Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: elearning.dstgroup.pt
I ran this command:
It produced this output:
My web server is (include version):Apache 2.4.6
The operating system my web server runs on is (include version):centos 7 - 6.1810.2.e17
My hosting provider, if applicable, is: on premise
I can login to a root shell on my machine (yes or no, or I don’t know): yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):no, ssh
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you’re using Certbot):certbot 1.0.0
Initially we add a certificate manually, and it worked, and is the one the broswer is pointing. This one is now expired.
meanwhile we used certbot to create a new certificate to the same domain, and to renew automatic, and is working fine, but is not being used by apache!
SSL.conf
Listen 443 https
SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog
SSLSessionCache shmcb:/run/httpd/sslcache(512000)
SSLSessionCacheTimeout 300
SSLRandomSeed startup file:/dev/urandom 256
SSLRandomSeed connect builtin
SSLCryptoDevice builtin
#SSLCryptoDevice ubsec
SSL Virtual Host Context
<VirtualHost default:443>
DocumentRoot “/var/www/html”
ServerName elearning.dstgroup.pt
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite HIGH:3DES:!aNULL:!MD5:!SEED:!IDEA
Server Certificate:
SSLCertificateFile /etc/letsencrypt/live/elearning.dstgroup.pt/cert.pem
Server Private Key:
SSLCertificateKeyFile /etc/letsencrypt/live/elearning.dstgroup.pt/privkey.pem
Server Certificate Chain:
SSLCertificateChainFile /etc/letsencrypt/live/elearning.dstgroup.pt/chain.pem
#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
<Files ~ “.(cgi|shtml|phtml|php3?)$”>
SSLOptions +StdEnvVars
<Directory “/var/www/cgi-bin”>
SSLOptions +StdEnvVars
BrowserMatch "MSIE [2-5]"nokeepalive ssl-unclean-shutdown downgrade-1.0 force-response-1.0
CustomLog logs/ssl_request_log
“%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x “%r” %b”
ServerAlias elearning.dstgroup.pt
Include /etc/letsencrypt/options-ssl-apache.conf
</VirtualHost>
Httpd.conf
<VirtualHost *:80>
DocumentRoot “/var/www/html”
ServerName elearning.dstgroup.pt
RewriteEngine on
RewriteCond %{SERVER_NAME} =elearning.dstgroup.pt
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
#Supplemental configuration
Load config files in the “/etc/httpd/conf.d” directory, if any.
IncludeOptional conf.d/*.conf
Thanks