sudo certbot --apache

apchache 2.4.18

Server is running on site

I am getting the following in Chrome:
Your connection is not private
Attackers might be trying to steal your information from kaskie-family.no-ip.org (for example, passwords, messages, or credit cards). Learn more

With this certificate information:
SSL Server Certificate
Common Name (CN) kaskie-family.no-ip.org
Organization (O)
Organizational Unit (OU)
Common Name (CN) StartCom Class 1 DV Server CA
Organization (O) StartCom Ltd.
Organizational Unit (OU) StartCom Certification Authority
Issued On Wednesday, March 22, 2017 at 10:28:02 AM
Expires On Sunday, March 22, 2020 at 10:28:02 AM
SHA-256 Fingerprint EA EE C4 1F 51 46 F1 EC D0 50 06 9E 96 58 AC 5F
00 41 0D 85 82 F0 E7 40 2B DE 9B CD C5 DC 3A C0
SHA-1 Fingerprint 75 AF 14 AB 88 2F 03 12 C7 DD 69 C1 00 7F 80 DB
01 45 90 08

Also, my default-ssl.conf:

		ServerName kaskie-family.no-ip.org
	ServerAlias www.kaskie-family.no-ip.org

	DocumentRoot "/var/www/html"
	SSLCertificateFile /etc/letsencrypt/live/kaskie-family.no-ip.org/fullchain.pem
	SSLCertificateKeyFile /etc/letsencrypt/live/kaskie-family.no-ip.org/privkey.pem
	SSLCertificateChainFile /etc/letsencrypt/live/kaskie-family.no-ip.org/chain.pem
	Include /etc/letsencrypt/options-ssl-apache.conf



Can you try to restart the Apache?
(Just in case certbot didn’t)

Also, please run this command and share us the output. apache2ctl -S

You’re using an old certificate issued by StartCom. However, you’ve issued two certificates from Let’s Encrypt today


But your web server isn’t using either of them. Did you do something to configure your server to use the newly-issued certificates after you issued them?


I had a hard time stopping apache! Had to run “killall” but finally got it to stop. Restarted it.

Getting this now:
This site can’t provide a secure connection
kaskie-family.no-ip.org sent an invalid response.

apache2ctl -S
AH00526: Syntax error on line 21 of /etc/apache2/sites-enabled/default-ssl.conf:
SSLCertificateFile: file '/etc/letsencrypt/live/wafka.no-ip.org/fullchain.pem' does not exist or is empty
Action '-S' failed.
The Apache error log may have more information.

The error is referring to a different VirtualHost. But to be safe, I renewed that certificate.


Congratulations! You have successfully enabled https://wafka.no-ip.org

You should test your configuration at:


  • Congratulations! Your certificate and chain have been saved at:
    Your key file has been saved at:
    Your cert will expire on 2018-08-18. To obtain a new or tweaked
    version of this certificate in the future, simply run certbot again
    with the “certonly” option. To non-interactively renew all of
    your certificates, run “certbot renew”

  • If you like Certbot, please consider supporting our work by:

    Donating to ISRG / Let’s Encrypt: https://letsencrypt.org/donate
    Donating to EFF: https://eff.org/donate-le



Can you check if those are okay? (I mean, can you try to get the Apache running… with no error?)

And them the issue might just resolved.

P.S. please check if there is any duplicate vHosts which might override the host (using startcom certs). Also, check if your domain is matching with the IP address…(just in case it doesn’t…)

Still not working, but new error:

This site can’t provide a secure connection
kaskie-family.no-ip.org sent an invalid response.

I also got rid of the other vhost, just to test. and now running the apache2ctl -S shows this:

AH00526: Syntax error on line 27 of /etc/apache2/sites-enabled/default-ssl.conf:
SSLCertificateFile: file '/etc/letsencrypt/live/kaskie-family.no-ip.org/fullchain.pem' does not exist or is empty
Action '-S' failed.
The Apache error log may have more information.


And this is the results of the SSL test:

Does that file actually exist? Have you manually deleted or renamed anything within /etc/letsencrypt?


Please show these four (you can post replies individually if you like):
sudo certbot certificates
grep -Eri 'servername|serveralias' /etc/apache2
grep -Eri 'SSLProtocol|SSLCipherSuite' /etc/apache2
netstat -pant | grep -i listen

