# Letsencrypt successfully install in ubuntu but not redirection to https

**URL:** <https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981>\
**Category:** Help\
**Created:** [August 13, 2020, 2:00pm UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981 "2020-08-13T14:00:00Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 13, 2020, 2:00pm UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/1 "2020-08-13T14:00:00Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:  
3mad.in  
I ran this command:  
sudo lsof -iTCP -sTCP:LISTEN -P  
It produced this output:

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/5/a/5a22095da62dd9c7c2aad896f442225386b8092e.png)  
My web server is (include version):  
Apache2  
The operating system my web server runs on is (include version):  
Ubuntu 18.04 LTS  
My hosting provider, if applicable, is:  
AWS  
I can login to a root shell on my machine (yes or no, or I don’t know):  
Yes  
The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):  
certbot --version : certbot 0.31.0  
certbot-auto --version : certbot 1.7.0

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 13, 2020, 9:02pm UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/2 "2020-08-13T21:02:15Z")

</div>

The title says “not working” but the content doesn’t say what is not working.

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 6:50am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/3 "2020-08-14T06:50:08Z")

</div>

sorry.  
Cant get redirection to https working after setup with Certbot

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 6:55am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/4 "2020-08-14T06:55:22Z")

</div>

Let’s start with:  
`apachectl -S`  
Which should show us all the domain names, and corresponding files, being served.  
Then please also show the HTTP vhost config that covers the domain name that isn’t redirecting (file name will be shown by that command).

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:06am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/5 "2020-08-14T07:06:42Z")

</div>

> [@rg305](#):
>
> apachectl -S

VirtualHost configuration:  
\*:80 is a NameVirtualHost  
default server 3mad.in (/etc/apache2/sites-enabled/000-default-le-ssl.conf:44)  
port 80 namevhost 3mad.in (/etc/apache2/sites-enabled/000-default-le-ssl.conf:44)  
port 80 namevhost 3mad.in (/etc/apache2/sites-enabled/000-default.conf:1)  
alias www.3mad.in  
\*:443 is a NameVirtualHost  
default server 3mad.in (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2)  
port 443 namevhost 3mad.in (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2)  
alias demo.3mad.in  
port 443 namevhost ip-172-31-42-11.ap-south-1.compute.internal (/etc/apache2/sites-enabled/default-ssl.conf:2)  
ServerRoot: "/etc/apache2"  
Main DocumentRoot: "/var/www/html"  
Main ErrorLog: "/var/log/apache2/error.log"  
Mutex watchdog-callback: using\_defaults  
Mutex rewrite-map: using\_defaults  
Mutex ssl-stapling-refresh: using\_defaults  
Mutex ssl-stapling: using\_defaults  
Mutex ssl-cache: using\_defaults  
Mutex default: dir="/var/run/apache2/" mechanism=default  
Mutex mpm-accept: using\_defaults  
PidFile: "/var/run/apache2/apache2.pid"  
Define: DUMP\_VHOSTS  
Define: DUMP\_RUN\_CFG  
User: name="www-data" id=33  
Group: name="www-data" id=33

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:08am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/6 "2020-08-14T07:08:10Z")

</div>

This is s problem:

> [@ashok64554](#):
>
> port 80 namevhost 3mad.in (/etc/apache2/sites-enabled/000-default-le-ssl.conf:44)  
> port 80 namevhost 3mad.in (/etc/apache2/sites-enabled/000-default.conf:1)

The same domain name is being served by two vhost config files.

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:10am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/7 "2020-08-14T07:10:46Z")

</div>

so can we run this for disable default site  
sudo a2dissite 000-default

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:11am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/8 "2020-08-14T07:11:47Z")

</div>

Yes, that will disable the default site.  
But I would review what both the files are doing before making a final decision.

Please show both files.

