hello i have check my site https://hsingh.ml with https://www.whynopadlock.com/ and it says that certificate is valid but when i browse my website i get the google triangle saying that the certificate is invalid.
Do you have a valid certificate on your server? If not, install one.
im using Flexible mode … do you mean cloudflare oringin certificate? i tried to istall it with cpanel but it says that the certificate is not valid for hsingh.ml
Flexible should not be chosen. Switch that to Full strict and make sure you have a proper certificate. An origin certificate should work just fine, if your server does not accept it you might also need its root certificate, which you can find on support.cloudflare.com
one more question : does this works with free plan? atm im using free plan because its tiny website for personal use.
Origin certificates works just as fine on the free plan as well.
this is what i get : The certificate uploaded is NOT for the domain name hsingh.ml ( was seen) .
Did you make sure all the hostnames are in there when you created it? Can you post the certificate (not the private key) here?
found this on : https://support.cloudflare.com/hc/en-us/articles/115000479507-Managing-Cloudflare-Origin-CA-certificates
i get the same error with origin certificate too
-----BEGIN CERTIFICATE-----
MIIEADCCAuigAwIBAgIID+rOSdTGfGcwDQYJKoZIhvcNAQELBQAwgYsxCzAJBgNV
BAYTAlVTMRkwFwYDVQQKExBDbG91ZEZsYXJlLCBJbmMuMTQwMgYDVQQLEytDbG91
ZEZsYXJlIE9yaWdpbiBTU0wgQ2VydGlmaWNhdGUgQXV0aG9yaXR5MRYwFAYDVQQH
Ew1TYW4gRnJhbmNpc2NvMRMwEQYDVQQIEwpDYWxpZm9ybmlhMB4XDTE5MDgyMzIx
MDgwMFoXDTI5MDgxNTE3MDAwMFowgYsxCzAJBgNVBAYTAlVTMRkwFwYDVQQKExBD
bG91ZEZsYXJlLCBJbmMuMTQwMgYDVQQLEytDbG91ZEZsYXJlIE9yaWdpbiBTU0wg
Q2VydGlmaWNhdGUgQXV0aG9yaXR5MRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRMw
EQYDVQQIEwpDYWxpZm9ybmlhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEAwEiVZ/UoQpHmFsHvk5isBxRehukP8DG9JhFev3WZtG76WoTthvLJFRKFCHXm
V6Z5/66Z4S09mgsUuFwvJzMnE6Ej6yIsYNCb9r9QORa8BdhrkNn6kdTly3mdnykb
OomnwbUfLlExVgNdlP0XoRoeMwbQ4598foiHblO2B/LKuNfJzAMfS7oZe34b+vLB
yrP/1bgCSLdc1AxQc1AC0EsQQhgcyTJNgnG4va1c7ogPlwKyhbDyZ4e59N5lbYPJ
SmXI/cAe3jXj1FBLJZkwnoDKe0v13xeF+nF32smSH0qB7aJX2tBMW4TWtFPmzs5I
lwrFSySWAdwYdgxw180yKU0dvwIDAQABo2YwZDAOBgNVHQ8BAf8EBAMCAQYwEgYD
VR0TAQH/BAgwBgEB/wIBAjAdBgNVHQ4EFgQUJOhTV118NECHqeuU27rhFnj8KaQw
HwYDVR0jBBgwFoAUJOhTV118NECHqeuU27rhFnj8KaQwDQYJKoZIhvcNAQELBQAD
ggEBAHwOf9Ur1l0Ar5vFE6PNrZWrDfQIMyEfdgSKofCdTckbqXNTiXdgbHs+TWoQ
wAB0pfJDAHJDXOTCWRyTeXOseeOi5Btj5CnEuw3P0oXqdqevM1/+uWp0CM35zgZ8
VD4aITxity0djzE6Qnx3Syzz+ZkoBgTnNum7d9A66/V636x4vTeqbZFBr9erJzgz
hhurjcoacvRNhnjtDRM0dPeiCJ50CP3wEYuvUzDHUaowOsnLCjQIkWbR7Ni6KEIk
MOz2U0OBSif3FTkhCgZWQKOOLo1P42jHC3ssUZAtVNXrCk3fw9/E15k8NPkBazZ6
0iykLhH1trywrKRMVw67F44IE8Y=
-----END CERTIFICATE-----
Thats the root certificate, you might need that too.
