# Certificate problem

**URL:** <https://community.letsencrypt.org/t/certificate-problem/157356>\
**Category:** Help\
**Created:** [August 8, 2021, 4:16am UTC](https://community.letsencrypt.org/t/certificate-problem/157356 "2021-08-08T04:16:00Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 4:16am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/1 "2021-08-08T04:16:00Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:jpedmedia.com

I ran this command:certbot --nginx, then certbot certificates

It produced this output:Found the following certs:  
Certificate Name: [jpedmedia.com](http://jpedmedia.com)  
Domains: [jpedmedia.com](http://jpedmedia.com) [mail.jpedmedia.com](http://mail.jpedmedia.com) notmyown.xyz [www.jpedmedia.com](http://www.jpedmedia.com) [www.mail.jpedmedia.com](http://www.mail.jpedmedia.com) www.notmyown.xyz  
Expiry Date: 2021-11-06 02:38:38+00:00 (VALID: 89 days)  
Certificate Path: /etc/letsencrypt/live/jpedmedia.com/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/jpedmedia.com/privkey.pem  
Certificate Name: [mail.jpedmedia.com](http://mail.jpedmedia.com)  
Domains: [mail.jpedmedia.com](http://mail.jpedmedia.com) [www.mail.jpedmedia.com](http://www.mail.jpedmedia.com)  
Expiry Date: 2021-11-06 02:47:44+00:00 (VALID: 89 days)  
Certificate Path: /etc/letsencrypt/live/mail.jpedmedia.com/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/mail.jpedmedia.com/privkey.pem  
Certificate Name: notmyown.xyz  
Domains: notmyown.xyz www.notmyown.xyz  
Expiry Date: 2021-11-06 02:58:57+00:00 (VALID: 89 days)  
Certificate Path: /etc/letsencrypt/live/notmyown.xyz/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/notmyown.xyz/privkey.pem

My web server is (include version):nginx

The operating system my web server runs on is (include version):debian 10

My hosting provider, if applicable, is:vultr

I can login to a root shell on my machine (yes or no, or I don't know):yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):0.31.0

I got a renewal email that stated my certs were expiring, so i logged into my server and ran certbot --nginx and updated my certs, then ran certbot certificates and verifed they are all renewed, my websites, [jpedmedia.com](http://jpedmedia.com) and notmyown.xyz work fine but i cannot sync my mail server, [mail.jpedmedia.com](http://mail.jpedmedia.com), to my email client, it tells me my cert is expired everytime. how do i fix this issue?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 8, 2021, 4:29am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/2 "2021-08-08T04:29:09Z")

</div>

Hi @jdpedersen1, and welcome to the LE community forum 🙂

> [@jdpedersen1](#):
>
> how do i fix this issue?

It sounds like maybe you have two issues:

1. The certificates aren't automatically renewing.  
[you should ensure to follow the best practice of running a job for that (twice a day)]

2. The mail program doesn't update itself when a cert is renewed.  
[you should ensure to restart the mail program each time the mail cert is renewed]

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 4:53am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/3 "2021-08-08T04:53:20Z")

</div>

Thank you for the quick response! So if I get what you are saying, I should update my certs twice a day? Also, I got frustrated with the mail client and uninstalled and reinstalled it and when i try to add my mail server it wont sync, it just fails and says my certs are expired.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 8, 2021, 5:27am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/4 "2021-08-08T05:27:26Z")

</div>

> [@jdpedersen1](#):
>
> I should update my certs twice a day?

You should run:  
`certbot renew`  
twice a day.  
[it won't actually renew your certs twice a day - only when they are nearing expiry]

> [@jdpedersen1](#):
>
> says my certs are expired

Do you recall how you configured the mail server to use a cert?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 8, 2021, 7:33am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/5 "2021-08-08T07:33:38Z")

</div>

I'm wondering, is there any reason why some hostnames are in multiple certificates?  
I.e., the following certificate contains _all_ hostnames:

> [@jdpedersen1](#):
>
> Certificate Name: [jpedmedia.com](http://jpedmedia.com)  
> Domains: [jpedmedia.com](http://jpedmedia.com) [mail.jpedmedia.com](http://mail.jpedmedia.com) notmyown.xyz [www.jpedmedia.com](http://www.jpedmedia.com) [www.mail.jpedmedia.com](http://www.mail.jpedmedia.com) www.notmyown.xyz

And the following cert contains two hostnames which are also included in the cert above:

> [@jdpedersen1](#):
>
> Certificate Name: [mail.jpedmedia.com](http://mail.jpedmedia.com)  
> Domains: [mail.jpedmedia.com](http://mail.jpedmedia.com) [www.mail.jpedmedia.com](http://www.mail.jpedmedia.com)

The same goes for:

> [@jdpedersen1](#):
>
> Certificate Name: notmyown.xyz  
> Domains: notmyown.xyz www.notmyown.xyz

Seems to me one or two (depending on which certificate(s) is/are in use) are redundant?

