You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EC2 Ubuntu实例Apache2更新GoDaddy SSL证书后仍显示旧过期证书问题

SSL证书更新后浏览器仍显示过期证书问题排查记录

该网站此前安装GoDaddy的SSL运行正常,目前SSL已过期约1个月,且首次申请SSL时使用的CSR文件已丢失。

已尝试操作步骤:

  • 在/etc/apache2/ssl目录下执行如下命令生成新的CSR文件:
    openssl req -new -newkey rsa:2048 -nodes -keyout mysite.com.key -out mysite.com.csr
    
  • 使用新生成的CSR在GoDaddy平台申请新的SSL证书,下载压缩包并上传至服务器,压缩包内含3个文件。
  • 将所有证书文件移动到/etc/apache2/ssl目录下,当前该目录共5个文件,列表如下:
    -rw------- root:root mysite.com.key
    -rw------- root:root mysite.com.csr
    -rw-r--r-- root:root 0000000000.crt
    -rw-r--r-- root:root 0000000000.pem
    -rw-r--r-- root:root gd_bundle-g2-g1.crt
    
  • 按如下配置更新VirtualHost虚拟主机设置:
    <VirtualHost *:443>
         ServerName www.mysite.com
         ServerAlias *.mysite.com
         DocumentRoot /var/www/html/mysite/public
    
         SSLEngine on
         SSLCertificateFile /etc/apache2/ssl/0000000000.crt
         SSLCertificateKeyFile /etc/apache2/ssl/mysite.com.key
         SSLCertificateChainFile /etc/apache2/ssl/gd_bundle-g2-g1.crt
    
         <Directory /var/www/html/mysite/public/>
                 Options Indexes FollowSymLinks MultiViews
                 AllowOverride All
                 Require all granted
         </Directory>
    </VirtualHost>
    
  • 成功执行如下命令重载配置:
    sudo a2dissite mysite-ssl.conf
    sudo a2ensite mysite-ssl.conf
    sudo systemctl reload apache2
    
  • 在服务器内执行如下命令检测,返回结果显示加载的是正确的新证书:
    openssl s_client -connect localhost:443
    

当前问题:
浏览器访问网站时仍显示旧的过期SSL证书,有效期未更新。
错误截图

更多尝试:
尝试安装免费SSL证书后,浏览器访问该域名仍返回GoDaddy的旧过期证书。

最新发现:
GoDaddy域名解析面板中有如下2条A记录配置,不确定是否为故障原因:

Type    Host        Points to
A       @           PROXIED
A       starkip     123.123.123.123

内容的提问来源于stack exchange,提问作者zarpio

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 09:54:03