Certificate name mismatch error on new certs recently made after working correctly for months

On the affected domains, we were finding that the new ones are getting diferent domains in the certs from hitch (SSL termination made to work with Varnish).

Looking back at the last time this happened, we found that memory consumption of the then 15 GB server was very high. Part of the solution then was to increase the virtual server's memory to 30 GB.

Today the consumption was again very high, particularly for hitch. We have resized this server to 60 GB and things are working better again.

It appears that when the server is running short of RAM, hitch starts to malfunction.

In terms of looking at the Apache configurations, I would note that the other older certs domains were working fine even with the problem. it was only the new ones.

For now I think we have a solution though some tuning may be needed for both Varnish and hitch on this server to ensure they use the appropriate amount of memory, child processes, etc.

Perhaps this post will help others who may have similar situations.

1 Like