Error code: SEC_ERROR_REVOKED_CERTIFICATE

What is the name of the domain?

https://my.one-inside.com/ https://we.one-inside.com/

What is the error message?

Error code: SEC_ERROR_REVOKED_CERTIFICATE

What is the issue you’re encountering

Secure Connection Failed An error occurred during a connection to my.one-inside.com. Peer’s Certificate has been revoked. Error code: SEC_ERROR_REVOKED_CERTIFICATE The page you are trying to view cannot be shown because the authenticity of the received data could not be verified. Please contact the website owners to inform them of this problem. Learn more… The sites work in Safari and Chrome. After some quick Googling, this seems to be a security issue with the “OCSP” check: OCSP Checker reports both domains als invalid/revoked.

What steps have you taken to resolve the issue?

uncheck: "Query OCSP responder servers to confirm the current validity of certificate

in firefox settings

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Off

Screenshot of the error

Did you renewed your origin SSL certificate and included sub-domains, or only main (root) domain? :thinking:

One of the root or intermediate certificates has expired (110 days ago).

What kind of method are you using to renew?
Might be you’d have to update at first or you’ve got an old one?

1 Like

Yep i notice that one of the cert expired on Mon, 30 Sep 2024. And probably this is the cause for revoking the cert.
But not sure which metod we are using to renew.

I need to upgrade the root certificatr as i know right?

The wildcard certificate covering “*.one-inside.com”, which was running from Dec 2 01:18:43 2024 GMT towards Mar 2 01:18:42 2025 GMT, has been revoked.

According to the revocation reasons, this was done due to a key compromise.

crt.sh | 15580400532

As you’re not having Proxied (:orange:) records, Cloudflare isn’t involved with the certificate in question.

You will therefore need to figure out how you’re requesting the certificate(s) on your own server, and then re-start the procedures, so that you can obtain a new certificate.

If you didn’t initiate the certificate revocation on your own, then it would sound to me like someone else gained access to the private key file for the certificate.

As the reason from the certificate authority is claiming that the revocation happened due to a key compromise, I will therefore suggest that you’re looking in to your server first, in order to secure it properly.

1 Like

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.