I was referring to the certificate you created?
error this time : The certificate uploaded is NOT for the domain name hsingh.ml (CloudFlare Origin Certificate was seen) .
-----BEGIN CERTIFICATE-----
MIIEnjCCA4agAwIBAgIUIK0/RVPRkepKfioNRCn48KH3kYEwDQYJKoZIhvcNAQEL
BQAwgYsxCzAJBgNVBAYTAlVTMRkwFwYDVQQKExBDbG91ZEZsYXJlLCBJbmMuMTQw
MgYDVQQLEytDbG91ZEZsYXJlIE9yaWdpbiBTU0wgQ2VydGlmaWNhdGUgQXV0aG9y
aXR5MRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRMwEQYDVQQIEwpDYWxpZm9ybmlh
MB4XDTE5MTAyNzA4MTkwMFoXDTM0MTAyMzA4MTkwMFowYjEZMBcGA1UEChMQQ2xv
dWRGbGFyZSwgSW5jLjEdMBsGA1UECxMUQ2xvdWRGbGFyZSBPcmlnaW4gQ0ExJjAk
BgNVBAMTHUNsb3VkRmxhcmUgT3JpZ2luIENlcnRpZmljYXRlMIIBIjANBgkqhkiG
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtiAkbIYEU2S0ZIl9ByW0r5hzDoeIZZuB8F6f
1DarqOpYyWLQihPh0SNRBrFrWkoc4NQ2H5BCM92QcvQbi4dmi1JD8+r89oRQ7egu
uo9wCqEIYNfAzJev5dQegYRrMWkqfXtNX+z9UGUCjQ4JZCk5HanLHDHAYiV7Un13
6Q1sviFGFxxAhlZGAdoCbfE2hirO4hz1KBPf7EobpT5W2n75TShmpZnAfEs5gWgB
8xym7ePX2QQzSo3cldaB7+SwBe+bJMpg24FSpboaS26oc2/+Fm7wC5B+lD7fpG4M
j5yUXwhMrF3006hagjqLTnX1ZOuQ6SyTzRrd7/08NwvJrHEs4QIDAQABo4IBIDCC
ARwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcD
ATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBShOjbQMxMwypKT4ayqSJ2OsXJL2jAf
BgNVHSMEGDAWgBQk6FNXXXw0QIep65TbuuEWePwppDBABggrBgEFBQcBAQQ0MDIw
MAYIKwYBBQUHMAGGJGh0dHA6Ly9vY3NwLmNsb3VkZmxhcmUuY29tL29yaWdpbl9j
YTAhBgNVHREEGjAYggsqLmhzaW5naC5tbIIJaHNpbmdoLm1sMDgGA1UdHwQxMC8w
LaAroCmGJ2h0dHA6Ly9jcmwuY2xvdWRmbGFyZS5jb20vb3JpZ2luX2NhLmNybDAN
BgkqhkiG9w0BAQsFAAOCAQEAMbTqd3dVK8O2qhrb9OLEBORa162rBGAuKfRRAes6
AbJ3VQfyGrL8a0q+yd/jLfFltOTMjFyWvUWhY+LFsDS1Rhdf0UMyS39dUC3cywHn
brJ1J3GumRPAoSm+tdveTE/BVhXnXC7nZ/XZgp5dAoLebph41rGaRbx0e0zYnBDT
iXYvQfjAmgG8r7z00dsBF6OidnxPCnJJX+K964t9V07aYxHxKX5jbH66Um9/A096
dHTvkkbskzoWDWwZEoV+3Pj/4eKRFnrCncQ0wUoCZmBR9uhTzM2L/Faj9Qjowstc
7XtlUvs3cXKW7dUqbeSo0svur3l7d4F+hkDmhScWbqMMFA==
-----END CERTIFICATE-----
That might because your domain is not in the common name but in the SANs instead. That would be something your host would need to fix.
Alternatively you can also get a Lets Encrypt certificate.
so do you suggest me to change my domain name or
i don’t know what do you mean here… how can i get that ? anyway thanks for your quick answers
Nvm just checked on google and found it
No, I am saying that your host has a problem because they do not validate the certificate properly.
This topic was automatically closed after 30 days. New replies are no longer allowed.