Our organization recently received a GoDaddy R1 certificate, and some systems do not natively trust the new certificate hierarchy yet. To make the certificate work on certain servers, I have been downloading GoDaddy's DV R1 bundle that includes the cross-signed chain. Microsoft Edge accepts the certificate, but Chrome reports a trust error. The same issue affects the VPN web portal where users download the VPN client. I expected the portal to work if the same intermediate or cross-signed bundle were installed, but the networking team says that approach will not fix it. What certificate chain or firewall/VPN configuration is required so that browsers trust the site?
3 Answers
The trust store used by the VPN appliance matters too. If the VPN service is hosted on a firewall, verify that the required intermediate and root certificates are installed in the firewall’s appropriate certificate store, then confirm which chain the public-facing portal is actually presenting. A browser-based TLS test can reveal whether the server is omitting an intermediate or sending the wrong one.
The VPN device or firewall needs to send the complete certificate chain to connecting clients. That usually means installing the server certificate along with the correct intermediate or cross-signed certificate, rather than installing the bundle as a root certificate. The exact file format and configuration depend on the VPN vendor, so check how that platform expects its certificate chain to be uploaded.
Some devices choose a shorter chain when multiple options are installed, so make sure the appliance is presenting the chain that older clients need instead of only the newer R1 path.
Different browsers can behave differently because they may use different trust stores and chain-building rules. Edge may successfully build a path that Chrome rejects. The cross-signing certificate can help with compatibility, but it must be configured as part of the server’s delivered chain in the VPN appliance; simply downloading the bundle or adding it to one server will not change what the portal sends to users.
That is what I thought I was doing with the GoDaddy bundle, but the networking team says the VPN platform cannot use it that way. They may need the certificates uploaded separately or in a vendor-specific format.

I believe the networking team has installed the certificates on the firewall, but I do not have access to verify the configuration or see which chain the portal is sending.