Skip to main content

After installing the new Sectigo and sslTrus roots, the certificate chain is complete—why do some devices still show an untrusted warning?

Cause

Although third-party certificate inspection tools show that the certificate chain of Sectigo's new root certificate Sectigo Public Server Authentication Root R46 is complete and intact, older endpoints, some operating systems, and built-in root certificate stores do not have this new root pre-installed, so they cannot trust it natively.

Solution

Deploying only the new root plus intermediate certificates is not sufficient to support older devices. You must additionally configure and supply the cross-signed root certificate USERTrust RSA Certification Authority.

Building the trust chain via the cross-signed root allows older devices that do not have the new root pre-installed to validate the certificate normally and eliminate untrusted warnings.

Steps:

  1. When downloading the certificate from the Racent console, select the certificate package that includes the cross-signed root certificate
  2. On the server, deploy the cross-signed root certificate together with the site certificate (i.e., configure the complete certificate chain)
  3. After deployment, verify using an SSL inspection tool to ensure that both new and old devices can establish trusted connections normally