• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Problems with SSL Cert

tdktank59

Gawd
Joined
Jan 23, 2007
Messages
590
Not sure whats happening, my cert is about to expire so I renewed it and have installed it onto the server.

I am using CPanel (not by choice, since my clients seem to want it...)

url: http://421entertainment.com/cpanel

I get a nasty error message saying:
Secure Connection Failed

An error occurred during a connection to ssl.421entertainment.com:2083.

Peer's Certificate has been revoked.

(Error code: sec_error_revoked_certificate)
* The page you are trying to view can not be shown because the authenticity of the received data could not be verified.

* Please contact the web site owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.

Ive tried rekeying my cert, and reinstalling it multiple times. however nothing seems to get the message to go away.

Anyone got any ideas, or advice (besides get rid of cpanel, which I plan to do soon)

Got the Cert from the server, not sure what it means tho...
Averna:~ tkensiski$ openssl s_client -connect ssl.421entertainment.com:443
CONNECTED(00000003)
depth=3 /L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
verify error:num=19:self signed certificate in certificate chain
verify return:0
---
Certificate chain
0 s:/O=ssl.421entertainment.com/OU=Domain Control Validated/CN=ssl.421entertainment.com
i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
1 s:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
i:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority
2 s:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority
i:/L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
3 s:/L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
i:/L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFhDCCBGygAwIBAgIGdSpS8aTNMA0GCSqGSIb3DQEBBQUAMIHKMQswCQYDVQQG
EwJVUzEQMA4GA1UECBMHQXJpem9uYTETMBEGA1UEBxMKU2NvdHRzZGFsZTEaMBgG
A1UEChMRR29EYWRkeS5jb20sIEluYy4xMzAxBgNVBAsTKmh0dHA6Ly9jZXJ0aWZp
Y2F0ZXMuZ29kYWRkeS5jb20vcmVwb3NpdG9yeTEwMC4GA1UEAxMnR28gRGFkZHkg
U2VjdXJlIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MREwDwYDVQQFEwgwNzk2OTI4
NzAeFw0xMTAzMTQyMjIwMDVaFw0xMjAzMjUxNjIwMDdaMGkxITAfBgNVBAoTGHNz
bC40MjFlbnRlcnRhaW5tZW50LmNvbTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wg
VmFsaWRhdGVkMSEwHwYDVQQDExhzc2wuNDIxZW50ZXJ0YWlubWVudC5jb20wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCpGYsdt9knyyYID1Cu0rzMXoYc
MAmLv1UsTGqwS0/ZRV/xCv8qewNh1wfHcCSwbSfhcAL79zI7U8YTy+HcfpDaaYLf
SigQ5c1pm1RDdrB8HZHFKJNTbYKofP6KFvGqAoIfJYuq56lCz0RpB3Dv1LwxADB8
U4Z4LnSdwqrrSsvrZCx2jKkpHoIoUqzn695lF2fa8jtw3cEK+76fOjmX/dNjpFn4
9ikCipxm8iZuxsq2BvajABvZfLxtaMSvmyi1yns0+rrxfjOJncRhrPic1n7PMtVf
bGN6lF1J/dHOYtY+UPqKPw1/hMJ93ZT/8KjApwieridC3DBfCGBYH9WJkFpLAgMB
AAGjggHOMIIByjAPBgNVHRMBAf8EBTADAQEAMB0GA1UdJQQWMBQGCCsGAQUFBwMB
BggrBgEFBQcDAjAOBgNVHQ8BAf8EBAMCBaAwMwYDVR0fBCwwKjAooCagJIYiaHR0
cDovL2NybC5nb2RhZGR5LmNvbS9nZHMxLTMyLmNybDBNBgNVHSAERjBEMEIGC2CG
SAGG/W0BBxcBMDMwMQYIKwYBBQUHAgEWJWh0dHBzOi8vY2VydHMuZ29kYWRkeS5j
b20vcmVwb3NpdG9yeS8wgYAGCCsGAQUFBwEBBHQwcjAkBggrBgEFBQcwAYYYaHR0
cDovL29jc3AuZ29kYWRkeS5jb20vMEoGCCsGAQUFBzAChj5odHRwOi8vY2VydGlm
aWNhdGVzLmdvZGFkZHkuY29tL3JlcG9zaXRvcnkvZ2RfaW50ZXJtZWRpYXRlLmNy
dDAfBgNVHSMEGDAWgBT9rGEyk2xF1uLuhV+auud2mWjM5zBBBgNVHREEOjA4ghhz
c2wuNDIxZW50ZXJ0YWlubWVudC5jb22CHHd3dy5zc2wuNDIxZW50ZXJ0YWlubWVu
dC5jb20wHQYDVR0OBBYEFECr3rf2lkqhcTD4efUDXoS1UliSMA0GCSqGSIb3DQEB
BQUAA4IBAQAJr4C+rP0tEX7lO/vz7KnMSBWYnVa8g1qSStfaU+fYCvQky4AfWkK3
G04fVRaZBDIyu87buDdAdOQtKaRT1Pkf5s1IozJhk30msQvBI3NmaUSZsW3Bdf/L
z8g2Y1+pNz+Hs4m8XXIkD8DZ6nf3XxEOajGokDdHmhnzEUI3Inrmo3y3ctcA3+wI
q4SmRgpkBd1zxsqZc5DPt5LsdEmU05w+d4rEAEkaH/C09hP8CRjxI5SK/MAdtVBk
Y0u5enESDWXCJA8Y2gTWe+uESeX2cIDENlqG/E143MyYEFxguh7Bc5oFyr6Yo/yD
bUh4dRIAVocfChkSswJfCHevX07SrwjH
-----END CERTIFICATE-----
subject=/O=ssl.421entertainment.com/OU=Domain Control Validated/CN=ssl.421entertainment.com
issuer=/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287
---
No client certificate CA names sent
---
SSL handshake has read 5393 bytes and written 325 bytes
---
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA
Server public key is 2048 bit
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : DHE-RSA-AES256-SHA
Session-ID: D3B6B2A347AFFEECF27170B60FCD2691F6DFE9B9897A53855D131D15B8077573
Session-ID-ctx:
Master-Key: E0FEA7F389740D8CC80E4B2DF36F4BBE601FCA9736488AF464645BDE2485B130CA44C64AB32FE21F3F2766693DD82C14
Key-Arg : None
Start Time: 1300142772
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
 
