# Is there a way to exclude specific domains from Certbot?

**URL:** <https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572>\
**Category:** Server\
**Created:** [February 8, 2019, 4:42am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572 "2019-02-08T04:42:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![r3d\_f0x](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@r3d\_f0x](https://community.letsencrypt.org/u/r3d_f0x)\
**Post date:** [February 8, 2019, 4:42am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/1 "2019-02-08T04:42:11Z")

</div>

I’m using domains from an alternate DNS root and Certbot breaks when I try to run it with those domains in the server files. Is there a way to list domains to be excluded each time I run Certbot?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 8, 2019, 4:56am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/2 "2019-02-08T04:56:16Z")

</div>

> [@r3d\_f0x](#):
>
> alternate DNS root

Do you mean like .onion or .bit or .internal?

How does Certbot break?

If you know exactly which domains you want, you should be able to just do:

```
certbot --apache -d example.org -d www.example.org

```

and it won't bother about any other domains.

---

<div class="post-metadata">

**Author:** ![r3d\_f0x](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@r3d\_f0x](https://community.letsencrypt.org/u/r3d_f0x)\
**Post date:** [February 8, 2019, 5:08am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/3 "2019-02-08T05:08:18Z")

</div>

Does the -d flag remove those domains? If so it will be easy to put them into a file.

I’m using OpenNIC domains.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 8, 2019, 5:24am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/4 "2019-02-08T05:24:37Z")

</div>

`-d` specifies which domains you want to be included on a certificate.

Certbot shouldn’t be “breaking” when it encounters domains it can’t resolve. I’d like to see what the actual error/output is, so that we can differentiate between a validation error (i.e. CA thinks the DNS doesn’t resolve) or an actual error/bug (Certbot can’t parse webserver config).

The answer to your question relies on that.

---

<div class="post-metadata">

**Author:** ![r3d\_f0x](https://avatars.discourse-cdn.com/v4/letter/r/3da27b/32.png) [@r3d\_f0x](https://community.letsencrypt.org/u/r3d_f0x)\
**Post date:** [February 8, 2019, 5:51am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/5 "2019-02-08T05:51:35Z")

</div>

It says there was an error because a name didn’t end it a public suffix. Specifying a list of domains with a file would also work.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 8, 2019, 5:53am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/6 "2019-02-08T05:53:40Z")

</div>

Cool, that’s an expected CA error.

So using a bunch of `-d` is probably your best option.

Edit: I suggested `--allow-subset-of-names` but on second thought that probably won’t work, because the alternate root domains would be rejected at the new-order stage, not during validation. Sorry! Your use case is not that common I guess.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 8, 2019, 6:05am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/7 "2019-02-08T06:05:59Z")

</div>

> [@r3d\_f0x](#):
>
> Is there a way to list domains to be excluded each time I run Certbot?

I'm confused...  
How are names being included?  
How is that process including names you don't want included?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 10, 2019, 6:06am UTC](https://community.letsencrypt.org/t/is-there-a-way-to-exclude-specific-domains-from-certbot/85572/8 "2019-03-10T06:06:03Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
