# Cannot connect using ssl (iphone email error)

**URL:** <https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746>\
**Category:** Help\
**Created:** [March 7, 2020, 6:01pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746 "2020-03-07T18:01:40Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:01pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/1 "2020-03-07T18:01:40Z")

</div>

do i need to add my mail server ([mail.eyethrees.net](http://mail.eyethrees.net)) to my cert?  
i would assume so, right?  
and if so, what is the proper way to do that without messing up my other certs?

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [March 7, 2020, 6:03pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/2 "2020-03-07T18:03:59Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:08pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/3 "2020-03-07T18:08:45Z")

</div>

My domain is [eyethrees.net](http://eyethrees.net)  
I haven’t run any command yet  
so there’s no output yet  
my webserver is apache 2.4.6  
my OS is centos 7.7.1908  
i host this myself  
i can login to ssh (priv key access restricted)  
i so have webmin installed but use the terminal if possible  
certbot is version 1.0.0

edit: i’m going to take a walk and clear my head (back in a hour or two)

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:11pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/4 "2020-03-07T18:11:38Z")

</div>

> [@ccheath](#):
>
> do i need to add my mail server ([mail.eyethrees.net](http://mail.eyethrees.net)) to my cert?

yes, or you can get another cert for that server only.

if it's a separate machine, it's better to get a separate cert. you can get it in any usual way with certbot.

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:14pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/5 "2020-03-07T18:14:28Z")

</div>

thank you…  
it is not a separate machine (everything is all on one VPS)  
so would that be with the --expand flag??

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:15pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/6 "2020-03-07T18:15:17Z")

</div>

yep. remember to tell certbot _all_ domains that should be in the cert.

even if it’s on the same machine, you can still use different certs, though

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [March 7, 2020, 6:16pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/7 "2020-03-07T18:16:48Z")

</div>

You can also attempt to use the main domain’s certificate on that server.

(Means you can connect to `eyethrees.net` instead of `mail.eyethrees.net`)

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:22pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/8 "2020-03-07T18:22:14Z")

</div>

ugh... all? i've got like 12

after reading this help thread i remembered i had a problem with webroot and switched to the apache

> [@Correct steps to add another domain to existing certificate](https://community.letsencrypt.org/t/correct-steps-to-add-another-domain-to-existing-certificate/64654/4):
>
> S…

do i need to add the --apache flag again too when i use the --expand?

* * *

also i just tried to use [eyethrees.net](http://eyethrees.net) instead of [mail.eyethrees.net](http://mail.eyethrees.net) in the iphone add account config and that didn't work...  
to do properly do this would i need to go back to my postfix and dovecot configs and switch out [mail.eyethrees.net](http://mail.eyethrees.net) mentions for just [eyethrees.net](http://eyethrees.net) ??

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:23pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/9 "2020-03-07T18:23:36Z")

</div>

> [@ccheath](#):
>
> ugh… all? i’ve got like 12

all, in the cert. not all, you own. you can have multiple certs. but expanding a cert is not very different from issuing a new one, you need to list all the domains you want it valid for.

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:27pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/10 "2020-03-07T18:27:37Z")

</div>

not sure i follow exactly…  
so currently i have multiple certs? and i shouldn’t expand i should just add another cert?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:28pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/11 "2020-03-07T18:28:19Z")

</div>

I don't know, but you certainly can.

> [@ccheath](#):
>
> expand i should just add another cert?

This is your choice.

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:29pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/12 "2020-03-07T18:29:02Z")

</div>

ok so what command should i run then?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:30pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/13 "2020-03-07T18:30:31Z")

</div>

just run `certbot` interactively and answer its questions. if you tell some overlapping domains, it will ask to expand, otherwise it should make a separate cert.

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:30pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/14 "2020-03-07T18:30:50Z")

</div>

ok perfect thank you

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:37pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/15 "2020-03-07T18:37:30Z")

</div>

one last question… what about selecting the vhost… this is a mail server so i haven’t setup a vhost for it…

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:42pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/16 "2020-03-07T18:42:03Z")

</div>

well… something is serving that login page. maybe it’s not apache, but something is.

anyhow, you should dell your mailserver where the certificate is

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:42pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/17 "2020-03-07T18:42:33Z")

</div>

login page?  
this is postfix/dovecot

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:43pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/18 "2020-03-07T18:43:30Z")

</div>

> [@Letsencrypt certificate for mail server](https://community.letsencrypt.org/t/letsencrypt-certificate-for-mail-server/70913/6):
>
> I…

i was just noticing this reply about the -a apache and -i apache differences  
and it was suggested to just use the -a while doing a certonly  
should i try that?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 7, 2020, 6:45pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/19 "2020-03-07T18:45:43Z")

</div>

you probably already have.

you should install the cert you got into your mailserver (and config certbot to reload it on renewals, with `certbot install --deploy-hook something`)

---

<div class="post-metadata">

**Author:** ![ccheath](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ccheath/32/37143_2.png) [@ccheath](https://community.letsencrypt.org/u/ccheath)\
**Post date:** [March 7, 2020, 6:48pm UTC](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746/20 "2020-03-07T18:48:24Z")

</div>

```
 [cch@server: ~]$sudo certbot certificates
 Saving debug log to /var/log/letsencrypt/letsencrypt.log
 
 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
 Found the following certs:
   Certificate Name: server.eyethrees.net
     Domains: alatrist.com blog.chrisheath.us chrisheath.us dominusbrand.com eyethrees.net hotttsun.com mail.eyethrees.net server.eyethrees.net www.alatrist.com www.blog.chrisheath.us www.chrisheath.us www.dominusbrand.com www.eyethrees.net www.hotttsun.com
     Expiry Date: 2020-06-05 17:36:16+00:00 (VALID: 89 days)
     Certificate Path: /etc/letsencrypt/live/server.eyethrees.net/fullchain.pem
     Private Key Path: /etc/letsencrypt/live/server.eyethrees.net/privkey.pem
 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
 [cch@server: ~]$

```

so this means i have only one cert right?

[Next page](https://community.letsencrypt.org/t/cannot-connect-using-ssl-iphone-email-error/115746.md?page=2)
