Dehydrated certificate doesn't turn "green" in browser

I followed this guide, twice. It “works”, because I can reach my HA from the DuckDNS domain, but the https is still insecure and I need to manually accept the browser warning.

It’s outdated or I’m missing something?

When accessing from inside you own network are you using your duckdns address or the direct IP of your HA instance?

https://myduckdns.org:8123

or

https://192.168.1.1:8123

I always use the DuckDNS url, even inside my LAN.

Check the certificate in browser. Is the cert presented to browser current cert

The certificate was correct, it was the current one with correct dates.
I had to reboot the entire server, not just HA as described in the guide to turn the browser’s label “green”.