> [@jdpedersen1](#):
>
> Also, I got frustrated with the mail client and uninstalled and reinstalled it and when i try to add my mail server it wont sync, it just fails and says my certs are expired.

Is your mailserver being _reloaded_ after the renewal? Because it will only pick up and use the renewed certificate after a reload or restart.

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 11:50am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/6 "2021-08-08T11:50:59Z")

</div>

Basically when i set up nginx, I created a sites-enabled dir with 3 files, one for each of my 2 websites and one for my mail server, what's strange is that my certs expired once before and I did not have an issue when I renewed, nothing has changed in my nginx conf and this time things are screwy. I have tried a couple clients thinking the client was the problem but they all say my certs are expired. I also tried removing all certs and uninstalling certbot completely including dependencies and any created files and directories, then reinstalling and running again, still have same issue.

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 11:52am UTC](https://community.letsencrypt.org/t/certificate-problem/157356/7 "2021-08-08T11:52:46Z")

</div>

It should be, I run systemctl restart nginx, and I also ran systemctl disable nginx && systemctl enable --now nginx, output shows stopping and starting.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 8, 2021, 12:07pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/8 "2021-08-08T12:07:31Z")

</div>

Are your mail clients connecting to nginx? ❓ I thought nginx was just a webserver, I didn't know it was also a mail server.

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 12:15pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/9 "2021-08-08T12:15:32Z")

</div>

They were connecting with no issue until now,

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 8, 2021, 12:18pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/10 "2021-08-08T12:18:57Z")

</div>

Could you perhaps explain to me how a mail client can connect to a webserver? Are you absolutely sure the mail clients aren't connecting to Postfix and Dovecot?

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 12:31pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/11 "2021-08-08T12:31:32Z")

</div>

Excuse me, yes, I run dovecot and postfix on the server. Everything has been running with ease until now so I completely forgot about those.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 8, 2021, 12:33pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/12 "2021-08-08T12:33:04Z")

</div>

Please reload your Dovecot so it makes use of the most recently issued/renewed certificate, assuming you've configured Dovecot to read the certificate from the appropriate location in `/etc/letsencrypt/`.

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 1:28pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/13 "2021-08-08T13:28:45Z")

</div>

reloaded dovecot, verified etc/dovecot/dovecot.conf shows ssl cert and ssl key at /etc/letsencrypt/live/mail.jpedmedia.com/fullchain.pem and privkey.pem.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 8, 2021, 1:33pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/14 "2021-08-08T13:33:05Z")

</div>

Well, the reloading did _something_ at least:

```nohighlight
< * OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS LOGINDISABLED] Dovecot (Debian) ready.
> . CAPABILITY
< * CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS LOGINDISABLED
< . OK Pre-login capabilities listed, post-login capabilities have more.
> . STARTTLS
< . OK Begin TLS negotiation now.
... binary TLS stuff ...
< * BYE [UNAVAILABLE] TLS initialization failed.

```

For some reason your TLS (through STARTTLS) is failing now. Please check the Dovecot error log to see why.

Edit:  
Seems to be working now 🙂 _With_ the correct certificate too.

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 1:56pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/15 "2021-08-08T13:56:29Z")

</div>

well not getting the cert expired error so that is good, but cant login because says authentication fail, check username and password,neither of those have changed. this is ridiculous, I think I will just destroy my server and start over.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [August 8, 2021, 1:57pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/16 "2021-08-08T13:57:47Z")

</div>

> [@jdpedersen1](#):
>
> I think I will just destroy my server and start over.

Please backup and restore your perfectly fine certificates in `/etc/letsencrypt/`. Or even better: as root (or sudo), `tar` the entire directory and back that up so you can restore it again (as root or using sudo).

That said: my experience with Linux is that it's almost NEVER EVER necessary to start over from scratch. It's probably better in the long run to learn good debugging skills and fix the issue at hand. 99,99&nbsp;% of time you can learn almost everything you need to know from the error logs in combination with Google.

---

<div class="post-metadata">

**Author:** ![jdpedersen1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jdpedersen1/32/51770_2.png) [@jdpedersen1](https://community.letsencrypt.org/u/jdpedersen1)\
**Post date:** [August 8, 2021, 1:59pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/17 "2021-08-08T13:59:04Z")

</div>

will do, thank you for all your input and info is is greatly appreciated

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 8, 2021, 8:11pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/18 "2021-08-08T20:11:04Z")

</div>

The problem now seems to be within the Dovecot config.  
Which may easier to fix than redoing the entire server.  
But whatever makes it work... wins!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 7, 2021, 8:11pm UTC](https://community.letsencrypt.org/t/certificate-problem/157356/19 "2021-09-07T20:11:05Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
