R1v1 intermediate and the cross-signed R1 certificate are in Intermediate Certification Authorities, the self-signed R1 root is removed from Trusted Root Certification Authorities, and the site certificate is in Personal. After restarting IIS, Chrome still reports the same error while Edge works.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.