Hostname/IP does not match certificate’s altnames

Hello,

I use the lets encrypt certificate for my domain (https://www.eyes-on-me.de/). On this website a booking app is installed which also sends notification mails to clients. This mail sending function is not working because of this error:

Error [ERR_TLS_CERT_ALTNAME_INVALID]: Hostname/IP does not match certificate's altnames: 
Host: eyes-on-me.de. ist not in the cert's altnames: DNS: kundenservereasy12.de

How can I fix that? Could you please help me with that?

Best Regards

Welcome to the community @Classix

Your cert only has the name eyes-on-me.de in it. You need to add the name www.eyes-on-me.de to it so that both work. If you need more advice please complete the questions on the form you were shown as best you can

============================

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

2 Likes

Hello @MikeMcQ,

thank you for your quick response. How can I add the missing name www.eyes-on-me.de to the cert?

I will try to answer those questions:

My domain is: https://www.eyes-on-me.de/

I ran this command: A third party app on the website was throwing the error when trying to send notification via email

It produced this output:

Error [ERR_TLS_CERT_ALTNAME_INVALID]: Hostname/IP does not match certificate's altnames: 
Host: eyes-on-me.de. ist not in the cert's altnames: DNS: kundenservereasy12.de

My web server is (include version): Should be latests apache version (did not figured out where to check)

The operating system my web server runs on is (include version): Linux

My hosting provider, if applicable, is: kundenservereasy12.de

I can login to a root shell on my machine (yes or no, or I don't know): Me not, but I can ask my hosting provider to execute some command

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): latest Joomla version

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

It sounds like you got your cert from your hosting provider. You need to ask them to make a new cert with both names in it.

3 Likes

It looks like Apache is up to some mischief!

2 Likes

Your Postfix has a certificate for kundenservereasy12.de configured and not for eyes-on-me.de. Are you the sysop for that mailserver? If not, you probably should just configure your "third party app" (what app?) to connect to kundenservereasy12.de instead of eyes-on-me.de.

4 Likes

Thank you all for your help.
I've managed to set the correct certificate for 'eyes-on-me.de' in the mailserver settings.
This has fixed the issue.

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.