# Cannot verify domain with openssl

**URL:** <https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545>\
**Category:** Server\
**Created:** [February 25, 2016, 5:43pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545 "2016-02-25T17:43:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dgriffen](https://avatars.discourse-cdn.com/v4/letter/d/a698b9/32.png) [@dgriffen](https://community.letsencrypt.org/u/dgriffen)\
**Post date:** [February 25, 2016, 5:43pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/1 "2016-02-25T17:43:42Z")

</div>

I am having trouble verifying my domain with openssl, when i run:  
`openssl s_client -connect www.griffen.io:443 -CAfile /etc/ssl/certs/ca-certificates.crt`  
I get the following errors:

```
depth=0 CN = www.griffen.io
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = www.griffen.io
verify error:num=27:certificate not trusted
verify return:1
depth=0 CN = www.griffen.io
verify error:num=21:unable to verify the first certificate
verify return:1

```

But when I visit the url in the browser, the browser is fine with the certificate, what is happening and why is openssl failing to verify?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 25, 2016, 5:49pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/2 "2016-02-25T17:49:55Z")

</div>

You’ll have to refer to `fullchain.pem` in your webserver configuration, in stead of `cert.pem`.

---

<div class="post-metadata">

**Author:** ![dgriffen](https://avatars.discourse-cdn.com/v4/letter/d/a698b9/32.png) [@dgriffen](https://community.letsencrypt.org/u/dgriffen)\
**Post date:** [February 25, 2016, 5:52pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/3 "2016-02-25T17:52:34Z")

</div>

I am using the fullchain.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 25, 2016, 5:54pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/4 "2016-02-25T17:54:44Z")

</div>

Then you should reload your webserver, because it’s not showing:

```
---
Certificate chain
 0 s:/CN=www.griffen.io
   i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X1
---

```

See also: [https://www.ssllabs.com/ssltest/analyze.html?d=griffen.io&hideResults=on&latest](https://www.ssllabs.com/ssltest/analyze.html?d=griffen.io&hideResults=on&latest) (“Chain issues: Incomplete”)

**_Or_** you’re running a old version of Apache (pre 2.4.8) that requires SSLCertificateFile (`cert.pem`) _ánd_ SSLCertificateChainFile (`chain.pem`).

By the way, you really should check your servers configuration… See all the orange warnings on SSLLabs…

---

<div class="post-metadata">

**Author:** ![dgriffen](https://avatars.discourse-cdn.com/v4/letter/d/a698b9/32.png) [@dgriffen](https://community.letsencrypt.org/u/dgriffen)\
**Post date:** [February 25, 2016, 5:57pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/5 "2016-02-25T17:57:25Z")

</div>

Odd, It should have the full chain, because I never pointed it towards just cert.pem. I’m running a custom server so I’ll take a look at its documentation to see what it needs.

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [May 20, 2018, 8:59pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/6 "2018-05-20T20:59:14Z")

</div>

2 posts were split to a new topic: [Dovecot: “unable to get local issuer certificate”](https://community.letsencrypt.org/t/dovecot-unable-to-get-local-issuer-certificate/62377)

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [May 20, 2018, 8:59pm UTC](https://community.letsencrypt.org/t/cannot-verify-domain-with-openssl/11545/7 "2018-05-20T20:59:28Z")

</div>


