Backup Certificate work?

What is the name of the domain?

www.jemberkab.go.id

website proxy enabled : disposisi.jemberkab.go.id
website proxy disabled : tte.jemberkab.go.id

What is the issue you’re encountering

Origin server SSL Certificate has renewed, but still cover by Google Trust Services

What are the steps to reproduce the issue?

Our domain SSL configured as Full Strict using Sectigo. It will expired on September 3, 2024 (7 days).
We have renewed this SSL and deployed into origin server, extend until September 23, 2025.
However, those new certificate only appear in browser for our website that isn’t enable Cloudflare Proxy.
For website that enable Cloudflare Proxy, is showed issued by Google Trust Services.

Is that due to handled by Cloudflare Backup Certificates ? As thread below :

If so, my question is :

  1. How many remaining expired days that trigger Backup Certificates active ?
  2. Will it switch automatically to origin server Sectigo SSL after Backup Certificates validity ends (90 days) ?

If you are using Universal SSL, Cloudflare will obtain and update around every 60 days an SSL certificate for use on the edge. Clients connecting via proxied DNS records will see this certificate and not your origin SSL certificate…

Cloudflare’s proxy will see your origin SSL certificate when it connects and uses that to secure the Cloudflare-to-origin connection so it is important to keep a valid SSL certificate on the origin.

Using your own SSL certificate on the Cloudflare edge requires a Business or Enterprise plan…

1 Like

I got it. Thanks

Out of curiosity, I visited your website, and I was immediately blocked. (Cloudflare Ray ID: 8ba05d66dea3b8c1 )

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.