from Hacker News

GoDaddy Cert and Chrome Update = Net:Err_certificate_transparency_required

by besus on 5/2/22, 7:43 PM with 23 comments

Recent Chrome update rejects valid GoDaddy SSL certs as of this afternoon. Anyone else running into this one?
  • by joegyoung on 5/2/22, 10:13 PM

    This is GoDaddy's response to the issue --- We really appreciate your patience and time. To have the better product and user experience a patching update has been rolled out and it is currently under progress. We apologize for any inconvenience this has caused. Unfortunately, the complexity of the work is taking longer than expected and we are unable to provide any estimated time frame. Our engineer team is already working diligently to get the issue resolved at the earliest. We appreciate your patience and understanding in this matter.

    At present Google chrome version is not compatible with SSL TLS version for all registrars not only GoDaddy so most of sites are effected. So our developers are working with them to resolve the issue on high priority.

  • by groundshark on 5/2/22, 8:21 PM

    Atlassian posted that it's been resolved for Bitbucket[1]

    [1] https://bitbucket.status.atlassian.com/incidents/r6jvgswd238...

  • by jerry777777 on 5/2/22, 10:28 PM

    Hi all- I have 2 sites with SSL certs with Godaddy and both started having this exact problem a few hours ago.. only with chrome, works fine in bing and firefox. on windows 10 desktop. I tried costco.com and got the same error. Called Godaddy a minute ago and they said they can't comment on any other customers but said using chrome on his end he could access both my sites and costco without any error. My sites' certs are due to renew in 2 months. Do you think if I rekey them today and install the rekeyed certs that might solve the problem? Thanks! ~Jerry
  • by ivank on 5/3/22, 2:08 AM

  • by andyco01 on 5/2/22, 10:46 PM

    The response I got from Godaddy and worked for us:

    Chrome retired some CT logs on May 1st. For OLD certificates, that is ones issued sometime before June 2020, they might contain SCTs that have now all been retired by Google. Normally this should not be an issue, but if ALL the SCTs on a certificate are now retired, then the it looks like the most recent version of Chrome will not trust it.

    You need to rekey the SSL by generating a new CSR from hosting plan and then you need to upload the new SSL files in the hosting plan please.

  • by LinuxBender on 5/2/22, 7:56 PM

    Out of curiosity, do you get any errors in Qualys [1] or TestSSL [2]? Use the checkbox to hide your domain from results on the Qualys site. Testssl is just bash+openssl that runs from your machine.

    [1] - https://www.ssllabs.com/ssltest/

    [2] - https://github.com/drwetter/testssl.sh.git

  • by paustint on 5/2/22, 7:56 PM

    Yeah, noticed it with Bitbucket and Sendgrid - cannot access their websites from Chrome.
  • by joegyoung on 5/2/22, 8:03 PM

    I have a wildcard cert with Godaddy and all the sites with the cert cant be accessed through Chrome. Qualys reports no issues
  • by MBCook on 5/2/22, 7:53 PM

    Yes my company is. As are Costco and others.
  • by codegeek on 5/2/22, 10:26 PM

    just reported by some of our clients. We have emails sent through sendgrid and the links are throwing this error (assuming sendgrid tracking links use Godaddy SSL).
  • by vinnys72 on 5/2/22, 7:56 PM

    yes sir, opened a ticket with GoDaddy and they are stating that many people are calling in on this issue within the last few hours
  • by biohazard421 on 5/2/22, 8:56 PM

    our GoDaddy wildcard certificate is getting rejected by Chrome. In the GoDaddy chat queue currently...
  • by Alajakara on 5/2/22, 8:53 PM

    we have the same problem, somebody solved?