Search code examples
apachegoogle-chromesslmod-ssl

Red https with cross without reason (Apache + mod_ssl)


I just added mod_ssl with a signed certificate, but I can't figure why Google chrome is marking my connection as untrusted

screenshot:

My website details

although, another website has almost the same details, but Google chrome is not marking it as untrusted:

The other website

Can someone help me, why google chrome is marking my website as untrusted?

EDIT 1 (Adding certificate information) Certificate information


Solution

  • Per Google's note on SHA-1 deprecation,

    Sites with end-entity certificates that expire on or after 1 January 2017, and which include a SHA-1-based signature as part of the certificate chain, will be treated as “affirmatively insecure”. Subresources from such domain will be treated as “active mixed content”.

    The current visual display for “affirmatively insecure” is a lock with a red X, and a red strike-through text treatment in the URL scheme.

    Google Chrome showing and “affirmatively insecure” site