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:15am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/9 "2020-08-14T07:15:44Z")

</div>

/etc/apache2/sites-enabled/000-default.conf  
\<VirtualHost \*:80\>  
# The ServerName directive sets the request scheme, hostname and port that  
# the server uses to identify itself. This is used when creating  
# redirection URLs. In the context of virtual hosts, the ServerName  
# specifies what hostname must appear in the request’s Host: header to  
# match this virtual host. For the default virtual host (this file) this  
# value is not decisive as it is used as a last resort host regardless.  
# However, you must set it for any further virtual host explicitly.  
ServerName 3mad.in  
ServerAlias www.3mad.in

```
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html

<Directory /var/www/html>
    Options Indexes FollowSymLinks MultiViews
    AllowOverride All
    Require all granted
</Directory>

# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn

ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined

# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf

```

#SSLEngine on  
#SSLCertificateFile /etc/letsencrypt/live/3mad.in/cert.pem  
#SSLCertificateKeyFile /etc/letsencrypt/live/3mad.in/privkey.pem  
#SSLCertificateChainFile /etc/letsencrypt/live/3mad.in/chain.pem

# vim: syntax=apache ts=4 sw=4 sts=4 sr noet

/etc/apache2/sites-enabled/000-default-le-ssl.conf  
  
\<VirtualHost \*:443\>  
# The ServerName directive sets the request scheme, hostname and port that  
# the server uses to identify itself. This is used when creating  
# redirection URLs. In the context of virtual hosts, the ServerName  
# specifies what hostname must appear in the request’s Host: header to  
# match this virtual host. For the default virtual host (this file) this  
# value is not decisive as it is used as a last resort host regardless.  
# However, you must set it for any further virtual host explicitly.  
ServerName 3mad.in  
#ServerAlias www.3mad.in

```
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html

# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn
<Directory /var/www/html>
    Options Indexes FollowSymLinks MultiViews
    AllowOverride All
    Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined

# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf

```

Include /etc/letsencrypt/options-ssl-apache.conf  
ServerAlias demo.3mad.in  
SSLCertificateFile /etc/letsencrypt/live/3mad.in/fullchain.pem  
SSLCertificateKeyFile /etc/letsencrypt/live/3mad.in/privkey.pem  
  
  
  
\<VirtualHost \*:80\>  
# The ServerName directive sets the request scheme, hostname and port that  
# the server uses to identify itself. This is used when creating  
# redirection URLs. In the context of virtual hosts, the ServerName  
# specifies what hostname must appear in the request’s Host: header to  
# match this virtual host. For the default virtual host (this file) this  
# value is not decisive as it is used as a last resort host regardless.  
# However, you must set it for any further virtual host explicitly.  
ServerName 3mad.in  
#ServerAlias www.3mad.in

```
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html

<Directory /var/www/html>
    Options Indexes FollowSymLinks MultiViews
    AllowOverride All
    Require all granted
</Directory>

# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn

ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined

# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:22am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/10 "2020-08-14T07:22:41Z")

</div>

The two blocks are essentially the same.  
With only one minor difference:

```auto
/etc/apache2/sites-enabled/000-default.conf
ServerAlias www.3mad.in

/etc/apache2/sites-enabled/000-default-le-ssl.conf
#ServerAlias www.3mad.in

```

I would go ahead and disable the default file first and then we can work on the redirection.

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:24am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/11 "2020-08-14T07:24:28Z")

</div>

done

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/7/d/7dab79ba328fe89984e12336f73018dc172a27c5.png)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:25am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/12 "2020-08-14T07:25:17Z")

</div>

Please show the current:  
`apachectl -S`

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:26am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/13 "2020-08-14T07:26:12Z")

</div>

> [@rg305](#):
>
> apachectl -S

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/1/4/14071daf9b7eb1eb13e62cfce754accd0308a97c.png)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:29am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/14 "2020-08-14T07:29:30Z")

</div>

Much better 🙂  
Now insert this code right after “DocumentRoot” line in `000-default-le-ssl.conf`

