Certbot certificate not secure

My domain is: facebook-authenticate.ml

I got the certbot certificate succesfully however it still shows as not secure.

I did a scan on www.whynopadlock.com and all is good except it says invalid intermediate, i dont know how to fix this error if this even is this cause of the not secure message I don't really know.

I'm setting up a gophish server as part of a pentesting course I'm taking any help would be much appreciated.

My web server is (include version): ubuntu 22.x

My hosting provider, if applicable, is: linode.com

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): latest

You keep removing questions from the questionnaire. Please don't do that. Something has gone wrong with installing the certificate so I really like to see the Certbot command you've used and its exact output:

(Also, Ubuntu is not a webserver software, but a Linux distribution a.k.a. OS.)


oh sorry
I ran this command: sudo certbot certonly --standalone

certificate issued successfully
certificate is saved at /etc/letsencrpyt ...

basically the successful message dont know how to screenshot it but hope u get the gist.


I doubt that. Your webserver is still serving just the end leaf certificate without the intermediate certificate(s). Re-running the Certbot command wouldn't have changed anything. You probably forced a renewal unnecessarily, so you now have two certificates issued: crt.sh | facebook-authenticate.ml The first one was perfectly fine already, so the only thing you've managed is adding extra load on the Let's Encrypt systems unnecessarily.

As you've used the certonly subcommand, you must have installed the certificate manually. When doing so, you probably have used cert.pem instead of fullchain.pem, thus missing the intermediate(s).

Also, I'm curious why you're using the standalone authenticator? That's usually not the best option. Although as you have not specified which webserver you're using I can't make any recommendation.


