# Renewal problem: Site now will not load

**URL:** <https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410>\
**Category:** Help\
**Created:** [November 25, 2018, 8:06pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410 "2018-11-25T20:06:08Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![LEForTheWin](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@LEForTheWin](https://community.letsencrypt.org/u/LEForTheWin)\
**Post date:** [November 25, 2018, 8:06pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/1 "2018-11-25T20:06:08Z")

</div>

Hello folks:

Renewing **[https://fundamentalobjects.com](https://fundamentalobjects.com)** today.

I am on Windows 2008 R2 server.

I followed all steps used when creating the original cert.

- Cert created ok.
- .pfx created ok.
- imported .pfx into Server Certificates ok.
- the newly updated expiration date range shows on the cert.
- restarted, renewed, refreshed, recycled everything in IIS multiple times.
- rebooted twice.

When I try to open the page I get:

> Secure Connection Failed  
> The connection to the server was reset while the page was loading.  
> The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.  
> Please contact the website owners to inform them of this problem.

  

I even see this directly within IIS when browsing the site,  
(never leaving the box).

Any thoughts on what I'm forgetting?

Thank you!

Newly updated dates:

![x](https://global.discourse-cdn.com/letsencrypt/original/3X/e/4/e44a1acb63fd4c5c121431e4de510eda4fafa1f9.png)

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [November 25, 2018, 8:55pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/2 "2018-11-25T20:55:19Z")

</div>

Hi @LEForTheWin

> [@LEForTheWin](#):
>
> Renewing **[https://fundamentalobjects.com](https://fundamentalobjects.com)** today.

mhm. I see the SendFailure - Error:

> SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

Your http connections are ok, both (www and non-www) redirects to https.

So it looks that your configuration is wrong. Can you create a screenshot of one of your https bindings?

Is it possible that you have deactivated all your TLS-protocols?

Perhaps use IISCrypto ( [Nartac Software - IIS Crypto](https://www.nartac.com/Products/IISCrypto) ) to check if TLS.1.0, 1.1 and 1.2 are active.

Or you have selected completely wrong cipher suites.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 25, 2018, 9:15pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/3 "2018-11-25T21:15:55Z")

</div>

Which version of IIS?

---

<div class="post-metadata">

**Author:** ![LEForTheWin](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@LEForTheWin](https://community.letsencrypt.org/u/LEForTheWin)\
**Post date:** [November 25, 2018, 9:24pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/4 "2018-11-25T21:24:00Z")

</div>

Thank you for the response @JuergenAuer!

Below are the bindings.

These two sites are on the same cert (same IP) as they originally were.

Short of any (stupid) Microsoft-auto server updates,  
the server was unchanged by me since the initial cert was created 90 days ago.

I literally changed nothing in the LE64 script run the first time,  
other than to add `-name funobj` as a user-friendly name during .pfx creation.

(I retried the whole thing with -name removed as well).

 ![b](https://global.discourse-cdn.com/letsencrypt/original/3X/3/0/300b08c9961e4d6cbed54b0a659e2c2ad664a20d.png)

---

<div class="post-metadata">

**Author:** ![LEForTheWin](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@LEForTheWin](https://community.letsencrypt.org/u/LEForTheWin)\
**Post date:** [November 25, 2018, 9:26pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/5 "2018-11-25T21:26:38Z")

</div>

I looking at **IIS Crypto** now.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [November 25, 2018, 9:29pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/6 "2018-11-25T21:29:54Z")

</div>

> [@LEForTheWin](#):
>
> Below are the bindings.

Thanks. But what's the content of one binding?

With Windows 2008, you can have only one certificate.

And host names are ignored, because Windows 2008 doesn't support SNI.

You need one 443 binding with one certificate (with 4 domain names).

Perhaps the certificates are removed from the binding -\> no certificate, no https.

---

<div class="post-metadata">

**Author:** ![LEForTheWin](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@LEForTheWin](https://community.letsencrypt.org/u/LEForTheWin)\
**Post date:** [November 25, 2018, 10:45pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/7 "2018-11-25T22:45:42Z")

</div>

Thanks.

How did it work the prior 3 months?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 26, 2018, 1:25am UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/8 "2018-11-26T01:25:37Z")

</div>

Did you add the cert form within IIS?  
Which version of IIS are you running?

---

<div class="post-metadata">

**Author:** ![LEForTheWin](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@LEForTheWin](https://community.letsencrypt.org/u/LEForTheWin)\
**Post date:** [November 26, 2018, 3:16am UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/9 "2018-11-26T03:16:19Z")

</div>

Hello @rg305

I am using IIS 7.5.7600.16385

Yes, I IMPORTED the .pfx from within IIS -\> Sever Certificates.  
It shows there OK.

Note – if you just click the .pfx in Windows Explorer to load it (as I have seen recommended) that will pop through to a 'successfully added" message; BUT, the cert does not really load into Server Certificates. You have to right click in there and choose Import… to get it to actually work.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 26, 2018, 4:47am UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/10 "2018-11-26T04:47:30Z")

</div>

IIS 7.5 doesn’t support SNI.  
If both HTTPS sites go to the same folder, try deleting one of them.  
Also try unbinding the cert and apply that change, then bind it back.  
IIS is notorious for not playing as expected.

---

<div class="post-metadata">

**Author:** ![LEForTheWin](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@LEForTheWin](https://community.letsencrypt.org/u/LEForTheWin)\
**Post date:** [November 26, 2018, 7:43pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/11 "2018-11-26T19:43:13Z")

</div>

Just notes:

I get that IIS sucks.  
Part of my effort here is to get Let’s Encrypt working on Windows as part of a guide to help people stage off of Windows servers onto Linux (#Debian).

I guess I still don’t see why it worked the first 3 months and broke only when reapplying the cert – but I will try to remove and reapply the bindings.

Notes:

- I only have/desire one cert. Both domains are on the one cert; to work on the one IP.

- Each domain points to a separate home folder.

- Nothing is different from when this was set up 3 months ago other that Normal Windows updates and renewing the LE certificate.

Thanks

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [November 26, 2018, 8:09pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/12 "2018-11-26T20:09:46Z")

</div>

> [@LEForTheWin](#):
>
> BUT, the cert does not really load into Server Certificates. You have to right click in there and choose Import… to get it to actually work.

If you only click, then the certificate is loaded in the "CurrentUser" Personal certificates. Not in the Machine\Webhosting.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 26, 2018, 8:23pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/13 "2018-11-26T20:23:22Z")

</div>

> [@LEForTheWin](#):
>
> I only have/desire one cert. Both domains are on the one cert; to work on the one IP.

Then you need to bind it only once.  
[at least until you get to IIS8 or greater]

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 26, 2018, 8:28pm UTC](https://community.letsencrypt.org/t/renewal-problem-site-now-will-not-load/78410/14 "2018-12-26T20:28:41Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
