[KB6258] "Website certificate revoked" warning blocks access to legitimate websites

Issue

  • Understand the "Website certificate revoked" warning

Solution

The "Website certificate revoked" warning appears because your ESET application has detected that a website’s security certificate is no longer valid.

If a security certificate is expired, revoked, or not updated correctly after replacement, the connection cannot be trusted, and the ESET application blocks it to protect you. This can refer to the website’s SSL/TLS certificate or to an intermediate certificate in the certificate chain (for example, the R3 certificate). Read more about resolving an expired R3 intermediate certificate.

This is not an issue with your ESET application or your device. The certificate must be fixed by the website owner, and there is no option to safely continue to the site until this is resolved.

You can use this tool to check a website's certificate chain. The results show both the SSL/TLS certificate and the intermediate certificates it depends on, helping you identify which certificate in the chain is causing the issue.

If you experience issues accessing trusted websites, clear your CRL (Certificate Revocation List) and OCSP (Online Certificate Status Protocol) cache.

Revoked SSL/TLS certificates cannot be bypassed

Revoked SSL/TLS certificates cannot be safely ignored or excluded, even in web browsers, because they represent a security risk. Access can only be bypassed by excluding the website's IP address, but most browsers will still block the connection.

We recommend accessing the website only after the certificate issue is fixed by the website owner.

Disabling SSL/TLS filtering reduces protection

We do not recommend disabling SSL/TLS filtering (or excluding your browser from SSL/TLS scanning) unless you are an experienced user. This will significantly reduce your ESET application's ability to detect threats hidden in encrypted (HTTPS) traffic.