` reads). %> Browsers Stopped Trusting Your Valid Certificate Because an Intermediate Certificate Was Revoked by Your CA Vendor | TLS Radar Skip to main content
outage-prevention 3 min read By TLS Radar Team

Browsers Stopped Trusting Your Valid Certificate Because an Intermediate Certificate Was Revoked by Your CA Vendor

A valid certificate can still stop working if your CA revokes the intermediate certificate it depends on. This isn't rare: in September 2026, four CAs missed a hard deadline to revoke old SHA-1-signed intermediates. Because Firefox and Chrome only catch up on their own schedules, the outage can show up weeks after the actual revocation with nothing local to explain it. TLS Radar now checks every scanned certificate chain against the CCADB's public list of revoked intermediates, free or paid.

Your certificate can be completely valid - correct dates, correct domain, nothing wrong with it - and browsers can still stop trusting it. This happens when your certificate authority (CA) revokes a middle certificate called an intermediate, which your certificate depends on to be trusted. The revocation happens on the CA's side, for reasons that have nothing to do with your certificate, and it can break your site weeks later with no warning.

What is an intermediate certificate?

An intermediate certificate links your certificate to a root that browsers already trust. You don't manage it or renew it - your browser fetches and checks it automatically every time someone visits your site. If your CA revokes that intermediate, every certificate depending on it is affected, including yours, even though your certificate itself never changed.

CAs revoke intermediates for reasons that have nothing to do with any single customer: a failed audit, an outdated signing algorithm, a missed compliance deadline. Whatever the cause, the effect on you is the same. Your certificate is fine. The document behind it isn't.

Why this doesn't happen right away

Firefox blocks a revoked intermediate once Mozilla adds it to OneCRL, a list Mozilla updates roughly once a month. Chrome blocks it only if its own revocation list, called the CRLSet, includes that intermediate. Neither happens the moment your CA revokes it. So your site can keep working normally for weeks, then start showing visitors "connection not private" warnings with no deploy, no renewal, and nothing your team touched to explain it.

This just happened, to four CAs at once

In September 2026, the CA/Browser Forum required every CA to revoke old, SHA-1-signed intermediate certificates by September 15. Four CAs missed the deadline, and all four incidents are public on Mozilla's Bugzilla:

  • GoDaddy revoked two intermediates on September 17, two days late. GoDaddy's own incident report attributes the delay to focusing on removing legacy root hierarchies rather than reviewing every affected certificate for the deadline (Mozilla Bugzilla 2072663).
  • FNMT, the Spanish CA, was notified of the miss on September 15 at 15:19 UTC and completed revocation on September 21, six days late (Mozilla Bugzilla 2073233).

In both cases, someone outside the CA caught the miss, not the CA itself. If your certificate depended on one of these intermediates, there was nothing on your end to warn you.

Is this urgent for your site right now?

Not every revoked intermediate carries the same risk. It depends on whether your certificate actually depends on the one that got revoked, or just happens to include it:

SituationWhat it means for you
The revoked intermediate is the one your certificate depends on to be trusted Fix it right away. Ask your CA to reissue against a chain it currently publishes, before Firefox's OneCRL or Chrome's CRLSet catches up.
It's an extra certificate your server sends but doesn't need Your site keeps working regardless. Clean it out of your certificate bundle on your own schedule, not as an emergency.

What TLS Radar checks

TLS Radar checks every certificate chain we scan against the CCADB's public list of revoked intermediates, on the free scan and the full scan. A revoked intermediate your chain depends on is flagged as high priority. An unused extra one is flagged too, at lower priority, so you know which situation you're actually in instead of guessing.

Check whether your chain includes a revoked intermediate

See whether any certificate in your chain traces back to an intermediate your CA has revoked - along with everything else our scanner checks. Free, no account required.

No more surprises. Sign up to get notified when an intermediate in your chain is revoked.

TLS Radar checks every certificate in your inventory against the CCADB's list of revoked intermediates, continuously. If your CA revokes something behind your certificate, you get an alert the same day, not weeks later when Firefox or Chrome catch up.

Related reading

Frequently asked questions

How can my site break if my certificate is valid?
Your certificate can be valid while the intermediate certificate behind it gets revoked by your CA, for reasons that have nothing to do with you. Once that happens, browsers eventually stop trusting the chain, even though your certificate itself never changed.
What is an intermediate certificate?
It's the certificate your CA uses to link your certificate to a root that browsers already trust. You never request or renew it yourself - your browser fetches it automatically.
Why doesn't this break my site right away?
Firefox only blocks a revoked intermediate once Mozilla adds it to OneCRL, updated roughly monthly. Chrome only blocks it if its own CRLSet includes that intermediate. So the outage can show up weeks after the revocation, with no deploy or renewal to point to.
Did this actually happen recently?
Yes. GoDaddy and FNMT both missed a September 15, 2026 deadline to revoke old SHA-1-signed intermediates, and in both cases someone outside the CA caught the miss (Mozilla Bugzilla 2072663, 2073233).
Does TLS Radar check for this?
Yes, on the free scan and the full scan. TLS Radar checks every scanned certificate chain against the CCADB's public list of revoked intermediates.

Get the next post in your inbox

TLS monitoring tips and product updates. No spam, unsubscribe anytime.

Keep reading

Comparing tools? See how TLS Radar stacks up against DigiCert and SSL.com.