New certificate gives certicicate of authority error

Rich Simpson 20 Reputation points
2026-06-21T15:31:33.6166667+00:00

New GoDaddy Certificate, after installing site Has Certificate of Authority Error

Community Center | Not monitored

2 answers

Sort by: Most helpful
  1. Maria Gerena 0 Reputation points
    2026-07-21T16:54:48.93+00:00

    I ran into a similar issue after GoDaddy began issuing new DV TLS certificates from its GoDaddy TLS Root CA – R1 hierarchy.

    GoDaddy has moved new DV certificates away from its previous G2 issuing hierarchy. Because the new R1 root is still being distributed to some browser and operating-system trust stores, GoDaddy intends servers to provide an R1-to-G2 cross-signed certificate chain during the transition. This allows clients that do not yet trust the R1 root directly to build the chain back to the already trusted GoDaddy G2 root.

    Based on the SSL Labs results posted in this thread, the Azure App Service appears to be serving only:
    Domain certificate

    └── GoDaddy TLS Intermediate CA DV – R1v1
    

    SSL Labs reports only two certificates being provided. The required GoDaddy TLS Root CA – R1 to G2 Cross Certificate does not appear to be presented, which would explain why Firefox works but Edge and Chrome return ERR_CERT_AUTHORITY_INVALID.

    Download the following bundle from GoDaddy’s certificate repository:

    GoDaddy Certificate Bundle – DV – R1 with Cross to G2, includes Root

    GoDaddy Certificate Repository

    Direct download: DV R1-to-G2 certificate bundle

    The bundle contains the R1 DV intermediate, the R1-to-G2 cross certificate, and the established G2 root.

    Rebuild the PFX using the domain certificate as the leaf certificate and the GoDaddy bundle as the additional certificate chain:

    openssl pkcs12 -export -out yourdomain-r1.pfx -inkey yourprivate.key -in yourdomain-certificate.crt -certfile gd_bundle_dv-r1-g2.crt.pem

    The PFX should contain:Your domain certificate

    GoDaddy TLS Intermediate CA DV – R1v1

    GoDaddy TLS Root CA – R1 to G2 Cross Certificate

    Go Daddy Root Certificate Authority – G2

    Upload the rebuilt PFX to Azure App Service, update the TLS binding for the custom domain, and test the site again. GoDaddy specifically states that the complete bundle must be installed rather than only the server certificate, because the bundle provides the alternate trust path needed during the R1 transition.

    After rebinding, SSL Labs should show the server providing three certificates:

    Domain certificate

    └── GoDaddy TLS Intermediate CA DV – R1v1
    
            └── GoDaddy TLS Root CA – R1, cross-signed by G2
    

    The final G2 root normally does not need to be sent by the server because it is already a client trust anchor.

    If Azure still provides only two certificates

    If the PFX contains the cross-signed certificate but SSL Labs continues to report only two certificates, Azure App Service is likely not presenting the additional cross certificate from the imported PFX. At that point, this should be raised with Azure support as an App Service certificate-chain presentation issue rather than continuing to rebuild the same PFX.

    As a diagnostic or temporary workaround on a controlled Windows device, download and install GoDaddy TLS Root CA – R1 into Trusted Root Certification Authorities:

    Direct download: GoDaddy TLS Root CA – R1

    We resolved the same R1 trust issue in a managed environment by deploying this root certificate through both Group Policy and Intune. Installing the root locally should make Edge and Chrome trust the new hierarchy and can confirm the diagnosis. However, this is only an appropriate permanent solution for managed corporate devices; a public website should provide the complete cross-signed certificate chain so visitors are not required to install a root certificate manually.

    GoDaddy references:

    Was this answer helpful?

    1 person found this answer helpful.

  2. Jerald Felix 18,760 Reputation points Volunteer Moderator
    2026-06-22T02:03:37.21+00:00

    Hello Rich Simpson,

    Greetings! Thanks for raising this question in the Q&A forum.

    This is a very common issue when working with GoDaddy certificates and Azure App Service. The "Certificate of Authority" error almost always means the .pfx file you uploaded is missing the intermediate certificate chain. GoDaddy issues the certificate in parts your domain certificate (.crt) plus one or more intermediate/bundle files (.pem) and Azure needs all of them merged together in the correct order inside a single .pfx.

    Here are clear step-by-step instructions to build the correct .pfx using OpenSSL (free and available for Windows, macOS, and Linux):

    Step 1: Identify your files from GoDaddy

    GoDaddy typically sends you:

    • yourdomain.crt — your actual domain certificate
    • gd_bundle.crt or one or more .pem files — the intermediate/chain certificates
    • You should also have your original private key file (.key) from when you generated the CSR

    Step 2: Merge the certificate and the bundle into one file

    Run this command to combine them in the correct order (leaf certificate first, then intermediates):

    cat yourdomain.crt gd_bundle.crt > mergedcertificate.crt
    

    On Windows (using Command Prompt), use:

    copy /b yourdomain.crt + gd_bundle.crt mergedcertificate.crt
    

    If GoDaddy gave you multiple .pem files instead of a single bundle, concatenate all of them in order after your domain cert:

    cat yourdomain.crt intermediate1.pem intermediate2.pem > mergedcertificate.crt
    

    Step 3: Create the .pfx file using OpenSSL

    openssl pkcs12 -export -out yourdomain.pfx -inkey yourprivate.key -in mergedcertificate.crt
    

    OpenSSL will prompt you to set an export password — make sure to remember it, as Azure will ask for it when you upload.

    Step 4: Upload the new .pfx to Azure App Service

    • Go to Azure Portal > Your App Service > Certificates
    • Under Bring your own certificates (.pfx), click + Add certificate
    • Upload your new yourdomain.pfx and enter the export password
    • Once uploaded, go to Custom domains > TLS/SSL bindings and update the binding for your custom domain to use the newly uploaded certificate

    Step 5: Verify the certificate chain is complete

    After the new certificate is live, test it at https://www.ssllabs.com/ssltest/ by entering your domain. If the chain is complete, you'll see a grade of A or A+ with no chain warnings.

    Tip: If you don't already have OpenSSL installed on Windows, you can download it from https://slproweb.com/products/Win32OpenSSL.html the Light version is sufficient.

    For reference: Configure TLS/SSL certificate in Azure App Service

    If this answer helps you kindly accept the answer which will help others who have similar questions.

    Best Regards,

    Jerald Felix.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.