Skip to main content

Installing GeoTrust SSL Digital Certificate comes with error.

I just renewed the SSL digital certificate of one of our web server for another one year. I'm installing and renewing SSL digital certificate for many years but this time I encounter a digital error. So I tried to troubleshoot to learn what's going on, and provide solution to fix this problem.

The renewal of digital certificate is the same process. You go to the server to create a new digital certificate, buy a SSL digital certificate from the vendor e.g. Verisign, GeoTrust, RapidSSL, and other provider, and then submit it. I choosed GeoTrust because it is very reasonable price to maintain a secure tunnel from your client internet browser to the web server.

The process is completed, the web server digital certificate is valid for another year. But I have some users complaining about "The security certificate presented by this website was not issued by a trusted certificate authority." I find out this from my Windows Vista users. I know I can ask them to check with other computer using Windows XP or Windows 7, this will work.

But I have the same users in the past so I digged more to get additional information.

I used the SSL Checker to verify the old and new digital certificates. The two web servers are using GeoTrust certificate, one certificate is not trusted in all web browsers (see the captured image above) and one is correctly listed (see the captured image on the right) in the certificate authority. I also noticed the Issuer changed from Equifax to GeoTrust DV SSL CA.

There are two solutions to resolve this certificate error. The first one is easy, let them use other computer using Windows XP or Windows 7 with IE 7.0 or latest. The second option is to follow the recommendation provided by SSL Shopper.

References:
SSL Checker. Retrieved last Sept. 8, 2010 from http://www.sslshopper.com/ssl-checker.html
SSL Certificate Not Trusted Error. Retrieved last Sept. 8, 2010 from http://www.sslshopper.com/ssl-certificate-not-trusted-error.html

Comments

Popular posts from this blog

Alternative Social Networks

If you are planning to create your  social network  e.g. similar to Facebook. Here's a short list of alternative software's: Open Source and Free​ http://buddypress.org/  - Wordpress (Open Source and Free) http://elgg.org/  - (Open Source and Free) Commercial Social Networks software http://www.socialengine.com/  ($299 Stand Alone, $29/mo Cloud) http://www.jomsocial.com/  (run with Joomla, need to know CMS) http://www.boonex.com/  (very expensive, $399 for Standard) http://www.anahitapolis.com/ http://www.oxwall.org/ http://sharetronix.com/ http://www.moosocial.com/ http://www.jcow.net/ http://phpdolphin.com http://www.grou.ps  (from free to Commercial, I left my networks and they are selling it  http://www.phpfox.com/  (I used this before, it's hard to maintain. I moved to NING but left too after it was sold to another company) http://www.ning.com  (I don't recommend using this service, it's hard to export your data when it's time to move) S

Learning Vulnerability Scanning by KING.NET

Learning Vulnerability Scanning is fun and easy. So I hope you enjoy reading this short how to guide on how to use vulnerability scanning to secure your servers and networks. NMAP is the swiss tool that you need to learn if you're serious in Cyber Security profession. The NMAP tool can be use with NSE scripting (Nmap Scripting Engine) to automate your tasks. For example using NSE Script using a  single vulnerability (cold fusion)  to scan our test lab machine. root@kali:~# nmap -v -p 80  --script http-vuln-cve2010-2861  10.11.1.220 Starting Nmap 6.47 ( http://nmap.org ) at 2016-07-22 17:34 EDT NSE: Loaded 1 scripts for scanning. NSE: Script Pre-scanning. Initiating ARP Ping Scan at 17:34 Scanning 10.11.1.220 [1 port] Completed ARP Ping Scan at 17:34, 0.04s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 17:34 Completed Parallel DNS resolution of 1 host. at 17:35, 13.01s elapsed Initiating SYN Stealth Scan at 17:35 Scanning 10.11.1.220 [1 port] Comp