Shows old certificate instead of new

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: cleani.biz

I ran this command: I manage a wordpress site where SSL certificate was installed by using Let's Encrypt plugin + manually activating certificate on hosting site. However, there was apparently some misconfigation bc plugin was never activated. Since the certificate was about to expire on 12th July I decided to issue a new one and make an installation properly. But after I did that it still shows the old certificate in a browser.
I have clear cache, tried incognito, different device, got my hosting delete old certificate (you can't do it manually, only add new) but even crt.sh doesn't show new certificate. I am not sure how to fix that.

It produced this output: new certificate is not recognized

My web server is (include version): Apache, not sure about version

The operating system my web server runs on is (include version): N\A

My hosting provider, if applicable, is: Cafe24

I can login to a root shell on my machine (yes or no, or I don't know): no

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no, only FTP availible

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): not using

Hi @xeene14, and welcome to the LE community forum :slight_smile:

It seems that the WP plugin wasn't able to renew the cert.
And since the cert is already expired...
I would suggest that you try removing SSL from the site altogether and then put it back.
Doing so may trigger it to obtain, and use, a new cert.
If that fails, and since you don't have root access, I would suggest speaking with your HSP about this problem; As they seem to control most of the pieces involved in this puzzle.

3 Likes

Hi, @rg305
I did exactly that. I asked my provider to remove old certs, which they did, reinstall the plugin, got new cert and put it manually into my account. However, the site still shows an old cert plus crt.sh doesn't show that I have a new one too. I am not sure, what I need to ask from my provider since the expired cert was installed manually and plugin was reinstalled after that. Could you guide me a little, please?
The cite also uses cashing plugin, any chance it might be involved?

Can you show us [only] the public cert file they provided [NOT the key file]?

3 Likes

When I tried to upload file, it doesn't appear in the folder. I hope just posting what's inside is ok.
Also, the file was provided by Really Simple SSL plugin not my hosting.

