Cerbot ssl not working


when I open my website on the browser, SSL works well but when I change my IP address with VPN and reconnect to the website, the browser returns " Your connection is not private" and a red line on “https”.

NGINX lates

Ubuntu 16.4

NO


Addresses: fe80::216:3eff:feb7:c726

curl -6 https://etrix.ir/
curl: (7) Couldn’t connect to server

Connecting to etrix.ir (etrix.ir)||:443… connected.
ERROR: cannot verify etrix.ir’s certificate, issued by ‘emailAddress=ssl@cpanel.tecmint.lan,CN=cpanel.tecmint.lan’:
Self-signed certificate encountered.
ERROR: certificate common name ‘cpanel.tecmint.lan’ doesn’t match requested host name ‘etrix.ir’.


Hi @SahandMG

you have a curious configuration ( https://check-your-website.server-daten.de/?q=etrix.ir )

Your first name server has a timeout.


Domainname Http-Status redirect Sec. G
http://etrix.ir/ 301 https://etrix.ir/ 0.333 A
http://etrix.ir/ 200 0.310 H
http://www.etrix.ir/ 404 0.327 M
Not Found
https://etrix.ir/ 200 7.650 B
https://etrix.ir/ 200 2.643 N
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
https://www.etrix.ir/ 200 6.540 N
Certificate error: RemoteCertificateNameMismatch

You have two ipv4 - addresses (and one ipv6, not shown). One has the correct certificate, the other has the wrong certificate.

One from Letsencrypt, but only with one domain name:

etrix.ir - 1 entry

The other is self signed:

E=ssl@cpanel.tecmint.lan, CN=cpanel.tecmint.lan

Perhaps check your configuration. Why has the second ip a different certificate?


Thanks for your reply.
I’m not using cPanel and don’t know about the second ipV4.
How can i fix this?


You control the DNS zone.
The authoritative name server for etrix.ir is (itself):
ns1.etrix.ir internet address =
ns1.etrix.ir AAAA IPv6 address = fe80::216:3eff:feb7:c726
ns2.etrix.ir internet address =
ns2.etrix.ir AAAA IPv6 address = fe80::216:3eff:feb7:c726

FYI: fe80::216:3eff:feb7:c726 is non-routable.

