Без рубрики

A reader reported receiving a message in Google Search Console about a self-signed SSL certificate. Google has been sending warnings about this for years. A self-signed SSL certificate is one that is issued by a server and not by a certificate authority (Comodo, Digicert, etc.). Self-signed SSL certificates will also cause browsers to issue a security warning, potentially affecting site traffic.

How to Check SSL Certificate Status

You can monitor and research your SSL certificate via Google’s Certificate Transparency Project tool. The Qualys SSL Labs page is a comprehensive tool for checking SSL certificate status.

If your certificate is indeed self-signed, you should consider obtaining a trusted SSL certificate. For more information read What Type of SSL Certificate Does Your Website Need?  and also Moving a WordPress Website from HTTP to HTTPS.

Some Warnings are False Positives

Some publishers have received the messages in error. These are called false positives.

A discussion in Google’s Webmaster Central Help Forum serves as an illustration. A member reported receiving the self-signed certificate message, even though his site is not self-signed. The discussion can be viewed here.

What happened was there was a small moment of time between switching certificate providers and it appears Google scanned his site in between the switch over. This is what triggered the false positive.

Here is what the publisher who received the notice stated:

“When I updated the certificate and rebooted the AWS VM I had a grub error and the VM did not restart. This is a known random quirk of this particular VM and the recovery process is to launch a new VM and restore from backup. For a 5 minute period before I remembered to block the public firewall while I rebuilt the server the nascent VM was live using the VM’s default self-signed certificate. When I opened up the firewall again the server was operating with an up-to-date Comodo certificate.

It is possible that, during that brief window, Googlebot might have polled the site…hell of a coincidence but possible…”

In another false positive report, this one from June 20th, 2018, a member reported receiving the self-signed certificate message even though their site has a valid certificate from GoDaddy.

Self-signed SSL Certificate Warniing

A member responded that it was likely in error and recommended ignoring Google’s warning about the self-signed SSL warning from Google’s Search Console.

Here is th explanation of why it was a false positive:

“This is due to the fact the server setup requires a browser to support SNI (Server Name Indication) to get the right certificate.

Pretty much all modern browsers do, there might be a very few users out there with very outdated versions that don’t.

The automated test doesn’t support it, so it gets the wrong, generic cert for the server.

The main googlebot supports it just fine though, so you are fine to disregard this, if you are not too worried about those very small percentage of users.”

Misconfigured SSL Certificates

It can be difficult to diagnose what the problem is. For one of my own websites I had certificate issues due to a secondary certificate not being properly installed.

There are instances of Lets Encrypt certificates triggering self-signed warnings. I found one in a closed and private Facebook Group. The other members were unable to help diagnose the reason so the member purchased a different certificate.

Lets encrypt certificate misconfigured leading to a self-signed certificate warning

In another case discussed on Let’s Encrypt’s forums it turns out that a technical issue related to how a dedicated server assigns certificates to multiple sites hosted on the same server was to blame for the self-signed certificate message.

Takeaway on Self-Signed SSL Certificate Warnings

If you are relying on a self-signed SSL certificate, you may wish to consider obtaining an SSL certificate from a trusted certificate authority. If you are using a trusted certificate authority and receive a warning from Google about a self-signed SSL certificate, you may wish to troubleshoot why you received this error.

In some cases the error message is received because of a misconfiguration. In others it is a false positive.

21.06.2018
self-signed-ssl-760x400

Risks in Using Self-Signed SSL Certificates

A reader reported receiving a message in Google Search Console about a self-signed SSL certificate. Google has been sending warnings about this for years. A self-signed […]
14.06.2018
no-follow-links-ranking-760x400

No Follow Links and Search Ranking

A discussion in a private Facebook group centered on whether no follow links had any SEO value. One member claimed he ranks web pages exclusively with no-follow links. […]
07.06.2018
law-firm-seo-760x400

Law Firm SEO: 5 Things You Can Do to Start Seeing Traffic & Results

Is your law firm website guilty of bad SEO? I’ve witnessed it far too many times. Law firm got bad advice. The law firm didn’t do any link […]
25.05.2018
seo-branding-760x400

The Secret to More Traffic & Better SEO? Branding

In certain SEO tribes, there is a notion that as long as a company ranks for certain keywords, they don’t need to worry too much about […]
17.05.2018
How-to-Setup-Google-Analytics-Goal-Tracking-3-760x400

How to Set up Google Analytics Goals & 7 Tips to Get Ahead

Determining objectives for a website is essential in justifying the need for a website in the first place. Creating goals for these objectives in your analytics […]
11.05.2018
google-update-florida-760x400

Google Update Florida – Why it Still Matters Today

In the early 2000’s, when Google announced an update, it usually meant a significant change in the search results. Google Update Florida in 2004 was a giant step […]
03.05.2018
knowledge-graph-2-1600x840-760x400

How to Maximize Your Reach Using Google’s Knowledge Graph

Few changes in search have had as big an impact as Google’s introduction of the Knowledge Graph in 2012. The Knowledge Graph is just one of the ways […]
26.04.2018
mobile-first-featured-image-760x400

Mobile Optimization: 12 Best Practices for the Mobile-First Era

Google’s mobile-first index is here. Now, more than ever, it’s essential to make sure that your development process includes best practices and techniques toward achieving an effective […]
18.04.2018
google-bug-xml-sitemaps-760x400

Google Black Hat Sitemap Bug: What It Means for XML Sitemaps

A few months back I discovered a shocking bug in how Google handles XML sitemaps, which enabled brand new sites to rank for competitive shopping terms […]
05.04.2018
structured-data-errors-760x400

SEO for Rich Results: How to Find & Fix Structured Data Errors

Using structured data on your website is an essential part of SEO. At its most basic, structured data helps engines understand your content better (a must as semantic web […]