Summary

-----BEGIN CERTIFICATE-----
MIIGKzCCBROgAwIBAgISBGpdNAdedSDJhz1LM4BeqhWWMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMzA0MTMwNTEyMDBaFw0yMzA3MTIwNTExNTlaMBUxEzARBgNVBAMT
CmNsZWFuaS5iaXowggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDShihM
6OpPH/YTYwnqQGHkB4zKppcbxHi5bNHGCP+GW5mNW8U1219ey41ASPyv+Ay9r4sO
C1494FZ0jUo0iYR7+J7fjS6M/BNaR9fljcqRvCdveHXSmtnsouNfJcyhgEiFWLoW
QoW5EiQYqaftYDTriJeC04pPLlPmlny5bWvMkJqULiGG070dW4kG5VGV06CztfM5
twNXfDJKhZt8/jh/QI48VszdtkiTsWIKOv9M+9wG8pn9t49HuLKcSJC9oTWYX+Qd
KsM1yGnZKv/Q8Dd2sDjpsa+wvcYdL7OwrDUExpU4euQYqIDByTNb6p8PpCXnCJmd
nXCoJu0CUbhioDpo4RrR2jdUYQoPxu/D6pCdWY6X5lJKevTcvS0Wj4y4yNx1kw6E
EEO2unsNJcpG4cVZu+dVauCrnBagdk3xB0qEbPaIlGeyP/Wue6Vv6neC4Oi1DPiH
Uq2FXGAIQ01xbTO8ODR1v2YY6sD/eTjYRnZvPNy7wxEN1fDnW/lr8uHPYX1eJ9+T
COpLEoWstYt0m4pGGSLzB8cxvT/vQRo0lcPRCUCcy85EAxQY39L/qC/PpnrI526H
K31Xss1jQlga+94tnn372gqxQgzn2DEIz+nWoqFMmHzxAXgZTfyBzbp6SmwbAynd
Ks8jJZkDpFFC2rPLDn06w6OqqQeotbNJYSJXgwIDAQABo4ICVjCCAlIwDgYDVR0P
AQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMB
Af8EAjAAMB0GA1UdDgQWBBQJryX/w+BKZrw5+yxikXRveBPXQjAfBgNVHSMEGDAW
gBQULrMXt1hWy65QCUDmH6+dixTCxjBVBggrBgEFBQcBAQRJMEcwIQYIKwYBBQUH
MAGGFWh0dHA6Ly9yMy5vLmxlbmNyLm9yZzAiBggrBgEFBQcwAoYWaHR0cDovL3Iz
LmkubGVuY3Iub3JnLzAlBgNVHREEHjAcggpjbGVhbmkuYml6gg53d3cuY2xlYW5p
LmJpejBMBgNVHSAERTBDMAgGBmeBDAECATA3BgsrBgEEAYLfEwEBATAoMCYGCCsG
AQUFBwIBFhpodHRwOi8vY3BzLmxldHNlbmNyeXB0Lm9yZzCCAQUGCisGAQQB1nkC
BAIEgfYEgfMA8QB3ALc++yTfnE26dfI5xbpY9Gxd/ELPep81xJ4dCYEl7bSZAAAB
h3k+BwAAAAQDAEgwRgIhAJYttsM8SZxuTkSKptT9AnmFsFyfqKdA7Uh45C3MK3q1
AiEA7hWIe6mFXAQ88HYGNssYVBU3kEinSryZWYrRMm1pKXYAdgB6MoxU2LcttiDq
OOBSHumEFnAyE4VNO9IrwTpXo1LrUgAAAYd5PgclAAAEAwBHMEUCIFlXPA7MipFT
89291zcsA/7UEr3jQZVhe5Kz83aSV5StAiEAxK3BSjRd+hDtmKT3ESkRfa/qgF2v
X4Dw8vkdYTeqvZ8wDQYJKoZIhvcNAQELBQADggEBAFsGPb29T0614HpVa8Y+4cO8
563Y+16rS6rvLZtYIuVamE6UCMZWgL8PjrWJtcrKC8O7Fl8/ZdMKhc70FVdAFxKs
UNDJSDEZ+d1jgTNUmBFdfDIN3vIXqUo/SGOTlCStSBDz58YntX8AMFsFvSeHvfka
JMyq961+RdVPoJb+XiQ0ln0Z35AJc7uyBr01O8s3X6NtIxCh9E9NzmFqpyKFfwVS
SRRYHLKawkJRjwNGMSVv1/wUiugWd0WHSJoh6rhZwVCFPiUY38PP3Oc7rBqK0/9m
kWdRKAbbsMNIKJn/RLE/zvtQ6VUe8L/kOr3dQz3Yr46IRJzLj1PkA5kS1K64psY=
-----END CERTIFICATE-----

That certificate expired five days ago:

3 Likes

But I just got it new from the plugin, how is it possible?
Also, in that case, how can I renew it or got new? I don't see anything regading renewal on plugin.
I am sorry if my questions are lame but i am not exactly familiart with the topic.

Hi, your web server is running Nginx, not Apache and the best thing to do is look at the configuration files for your website to determine which certificate file it's pointing to.

If you're not familiar with the administration of nginx I would recommend contacting a local web development company or a freelance web administrator who can help you.

1 Like

he's on shared hosting plan so I think it's nginx in front of apache- see OP that he doesn't have root access.

looks like godaddy-like situation , but they use in-house panel so unlikely any WP plugin automated for it.

4 Likes

hi, it's ngnix in front of apache as was said below. I don't have root acces, so want to know what to ask to my HSP so they can look it up and fix possibly.

Thanks, so the Apache part is not relevant as nginx is doing the work of "terminating" TLS, the problem is in the nginx config.