```auto
  #set the default action for all other requests
  <LocationMatch "^/(?!\.well-known)">
    #send all other requests to HTTPS
    RewriteEngine On
    RewriteCond %{HTTPS} !=on
    RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1
  </LocationMatch>

```

and restart Apache

to be clear: There are two documentroot lines, insert within the HTTP block

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:32am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/15 "2020-08-14T07:32:19Z")

</div>

done

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/e/c/ec0f0ca6514f10726648dd56d79c01b17222b71d.png)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:33am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/16 "2020-08-14T07:33:19Z")

</div>

Didn’t type fast enough.  
It actually goes lower in the other block - that is the HTTPS block  
[there is no need to redirect to HTTPS from within the HTTPS block - LOL]

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:38am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/18 "2020-08-14T07:38:53Z")

</div>

done  
  
\<VirtualHost \*:443\>  
# The ServerName directive sets the request scheme, hostname and port that  
# the server uses to identify itself. This is used when creating  
# redirection URLs. In the context of virtual hosts, the ServerName  
# specifies what hostname must appear in the request’s Host: header to  
# match this virtual host. For the default virtual host (this file) this  
# value is not decisive as it is used as a last resort host regardless.  
# However, you must set it for any further virtual host explicitly.  
ServerName 3mad.in  
#ServerAlias www.3mad.in

```
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn
<Directory /var/www/html>
    Options Indexes FollowSymLinks MultiViews
    AllowOverride All
    Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined

# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf

```

Include /etc/letsencrypt/options-ssl-apache.conf  
ServerAlias demo.3mad.in  
SSLCertificateFile /etc/letsencrypt/live/3mad.in/fullchain.pem  
SSLCertificateKeyFile /etc/letsencrypt/live/3mad.in/privkey.pem  
  
  
  
\<VirtualHost \*:80\>  
# The ServerName directive sets the request scheme, hostname and port that  
# the server uses to identify itself. This is used when creating  
# redirection URLs. In the context of virtual hosts, the ServerName  
# specifies what hostname must appear in the request’s Host: header to  
# match this virtual host. For the default virtual host (this file) this  
# value is not decisive as it is used as a last resort host regardless.  
# However, you must set it for any further virtual host explicitly.  
ServerName 3mad.in  
#ServerAlias www.3mad.in

```
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
 #set the default action for all other requests

```

\<LocationMatch “^/(?!.well-known)”\>  
#send all other requests to HTTPS  
RewriteEngine On  
RewriteCond %{HTTPS} !=on  
RewriteRule ^/?(.\*) https://%{SERVER\_NAME}/$1  
  
\<Directory /var/www/html\>  
Options Indexes FollowSymLinks MultiViews  
AllowOverride All  
Require all granted

```
# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn

ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined

# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:39am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/19 "2020-08-14T07:39:38Z")

</div>

OK let’s thy the HTTP site now.

Seems a bit busy right now:

```auto
curl -Iki 3mad.in
HTTP/1.1 503 Service Unavailable: Back-end server is at capacity
Connection: keep-alive

```

---

<div class="post-metadata">

**Author:** ![ashok64554](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ashok64554/32/41785_2.png) [@ashok64554](https://community.letsencrypt.org/u/ashok64554)\
**Post date:** [August 14, 2020, 7:42am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/20 "2020-08-14T07:42:19Z")

</div>

still show the same error

# Hmmm… can’t reach this page

**3mad.in** refused to connect.

Try:

- Checking the connection
- Checking the proxy and the firewall

ERR\_CONNECTION\_REFUSED

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 14, 2020, 7:43am UTC](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981/21 "2020-08-14T07:43:32Z")

</div>

I originally got this:

```auto
curl -Iki 3mad.in
HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Length: 7969
Content-Type: text/html
Date: Fri, 14 Aug 2020 06:52:31 GMT
ETag: "1f21-5acbea5eba1c0"
Last-Modified: Thu, 13 Aug 2020 09:08:31 GMT
Server: Apache/2.4.29 (Ubuntu)
Vary: Accept-Encoding
Connection: keep-alive

```

but now only this:

```auto
curl -Iki 3mad.in
HTTP/1.1 503 Service Unavailable: Back-end server is at capacity
Connection: keep-alive

```

[Next page](https://community.letsencrypt.org/t/letsencrypt-successfully-install-in-ubuntu-but-not-redirection-to-https/130981.md?page=2)
