# Certificate authority invalid

**URL:** <https://community.letsencrypt.org/t/certificate-authority-invalid/146173>\
**Category:** Help\
**Created:** [February 25, 2021, 4:56pm UTC](https://community.letsencrypt.org/t/certificate-authority-invalid/146173 "2021-02-25T16:56:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdenieul](https://avatars.discourse-cdn.com/v4/letter/j/c68b51/32.png) [@jdenieul](https://community.letsencrypt.org/u/jdenieul)\
**Post date:** [February 25, 2021, 4:56pm UTC](https://community.letsencrypt.org/t/certificate-authority-invalid/146173/1 "2021-02-25T16:56:54Z")

</div>

My domain is: [intranet.poupin.fr](http://intranet.poupin.fr)

I ran this command: sudo certbot certonly --standalone -d [intranet.poupin.fr](http://intranet.poupin.fr)

It produced this output: Congratulations ! Your certificate and chaine have been save at ..

My web server is (include version): AWS / Apache/ 2.4.43 (Unix)

The operating system my web server runs on is (include version): Lightsail / bitnami

My hosting provider, if applicable, is: aws

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 0.31.0

Hi,

I have the alert message "ERR\_CERT\_AUTHORITY\_INVALID" when i am going to my website [https://intranet.poupin.fr/](https://intranet.poupin.fr/).  
I dont understand why ?  
I don't have any problem for generate the certificate with certbot and i have the congratulations message ..  
I have already reboot my apache services and the server.

How can i debug this ?

Thanks ,

J.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 25, 2021, 5:01pm UTC](https://community.letsencrypt.org/t/certificate-authority-invalid/146173/2 "2021-02-25T17:01:55Z")

</div>

Hi @jdenieul

> [@jdenieul](#):
>
> I dont understand why ?

the result is expected. `certonly` doesn't install the certificate and doesn't restart the service you want to use the certificate.

A restart is required.

PS: The site is public. There isn't an expired certificate, there is a self signed. So you have to install the certificate.

```nohighlight
certbot --reinstall -d intranet.poupin.fr

```

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [February 25, 2021, 6:33pm UTC](https://community.letsencrypt.org/t/certificate-authority-invalid/146173/3 "2021-02-25T18:33:54Z")

</div>

> [@JuergenAuer](#):
>
> the result is expected. `certonly` doesn't install the certificate and doesn't restart the service you want to use the certificate.

@jdenieul, you might want to use `--apache` in this case instead of `certonly --standalone`.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 27, 2021, 6:33pm UTC](https://community.letsencrypt.org/t/certificate-authority-invalid/146173/4 "2021-03-27T18:33:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