4 Likes

they likely try to sell you a setigo certificate to you or upgrade your plan. what plan to you run on cafe24?
cafe24์—์„œ ์–ด๋–ค ์žฌํ’ˆ์„ ์‚ฌ์šฉํ•˜๊ณ  ๊ณ„์‹ ๊ฐ€์š”? ๋งค๋‹ˆ์ง€๋“œ ์›Œ๋“œํ”„๋ ˆ์Šค ์ƒํ’ˆ์—์„œ๋Š” ๋ฌด๋ฃŒ SSL ์žฌ๊ณตํ•œ๋‹ค๊ณ  ํ‘œ์‹œ ๋˜์–ด์žˆ์œผ๋‹ˆ ์•„๋งˆ ๊ทธ์ชฝ ํŒ”๋ ค๊ณ  ํ•˜์ง€ ์•Š์„๊นŒ ์‹ถ์€๋ฐ

4 Likes

I use 10G ๊ด‘์•„์šฐํ† ๋ฐ˜ FullSSD Plus ํผ์ŠคํŠธํด๋ž˜์Šค and unfortunately can't change it yet.
It doesn't come with SSL in it, I think, so that's why I was using let's encrypt.

๊ทธ๋Ÿผ ์•„๋งˆ ๋ฐ–์—์„œ ์ธ์ฆ์„œ๋ฅผ ๊ฐ€์ ธ์™€์•ผ ํ•˜๋‹ˆ๊นŒ ์œˆ๋„์šฐ์—์„œ ์ฒ˜๋ฆฌํ•ด์•ผ ํ•˜๋Š”๋ฐ ํŒŒ์ผ ์ˆ˜๋™์œผ๋กœ ์˜ฌ๋ฆฌ๋Š”๊ฑด ๊ท€์ฐฎ์€ ์ž‘์—…์ด๋ผ ํ•œ๋ฒˆ ๊ทธ WP ํ”Œ๋Ÿฌ๊ทธ์ธ ๋‹ค์‹œ ๋Œ๋ ค์„œ ์ธ์ฆ์„œ ์ƒ์„ฑ์€ ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•˜๊ณ  ์‹ถ์€๋ฐ ๊ฐ€๋Šฅํ• ๊นŒ์š”?, ๊ทธ๋ ‡๊ฒŒ ์ƒ์„ฑ๋๋‹ค๋ฉด Manual SSL installation ๋งค๋‰ด์—์„œ ํŒŒ์ผ๋“ค ๋ฐ›์•„์„œ cafe24 ํŒจ๋„์—๋‹ค ์˜ฌ๋ฆฌ๋ฉด ๋˜๋Š”๊ฑด๋ฐ
then you'd have to import it by web panel, while it's considered hearsay in here, I think web or windows based client: but before this could you try reorder certificate by that plugin?

4 Likes

I did exactly that last time: created new cert with plugin, installed in cafe24 web panel (and asked to delete the old ones) but it didn't work and still shows the same old cert. Even the file itself as I posted it a few hours ago.
This is the new cert (issued just now):

