# Net::err\_cert\_common\_name\_invalid

**URL:** <https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003>\
**Category:** Help\
**Created:** [August 30, 2019, 6:35pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003 "2019-08-30T18:35:30Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 6:35pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/1 "2019-08-30T18:35:30Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:www.thewificompany.com

I ran this command: I installed this all on digital ocean, I have the cert [unifi.thewificompany.com](http://unifi.thewificompany.com) in my a records, and when I went to the site to test my SSSL it gave me an A rating still getting the security issue

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, web host is network solutions, my controller is on Digital ocean

I can login to a root shell on my machine (yes or no, or I don’t know):yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [August 30, 2019, 6:52pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/2 "2019-08-30T18:52:13Z")

</div>

Hi @john-bailey

> [@john-bailey](#):
>
> [unifi.thewificompany.com](http://unifi.thewificompany.com)

checking this subdomain there is all good - [https://check-your-website.server-daten.de/?q=unifi.thewificompany.com](https://check-your-website.server-daten.de/?q=unifi.thewificompany.com)

The certificate is valid

```nohighlight
CN=unifi.thewificompany.com
	30.08.2019
	28.11.2019
expires in 90 days	unifi.thewificompany.com - 1 entry

```

and used, a Grade B is very good.

Is there an error with that domain? Perhaps only an old cache, share a screenshot.

Your main domain - https doesn't work - [https://check-your-website.server-daten.de/?q=thewificompany.com](https://check-your-website.server-daten.de/?q=thewificompany.com)

But that's expected, there is no certificate:

| Issuer | not before | not after | Domain names | LE-Duplicate | next LE |
| --- | --- | --- | --- | --- | --- |
| Let's Encrypt Authority X3 | 2019-08-30 | 2019-11-28 | [unifi.thewificompany.com](http://unifi.thewificompany.com) - 1 entries | duplicate nr. 1 | |
| Amazon | 2019-07-12 | 2020-08-12 | [dashboard.thewificompany.com](http://dashboard.thewificompany.com), [splash.thewificompany.com](http://splash.thewificompany.com) - 2 entries | | |
| Amazon | 2018-08-09 | 2019-09-09 | [dashboard.thewificompany.com](http://dashboard.thewificompany.com), [splash.thewificompany.com](http://splash.thewificompany.com) - 2 entries | | |

so no SSL connection is possible.

The error:

> Error creating a TLS-Connection: IANA TLS Alert No. 80, internal\_error. An internal error unrelated to the peer or the correctness of the protocol (such as a memory allocation failure) makes it impossible to continue. SSL\_ERROR\_INTERNAL\_ERROR\_ALERT (Mozilla) / ERR\_SSL\_PROTOCOL\_ERROR (Chrome)

So first step: Create a certificate with your main domain + www

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 6:55pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/3 "2019-08-30T18:55:54Z")

</div>

I am stupid, sorry, can you let me know exactly what this means?

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [August 30, 2019, 7:08pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/4 "2019-08-30T19:08:18Z")

</div>

Where do you see that error message?

> Net::err\_cert\_common\_name\_invalid

Your subdomain doesn't have a certificate error.

And your main domain doesn't have a https version with a wrong certificate. There is no https, not with a correct, not with a wrong certificate (self signed, expired, wrong domain name).

So both domains don't show that error.

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:11pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/5 "2019-08-30T19:11:42Z")

</div>

ok so i created an A record with my actual website hosting company to point to my hosted Digital ocean droplet, with a unifi controller on it. so I followed the instructions from the guys at crosstalk to get everything up and running, even my ssl certificate. i ran all the commands on my ubuntu server  
this is the site I went to after as instructed  
[https://www.ssllabs.com/ssltest/analyze.html?d=unifi.thewificompany.com&latest](https://www.ssllabs.com/ssltest/analyze.html?d=unifi.thewificompany.com&latest)  
does any of this make sense yet?

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:13pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/6 "2019-08-30T19:13:33Z")

</div>

here are the instructions I was following  
Install Certbot:

sudo add-apt-repository ppa:certbot/certbot

Press ENTER to continue when prompted.

sudo apt-get update sudo apt-get install python-certbot-apache -y

Now Certbot is installed, so the next step is to generate our SSL certificate.

sudo certbot --apache -d [vultrunifi.crosstalksolutions.com](http://vultrunifi.crosstalksolutions.com)

Substitute your own FQDN instead of [vultrunifi.crosstalksolutions.com](http://vultrunifi.crosstalksolutions.com). When prompted, enter in an email address for use with the SSL cert. Then press A to Agree when prompted followed by Y or N to share your email address with the Electronic Frontier Foundation (I said N). Next you will be asked if you want to redirect all HTTP traffic to HTTPS – choose option 2. Your Let’s Encrypt certificate has now been installed.

Next, we need to import that SSL certificate into UniFi – or in other words, we have to tell UniFi to use the Let’s Encrypt certificate.