Last edited:
sure enough....
An error occurred during a connection to ssl.421entertainment.com:2083.

Peer's Certificate has been revoked.

(Error code: sec_error_revoked_certificate)

let me do some reading, not sure if i can help, but i'll try, hopefully somebody else steps in too, asi am now interested
 
Your certificate has been revoked by the issuer. Its fairly straight forward, there is usually a reason code given in the CRL, or you can contact the issuer.

I would tell you what the reason is but Windows 7 CRL browsing window is useless (seriously only 4 keys per page and no search function, the list has thousands of entries). The list is at http://crl.godaddy.com/gds1-15.crl according to your certificate.
 
Last edited:
I just got the certificate yesterday...

I also called godaddy and they said that the cert is fine, and that it was something on my server...
 
^ It looked as though you were having trouble installing the cert and thought you would post it on the internet, glad you didn't. :)
 
Ok switched to a self signed cert...

Does not seem to fix the problem so something is wrong on the server side. As far as I can tell its installed correctly.
 
I just got the certificate yesterday...

I also called godaddy and they said that the cert is fine, and that it was something on my server...

Regardless of what GoDaddy says, I searched for and found the serial number of that cert you posted in the CRL indicated by the cert itself which means it is revoked. You can independently verify this information on your own if you don't believe me.
 
Regardless of what GoDaddy says, I searched for and found the serial number of that cert you posted in the CRL indicated by the cert itself which means it is revoked. You can independently verify this information on your own if you don't believe me.

No I trust you, Im trying to find a way to get this working.
Planning on just using a self signed for the moment until I can get godaddy to fix their shit...

However no matter what I do it wont clear out the godaddy cert...
 
Command:
Code:
wget -q -O - http://crl.godaddy.com/gds1-15.crl | openssl crl -inform DER -text | grep -A 6 -i "03ee03d63069ce"

Output:
Code:
Serial Number: 03EE03D63069CE
        Revocation Date: Mar 12 01:20:02 2011 GMT
        CRL entry extensions:
            X509v3 CRL Reason Code:
                Cessation Of Operation

Hope this helps you with your GoDaddy CSR
 
Last edited:
Back
Top