# Cert not working without www

**URL:** <https://community.letsencrypt.org/t/cert-not-working-without-www/66521>\
**Category:** Help\
**Created:** [July 11, 2018, 9:58pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521 "2018-07-11T21:58:44Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [July 11, 2018, 9:58pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/1 "2018-07-11T21:58:44Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [www.zedelitoral.com](http://www.zedelitoral.com) / [zedelitoral.com](http://zedelitoral.com)

I ran this command: Followed this instructions\> [https://certbot.eff.org/lets-encrypt/centosrhel7-apache](https://certbot.eff.org/lets-encrypt/centosrhel7-apache)

It produced this output: I can’t remember

My web server is (include version): Apache/2.4.6

The operating system my web server runs on is (include version): CentOS 7

My hosting provider, if applicable, is: One of the shareholders of my company

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

Extra\> \>result of certbot certificate

[root@zedelitoral ~]# certbot certificates  
Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Cannot extract OCSP URI from /etc/letsencrypt/live/zedelitoral.ec/cert.pem

* * *

## Found the following certs: Certificate Name: zedelitoral.ec Domains: zedelitoral.ec www.zedelitoral.ec Expiry Date: 2018-10-07 15:20:36+00:00 (VALID: 87 days) Certificate Path: /etc/letsencrypt/live/zedelitoral.ec/fullchain.pem Private Key Path: /etc/letsencrypt/live/zedelitoral.ec/privkey.pem

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [July 11, 2018, 9:59pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/2 "2018-07-11T21:59:59Z")

</div>

If you want the cert to work with both zedelitoral.ec and www.zedelitoral.ec, you’ll need to have both names on the certificate.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [July 11, 2018, 10:04pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/3 "2018-07-11T22:04:23Z")

</div>

Hi @mvelasco93

> [@mvelasco93](#):
>
> Found the following certs:  
> Certificate Name: zedelitoral.ec  
> Domains: zedelitoral.ec www.zedelitoral.ec  
> Expiry Date: 2018-10-07 15:20:36+00:00 (VALID: 87 days)

your certificate is created correct with two names.

[https://transparencyreport.google.com/https/certificates/STKWHBTmr7VYV5A21XITg%2FJLWj8u2%2FZ51U7MtarfWXQ%3D](https://transparencyreport.google.com/https/certificates/STKWHBTmr7VYV5A21XITg%2FJLWj8u2%2FZ51U7MtarfWXQ%3D)

[https://www.zedelitoral.ec/](https://www.zedelitoral.ec/) is correct and uses this certificate.

But [https://zedelitoral.ec/](https://zedelitoral.ec/) uses a self-signed certificate.

So your Apache-configuration of zedelitoral.ec is wrong.

---

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [July 30, 2018, 9:16pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/4 "2018-07-30T21:16:27Z")

</div>

Do you know a guide for what can I check to correct this? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [July 31, 2018, 2:06pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/5 "2018-07-31T14:06:31Z")

</div>

> [@mvelasco93](#):
>
> Do you know a guide for what can I check to correct this?

The Apache Documentation should help.

What's your configuration of www.zedelitoral.ec and zedelitoral.ec

zedelitoral.ec may have the wrong certificate files.

---

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [August 1, 2018, 4:04pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/6 "2018-08-01T16:04:23Z")

</div>

httpd.conf \> [https://pastebin.com/raw/WZVebUs6](https://pastebin.com/raw/WZVebUs6)  
sites-available/zedelitoral.ec.conf \> [https://pastebin.com/raw/wK7LZQmb](https://pastebin.com/raw/wK7LZQmb)

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [August 1, 2018, 4:37pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/7 "2018-08-01T16:37:35Z")

