# Enabling https rerouting apache freebsd certbot

**URL:** https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052
**Category:** Help
**Created:** [January 18, 2021, 7:41pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052 "2021-01-18T19:41:50Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 18, 2021, 7:41pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/1 "2021-01-18T19:41:50Z")

</div>

My domain is: [calvinundergroundpoker.com](http://calvinundergroundpoker.com)

Please ignore the red block out on the screenshots. Those were redacted to upload in a different forum.

I got to step 4 of the [certbot](https://certbot.eff.org/lets-encrypt/freebsd-apache) instructions and am struggling with installing the cert. I got the pem files successfully.

I have changed httpd.conf with these two lines:  
`SSLCertificateFile "/pathtofile/fullchain.pem"`  
and  
`SSLCertificateKeyFile "/pathtofile/privatekey.pem"`

And modified httpd-vhosts like so:

 ![Screenshot 2021-01-16 193506](https://global.discourse-cdn.com/letsencrypt/original/3X/0/8/082435a5ba01e469b09d1c2a3c443591713b6825.png)

It still isn't redirecting to the https site. Any suggestions? Yes I did resart apache after the changes...

My web server is (include version): Apache 2.4.46

The operating system my web server runs on is (include version): FreeBSD 11.4-RELEASE in freenas

My hosting provider, if applicable, is: google domains

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): 1.10.1

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [January 18, 2021, 8:58pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/2 "2021-01-18T20:58:28Z")

</div>

Did you reload your Apache? Any configuration change to the Apache configuration files are only _active_ after a reload or restart.

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 18, 2021, 9:27pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/3 "2021-01-18T21:27:06Z")

</div>

yes I did. I ran `service apache24 resart`. Would this be a port forwarding issue? I'm forwarding port 80 and port 443 traffic in my router to the ip of my apache instance

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [January 18, 2021, 9:36pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/4 "2021-01-18T21:36:20Z")

</div>

> [@masonvanmeurs](#):
>
> Would this be a port forwarding issue?

I don't think so, I'm getting a "Connection refused":

```
curl: (7) Failed to connect to calvinundergroundpoker.com port 443: Connection refused

```

This usually means the packets are getting through to the server, but there isn't any service listening on port 443.

Did you, besides the VirtualHost, also add a `Listen 443` in your Apache configuration? Without it, it won't listen on port 443, even if you add a port 443 VirtualHost.

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 18, 2021, 9:55pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/5 "2021-01-18T21:55:41Z")

</div>

I added `Listen 443` below the `Listen 80` line and `ServerName calvinundergroundpoker.com:443` below the line with `ServerName calvinundergroundpoker.com:80` in httpd.conf and restarted and no luck. httpd-ssl.conf is also listening on port 443

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [January 18, 2021, 10:26pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/6 "2021-01-18T22:26:42Z")

</div>

> [@masonvanmeurs](#):
>
> I added `Listen 443` below the `Listen 80` line and `ServerName calvinundergroundpoker.com:443` below the line with `ServerName calvinundergroundpoker.com:80`

Neither of those sounds right.  
Please show the modified file.

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 18, 2021, 10:37pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/7 "2021-01-18T22:37:45Z")

</div>

![image](https://global.discourse-cdn.com/letsencrypt/original/3X/4/a/4ad6d1bdbca990b2a9640858727229fe70a22216.png)

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 18, 2021, 10:38pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/8 "2021-01-18T22:38:29Z")

</div>

![image](https://global.discourse-cdn.com/letsencrypt/original/3X/2/a/2a1950fe9602bad773c10b8c811eb1192606e3ce.png)

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [January 19, 2021, 4:51am UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/9 "2021-01-19T04:51:57Z")

</div>

Hostnames don't use port numbers:  
 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/e/3/e3566bd70ae47a8cbb39eb8415feaf446fdd815a.png)

Change that to just one line:  
`ServerName calvinundergroundpoker.com`

Please show the output of:  
`apachectl -S`

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 19, 2021, 1:07pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/10 "2021-01-19T13:07:30Z")

</div>

Alright. I was just following the default values in the file that they give you. They had it with the port number after the hostname...

I changed those two lines to `ServerName calvinundergroundpoker.com`

Here's the output of `apachectl -S`

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/c/f/cfd8000d580fac747f12ac56359309b6a7bffbe0.png)

Restarted and still isn't redirecting to the https site...