A developer named [Steve Jenkins](https://www.stevejenkins.com/blog/2016/06/use-existing-ssl-certificate-linux-unifi-controller/) created a really great script that automates the rest of the process, making it super easy. So, thanks to Steve, and let’s download his script and modify a few settings.

sudo wget [https://raw.githubusercontent.com/stevejenkins/unifi-linux-utils/master/unifi\_ssl\_import.sh](https://raw.githubusercontent.com/stevejenkins/unifi-linux-utils/master/unifi_ssl_import.sh) -O /usr/local/bin/unifi\_ssl\_import.sh sudo chmod +x /usr/local/bin/unifi\_ssl\_import.sh

Next, edit the /usr/local/bin/unifi\_ssl\_import.sh file that we imported:

sudo nano -w /usr/local/bin/unifi\_ssl\_import.sh

Find the line that says ‘UNIFI\_HOSTNAME’ and change it to your own FQDN:

UNIFI\_HOSTNAME=[vultrunifi.crosstalksolutions.com](http://vultrunifi.crosstalksolutions.com)

Next, since we are on a Ubuntu Vultr server instead of a flavor of RedHat (which the script was based on), we need to comment out the RedHat stuff and uncomment the Debian/Ubuntu stuff:

# Uncomment following three lines for Fedora/RedHat/CentOS #UNIFI\_DIR=/opt/UniFi #JAVA\_DIR={UNIFI\_DIR} #KEYSTORE={UNIFI\_DIR}/data/keystore # Uncomment following three lines for Debian/Ubuntu UNIFI\_DIR=/var/lib/unifi JAVA\_DIR=/usr/lib/unifi KEYSTORE=${UNIFI\_DIR}/keystore

Next, enable Lets Encrypt mode (change LE\_MODE=no to LE\_MODE=yes):

LE\_MODE=yes LE\_LIVE\_DIR=/etc/letsencrypt/live

Save and exit nano by doing CTRL+X followed by Y.

Finally, run the script!

sudo /usr/local/bin/unifi\_ssl\_import.sh

If you now close your browser and then re-open it to https://[your UniFi FQDN]:8443, you should no longer have the security warnings, and you will have a valid HTTPS certificate installed. And no more pesky security warnings.

[![](https://global.discourse-cdn.com/letsencrypt/original/3X/6/a/6a89ed478d92c5487ed639558efb76475b4dba9b.jpeg)](https://crosstalksolutions.com/wp-content/uploads/2019/03/part21-a.jpg)

Let’s test this certificate further by running it against an SSL Server Test from [SSLLabs.com](http://SSLLabs.com). Open the following URL in your browser:

[https://www.ssllabs.com/ssltest/analyze.html?d=vultrunifi.crosstalksolutions.com&latest](https://www.ssllabs.com/ssltest/analyze.html?d=vultrunifi.crosstalksolutions.com&latest)

Substitute my FQDN for your own. This test takes a couple of minutes to run, but when complete, it should verify that everything is A-OK.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [August 30, 2019, 7:19pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/7 "2019-08-30T19:19:23Z")

</div>

> [@john-bailey](#):
>
> this is the site I went to after as instructed  
> [SSL Server Test: unifi.thewificompany.com (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=unifi.thewificompany.com&latest)  
> does any of this make sense yet?

Where is there an error?

That's a Grade A, that's good.

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:21pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/8 "2019-08-30T19:21:07Z")

</div>

[https://67.205.128.178:8443](https://67.205.128.178:8443)

this is my digital ocean hosted unifi controller

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:22pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/9 "2019-08-30T19:22:00Z")

</div>

see this is where I am running into a problem I dont know why it is doing this

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:24pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/10 "2019-08-30T19:24:27Z")

</div>

this is the a record I created does it look right?  
[unifi.thewificompany.com](http://unifi.thewificompany.com)  
7200  
67.205.128.178

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [August 30, 2019, 7:24pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/11 "2019-08-30T19:24:47Z")

</div>

> [@john-bailey](#):
>
> [https://67.205.128.178:8443](https://67.205.128.178:8443)

If you use the ip address, the certificate is always wrong.

Use

[https://unifi.thewificompany.com:8443/](https://unifi.thewificompany.com:8443/)

that works with your certificate.

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:26pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/12 "2019-08-30T19:26:47Z")

</div>

so wait dont we have to point [unifi.thewificompany.com](http://unifi.thewificompany.com) to the ip address of the server hosting my controller?

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:29pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/13 "2019-08-30T19:29:01Z")

</div>

so do I need to do anything different in the set up in ssh or do I leave it alone?

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [August 30, 2019, 7:29pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/14 "2019-08-30T19:29:08Z")

</div>

> [@john-bailey](#):
>
> dont we have to point [unifi.thewificompany.com](http://unifi.thewificompany.com) to the ip address of the server hosting my controller?

That's already done - [https://check-your-website.server-daten.de/?q=unifi.thewificompany.com](https://check-your-website.server-daten.de/?q=unifi.thewificompany.com)

| Host | T | IP-Address | is auth. | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| [unifi.thewificompany.com](http://unifi.thewificompany.com) | A | 67.205.128.178 North Bergen/New Jersey/United States (US) - DigitalOcean, LLC Hostname: [unifi.thewificompany.com](http://unifi.thewificompany.com) | yes | 1 | 0 |
| | AAAA | | yes | | |
| [www.unifi.thewificompany.com](http://www.unifi.thewificompany.com) | | Name Error | yes | 1 | 0 |

The check is 45 minutes old - and it's the same ip address you have shared.

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:32pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/15 "2019-08-30T19:32:49Z")

</div>

sorry for being stupiud, how much do you know about unifi controlelr and pre authenitaction in the guest portal? meaning I am trying to put the correct url into the pre auth and it throws up not allowing me so it needs a ip address or proper domain name and not the :8443/  
it has to do with redirect urls and https, getting errors,  
or if I put in [unifi.thewificompany.com](http://unifi.thewificompany.com) that should cover it?

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 7:39pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/16 "2019-08-30T19:39:20Z")

</div>

in my a record on my provider should we add the 8443 to the ip addrss maybe?

---

<div class="post-metadata">

**Author:** ![john-bailey](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@john-bailey](https://community.letsencrypt.org/u/john-bailey)\
**Post date:** [August 30, 2019, 8:43pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/17 "2019-08-30T20:43:08Z")

</div>

got it all figure out thank you so so much!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 29, 2019, 8:44pm UTC](https://community.letsencrypt.org/t/net-err-cert-common-name-invalid/101003/18 "2019-09-29T20:44:30Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