</div>

Hi @mvelasco93,

Regarding this conf:

```
<VirtualHost *:80>
ServerAdmin info@zedelitoral.ec
ServerName zedelitoral.ec
ServerAlias *.zedelitoral.ec
DocumentRoot /var/www/html/drupal
    ErrorLog logs/error.log
    CustomLog logs/access.log combined

RewriteEngine On
RewriteCond %{HTTPS} on
RewriteCond %{HTTP_HOST} !^www.\.
RewriteRule ^/(.*)$ http://www.zedelitoral.ec$1 [R=301]
</VirtualHost>

```

If you use `RewriteCond %{HTTPS} on` on a VirtualHost that is not using TLS it never will match that condition, also `RewriteCond %{HTTP_HOST} !^www.\.` is not correct you should remove the first dot `RewriteCond %{HTTP_HOST} !^www\.`

If you only want to redirect all domains to `https:///www.zedelitoral.ec` remove those rules and add a Redirect.

```
<VirtualHost *:80>
ServerAdmin info@zedelitoral.ec
ServerName zedelitoral.ec
ServerAlias *.zedelitoral.ec
DocumentRoot /var/www/html/drupal
    ErrorLog logs/error.log
    CustomLog logs/access.log combined
Redirect permanent / https://www.zedelitoral.ec/
</VirtualHost>

```

Regarding the certificate issue with domains that are not wwww., could you please show this conf file `/etc/httpd/sites-available/zedelitoral.ec-le-ssl.conf`?.

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [August 1, 2018, 5:36pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/8 "2018-08-01T17:36:06Z")

</div>

I’ll correct the vh conf.

This the ec-le-ssl.conf \> [https://pastebin.com/raw/HLRhDMnW](https://pastebin.com/raw/HLRhDMnW)

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [August 1, 2018, 5:43pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/9 "2018-08-01T17:43:52Z")

</div>

I see no problem with that conf. Remember to reload or restart the Apache WebServer once you have modified the conf files.

---

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [August 1, 2018, 6:01pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/10 "2018-08-01T18:01:45Z")

</div>

I had done the redirect thing. So for now, it solves the problem. Thanks!

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [August 1, 2018, 6:10pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/11 "2018-08-01T18:10:49Z")

</div>

Great, now you need to know the reason why `https://zedelitoral.com` is not showing the right cert, I suppose you have defined it on another ServerName or ServerAlias taking precedence to `zedelitoral.ec-le-ssl.conf`

As a quick test you could edit `httpd.conf` file and change the order of the includes:

Before:

```
IncludeOptional conf.d/*.conf
IncludeOptional sites-enabled/*.conf
Include /etc/httpd/sites-available/zedelitoral.ec-le-ssl.conf

```

After:

```
Include /etc/httpd/sites-available/zedelitoral.ec-le-ssl.conf
IncludeOptional conf.d/*.conf
IncludeOptional sites-enabled/*.conf

```

Restart Apache and try again.

Anyway, could you please execute this command and show the output?.

`grep -Ri zedelitoral /etc/httpd/*`

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [August 1, 2018, 9:05pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/12 "2018-08-01T21:05:18Z")

</div>

I have changed the httpd conf right now.

As of the result of the grep, it was pretty extensive so the last 2000 lines were copied [https://pastebin.com/N0VWUpj5](https://pastebin.com/N0VWUpj5)

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [August 1, 2018, 9:36pm UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/13 "2018-08-01T21:36:54Z")

</div>

Great, `https://zedelitoral.ec` works fine from my side

---

<div class="post-metadata">

**Author:** ![mvelasco93](https://avatars.discourse-cdn.com/v4/letter/m/ea5d25/32.png) [@mvelasco93](https://community.letsencrypt.org/u/mvelasco93)\
**Post date:** [August 2, 2018, 1:17am UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/14 "2018-08-02T01:17:19Z")

</div>

Thank you! I will leave the redirect so it follows the www site now. If a mod check this, you can close it.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 1, 2018, 1:17am UTC](https://community.letsencrypt.org/t/cert-not-working-without-www/66521/15 "2018-09-01T01:17:29Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
