# I got "this connection is not private" error on IOS only

**URL:** <https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281>\
**Category:** Help\
**Created:** [October 9, 2018, 6:49am UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281 "2018-10-09T06:49:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![haviay](https://avatars.discourse-cdn.com/v4/letter/h/e9bcb4/32.png) [@haviay](https://community.letsencrypt.org/u/haviay)\
**Post date:** [October 9, 2018, 6:49am UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/1 "2018-10-09T06:49:46Z")

</div>

My domain is:

> **[Main-test](https://www.qawobily.co.il/)**
>
> כניסה לאתר שלנו

  
I ran this command:  
New-AcmeIdentifier to create multi domain ssl certificate  
It produced this output:

My web server is (include version):  
Windows with IIS

the ssl certificate works well on all browsers and devices  
except iphone ios, there i got “this connection is not private” error message  
Any suggestions what can make it happen?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [October 9, 2018, 6:54am UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/2 "2018-10-09T06:54:54Z")

</div>

On your iOS device, you are probably trying to visit [https://qawobily.co.il/](https://qawobily.co.il/) (notice the lack of `www.`).

That domain won’t work on any device at all, because you only included the `www` version of your domain on the certificate.

---

<div class="post-metadata">

**Author:** ![haviay](https://avatars.discourse-cdn.com/v4/letter/h/e9bcb4/32.png) [@haviay](https://community.letsencrypt.org/u/haviay)\
**Post date:** [October 9, 2018, 7:27am UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/3 "2018-10-09T07:27:42Z")

</div>

This is very strange…  
i do redirect on my server to www sub domain  
and it works well in other browsers  
why this behavior is not the same on IOS?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [October 9, 2018, 7:34am UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/4 "2018-10-09T07:34:12Z")

</div>

> [@haviay](#):
>
> and it works well in other browsers

No, it doesn't. If you click this link in any desktop browser (without any kind of cache), it _will_ fail: [https://qawobily.co.il/](https://qawobily.co.il/)

The problem is that in order to send a redirect, you need to have a valid SSL connection already. In order to have that, the certificate needs to be valid for the first URL being visited.

So you should add that extra name to your certificate.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [October 9, 2018, 7:36am UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/5 "2018-10-09T07:36:14Z")

</div>

If you want, you can also adjust your HTTPS redirect to also ensure that the `www` subdomain is added, because currently it doesn’t:

```
$ curl -i qawobily.co.il
HTTP/1.1 301 Moved Permanently
Cache-Control: private
Transfer-Encoding: chunked
Location: https://qawobily.co.il/
```

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [October 9, 2018, 2:52pm UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/6 "2018-10-09T14:52:31Z")

</div>

> [@\_az](#):
>
> No, it doesn’t. If you click this link in any desktop browser (without any kind of cache), it _will_ fail: [https://qawobily.co.il/](https://qawobily.co.il/)

Probably users who run into this problem are using Chrome, which has a special case that considers this valid (!) even though it's not valid according to Internet standards. So you might want to say "any desktop browser (other than Chrome)" here. ☹

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 8, 2018, 2:52pm UTC](https://community.letsencrypt.org/t/i-got-this-connection-is-not-private-error-on-ios-only/74281/7 "2018-11-08T14:52:33Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