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [January 19, 2021, 2:42pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/11 "2021-01-19T14:42:06Z")

</div>

It seems that your `httpd-vhosts.conf` file isn't being used.  
Please show the output of:  
`grep -Ei 'include|servername|listen|config|ssl|virtual|root' /etc/httpd/httpd.conf`

[if file not found in `/etc/httpd/`, then replace that with your actual file location]  
If you don't know exactly where that file is, try:  
`find / -name httpd.conf`

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 19, 2021, 4:03pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/12 "2021-01-19T16:03:56Z")

</div>

The file is in a different directory than you specified so I modified it and ran  
`grep -Ei 'grep -Ei 'include|servername|listen|config|ssl|virtual|root' /usr/local/etc/apache24/httpd.conf >> file.txt` and got this output:

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/3/1/3175374c1fa1175b0892d942f480eb02342e6b9c.png)

I see lines in the 60s range are commented out including line 62. Is that my problem?

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [January 19, 2021, 6:55pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/13 "2021-01-19T18:55:56Z")

</div>

That is a definite deal-breaker.  
Your code is mainly in line 62 - and that is excluded from the main config.

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 19, 2021, 7:20pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/14 "2021-01-19T19:20:27Z")

</div>

I uncommented the line with  
`#Include blablah httpd.vhosts.conf`, restarted apache, and got this error:  
`root@poker service apache24 restart Performing sanity check on apache24 configuration: Syntax OK Stopping apache24. Waiting for PIDS: 71338. Performing sanity check on apache24 configuration: Syntax OK Starting apache24. /usr/local/etc/rc.d/apache24: WARNING: failed to start apache24 root@poker apache24 #`

Is there anything else I need to uncomment out to get this to work?

---

<div class="post-metadata">

### Author: ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)
#### Post date: [January 19, 2021, 8:58pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/15 "2021-01-19T20:58:35Z")

</div>

I can't say for certain without seeing the entire file:  
`/etc/apache24/extra/httpd-vhosts.conf`

And be sure the included line #62 has a slash before `etc`

---

<div class="post-metadata">

### Author: ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)
#### Post date: [January 19, 2021, 9:00pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/16 "2021-01-19T21:00:39Z")

</div>

At some point these ports will need some attention.

```nohighlight
PORT STATE SERVICE
80/tcp filtered http
443/tcp filtered https

```

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 19, 2021, 9:36pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/17 "2021-01-19T21:36:29Z")

</div>

Here's a [link](https://drive.google.com/drive/folders/1nvNz4DERB0QSs3sP_AT08jttDqtQAllq?usp=sharing) to a folder with a copy of my conf files. Hopefully seeing the whole file helps.

Restarting the service with the files as they are in the folder renders this output:

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/8/6/86b672eddc9aee18718a85cb16467ec23073bda9.png)

I'm not sure why its throwing an error since I'm only listening on port 443 in the ssl config file...

---

<div class="post-metadata">

### Author: ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)
#### Post date: [January 19, 2021, 10:06pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/18 "2021-01-19T22:06:40Z")

</div>

Your image explains the issue for you.  
**You have a "Listen 443" in httpd-ssl.conf.txt**

![Screenshot_2021-01-19_13-57-40](https://global.discourse-cdn.com/letsencrypt/original/3X/6/1/6135963dd16519a66d4666c27aacf35f0305baa1.png)

**And you also have another "Listen 443" directive in httpd.conf.txt**

![Screenshot_2021-01-19_13-58-34](https://global.discourse-cdn.com/letsencrypt/original/3X/3/5/35e88f022858c38299f1444df0bd78b19cd52f46.png)

One should be removed or "#commented out". Personally, I like to keep similar, or related directives close in the same file.

---

<div class="post-metadata">

### Author: ![masonvanmeurs](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@masonvanmeurs](https://community.letsencrypt.org/u/masonvanmeurs)
#### Post date: [January 19, 2021, 11:24pm UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/19 "2021-01-19T23:24:25Z")

</div>

Okay. Commented one out. Here's what I get. The files in the [folder](https://drive.google.com/drive/folders/1nvNz4DERB0QSs3sP_AT08jttDqtQAllq?usp=sharing) here have been updated

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/8/d/8d6b1ff2d236f2217ffe6085d7ff4babc2deee30.png)

---

<div class="post-metadata">

### Author: ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)
#### Post date: [January 20, 2021, 4:21am UTC](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052/20 "2021-01-20T04:21:13Z")

</div>

Why not look to see if another apache is running or possibly not totally stopped...

```nohighlight
ps aux | grep "apache2"

```

[Next page](https://community.letsencrypt.org/t/enabling-https-rerouting-apache-freebsd-certbot/143052.md?page=2)
