Google nags me about the certificate being self-signed?

In this case, CA should be chain.pem instead of fullchain.pem.