安装GoDaddy新SSL证书后IIS 8站点出现SEC_ERROR_REVOKED_CERTIFICATE错误求助
Hey there, let's work through this SEC_ERROR_REVOKED_CERTIFICATE issue step by step—here's what I'd check to get to the bottom of it:
First, let's confirm you're still using the correct new certificate:
- Open IIS Manager, navigate to your site, and go to Server Certificates under the site's features pane.
- Locate the GoDaddy cert you installed: verify its expiration date, issuer name, and right-click > View > go to the Details tab to check the "CRL Distribution Points" (this tells you where the server looks to confirm revocation status).
- Head to your site's Bindings (right-click site > Edit Bindings) and make 100% sure the HTTPS binding is linked to the new certificate—sometimes accidental reassignments happen after server restarts or config changes.
This error often pops up when the server/browser can't reach the CRL to verify the cert, or the CRL actually lists your new cert as revoked:
- From your server's Command Prompt, run this command to test CRL fetching and cert validation:
certutil -urlfetch -verify "C:\path\to\your\new\certificate.cer"
If you see a CRL fetch failure, it's likely a firewall/proxy blocking access to GoDaddy's CRL endpoints (they usually look likehttp://crl.godaddy.com/...). - If the output shows the cert is actually revoked, you'll need to contact GoDaddy support immediately—this could be a mistake on their end, or the cert was revoked unintentionally when you replaced the old expired one.
Cached certificate data can cause false positives even after the issue is fixed:
- Have users test the site in incognito mode, or clear their browser's SSL certificate cache (steps vary by browser, but look for "clear browsing data" > select "cached images and files" + "SSL certificates").
- On the IIS server, clear the Windows certificate cache:
- Open
certmgr.msc - Navigate to Trusted Root Certification Authorities > Certificates and delete any old GoDaddy certs or the revoked one
- Do the same in Intermediate Certification Authorities for outdated chain certs
- Open
- Restart IIS afterward with
iisresetin Command Prompt to apply changes.
GoDaddy requires intermediate certificates to be installed alongside your main cert—missing these can break revocation checks:
- In IIS Server Certificates, right-click your new cert > View > go to the Certification Path tab. If any intermediate certs show as untrusted or missing, download the correct ones from GoDaddy's certificate portal and install them in the Intermediate Certification Authorities store on your server.
Misconfigured SSL settings can interfere with revocation checks:
- Go to your site's SSL Settings in IIS: ensure Client Certificates is set to Accept or Ignore (unless you explicitly require client certs, which isn't common for public sites).
- Check your SSL protocol settings: disable outdated protocols like SSL 3.0 and ensure TLS 1.2/TLS 1.3 are enabled—old protocols can cause issues with modern CRL validation.
Looking at your C# snippet (using HttpClient and the Cognitive Services Speech SDK), make sure your code isn't overriding certificate validation incorrectly:
- If you've implemented a
ServerCertificateCustomValidationCallbackforHttpClient, double-check that it's not skipping or incorrectly enforcing revocation checks. Avoid hardcoding validation logic that bypasses default CRL checks unless absolutely necessary. - The Speech SDK may use its own HTTP client—confirm it's using the system's trusted certificate store (not a custom, outdated store) by default.
If none of these steps resolve the issue, the most probable cause is that the certificate was revoked by GoDaddy. Reach out to their support with your cert's serial number to get clarity and a replacement if needed.
内容的提问来源于stack exchange,提问作者MOHAN V

