Warning on Plesk: The CA certificate does not sign the certificate

This error can occur in Parallels Plesk panel when installing an SSL certificate. There are two main reasons for such an error:

  1. When the Certificate Authority bundle does not match the SSL certificate;
  2. If the intermediate certificates in the bundle were uploaded in an incorrect order.

plesk1

The Certificate Authority bundle is a file that contains an intermediate certificate (or several of them), and a root certificate. The intermediate certificate signs your SSL certificate, and the root certificate signs the intermediate one. These certificates, together with the certificate issued for your domain, form a certificate chain that can be recognized by browsers.

Each certificate type has its own matching CA bundle, and that is why it is important to use the correct bundle with the certificate. Otherwise, browsers can return the error when connecting to the website via HTTPS. There are several ways to make sure you are using the correct CA bundle:

  1. Download the CA bundle with the certificate issued for your domain in your Namecheap account: the instructions can be found in our article.
  2. Check if the bundle matches the certificate using this tool before installation. If the bundle matches the certificate, you will see the message as in the screenshot below:
  3. plesk2

  4. After the certificate is installed, test the website here. If the order of the certificates in the bundle is incorrect, the following message will appear:

plesk3

If the bundle is installed correctly, this message will appear instead:

plesk4

Sometimes, the CA bundle can be sent or downloaded in separate files. The files should be placed in a strict order to avoid errors during installation and in browsers when connecting to the website. For example, the order for most certificates from a Comodo CA bundle should be as follows:

COMODORSADomainValidationSecureServerCA.crt
COMODORSAAddTrustCA.crt
AddTrustExternalCARoot.crt

You can check the order of intermediate and root certificates for other SSL types here,or download a complete bundle here.

Updated
Viewed
24233 times

Need help? We're always here for you.

notmyip