Summary

-----BEGIN CERTIFICATE-----
MIIGKzCCBROgAwIBAgISBGpdNAdedSDJhz1LM4BeqhWWMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMzA0MTMwNTEyMDBaFw0yMzA3MTIwNTExNTlaMBUxEzARBgNVBAMT
CmNsZWFuaS5iaXowggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDShihM
6OpPH/YTYwnqQGHkB4zKppcbxHi5bNHGCP+GW5mNW8U1219ey41ASPyv+Ay9r4sO
C1494FZ0jUo0iYR7+J7fjS6M/BNaR9fljcqRvCdveHXSmtnsouNfJcyhgEiFWLoW
QoW5EiQYqaftYDTriJeC04pPLlPmlny5bWvMkJqULiGG070dW4kG5VGV06CztfM5
twNXfDJKhZt8/jh/QI48VszdtkiTsWIKOv9M+9wG8pn9t49HuLKcSJC9oTWYX+Qd
KsM1yGnZKv/Q8Dd2sDjpsa+wvcYdL7OwrDUExpU4euQYqIDByTNb6p8PpCXnCJmd
nXCoJu0CUbhioDpo4RrR2jdUYQoPxu/D6pCdWY6X5lJKevTcvS0Wj4y4yNx1kw6E
EEO2unsNJcpG4cVZu+dVauCrnBagdk3xB0qEbPaIlGeyP/Wue6Vv6neC4Oi1DPiH
Uq2FXGAIQ01xbTO8ODR1v2YY6sD/eTjYRnZvPNy7wxEN1fDnW/lr8uHPYX1eJ9+T
COpLEoWstYt0m4pGGSLzB8cxvT/vQRo0lcPRCUCcy85EAxQY39L/qC/PpnrI526H
K31Xss1jQlga+94tnn372gqxQgzn2DEIz+nWoqFMmHzxAXgZTfyBzbp6SmwbAynd
Ks8jJZkDpFFC2rPLDn06w6OqqQeotbNJYSJXgwIDAQABo4ICVjCCAlIwDgYDVR0P
AQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMB
Af8EAjAAMB0GA1UdDgQWBBQJryX/w+BKZrw5+yxikXRveBPXQjAfBgNVHSMEGDAW
gBQULrMXt1hWy65QCUDmH6+dixTCxjBVBggrBgEFBQcBAQRJMEcwIQYIKwYBBQUH
MAGGFWh0dHA6Ly9yMy5vLmxlbmNyLm9yZzAiBggrBgEFBQcwAoYWaHR0cDovL3Iz
LmkubGVuY3Iub3JnLzAlBgNVHREEHjAcggpjbGVhbmkuYml6gg53d3cuY2xlYW5p
LmJpejBMBgNVHSAERTBDMAgGBmeBDAECATA3BgsrBgEEAYLfEwEBATAoMCYGCCsG
AQUFBwIBFhpodHRwOi8vY3BzLmxldHNlbmNyeXB0Lm9yZzCCAQUGCisGAQQB1nkC
BAIEgfYEgfMA8QB3ALc++yTfnE26dfI5xbpY9Gxd/ELPep81xJ4dCYEl7bSZAAAB
h3k+BwAAAAQDAEgwRgIhAJYttsM8SZxuTkSKptT9AnmFsFyfqKdA7Uh45C3MK3q1
AiEA7hWIe6mFXAQ88HYGNssYVBU3kEinSryZWYrRMm1pKXYAdgB6MoxU2LcttiDq
OOBSHumEFnAyE4VNO9IrwTpXo1LrUgAAAYd5PgclAAAEAwBHMEUCIFlXPA7MipFT
89291zcsA/7UEr3jQZVhe5Kz83aSV5StAiEAxK3BSjRd+hDtmKT3ESkRfa/qgF2v
X4Dw8vkdYTeqvZ8wDQYJKoZIhvcNAQELBQADggEBAFsGPb29T0614HpVa8Y+4cO8
563Y+16rS6rvLZtYIuVamE6UCMZWgL8PjrWJtcrKC8O7Fl8/ZdMKhc70FVdAFxKs
UNDJSDEZ+d1jgTNUmBFdfDIN3vIXqUo/SGOTlCStSBDz58YntX8AMFsFvSeHvfka
JMyq961+RdVPoJb+XiQ0ln0Z35AJc7uyBr01O8s3X6NtIxCh9E9NzmFqpyKFfwVS
SRRYHLKawkJRjwNGMSVv1/wUiugWd0WHSJoh6rhZwVCFPiUY38PP3Oc7rBqK0/9m
kWdRKAbbsMNIKJn/RLE/zvtQ6VUe8L/kOr3dQz3Yr46IRJzLj1PkA5kS1K64psY=
-----END CERTIFICATE-----

what it's status page says? it should say why it still holds old certifiate.
https://really-simple-ssl.com/renewing-a-really-simple-ssl-lets-encrypt-ssl-certificate/

4 Likes

Basically it feels like installation is incomplete, bc it never said anything about the old certificate. When I started to renew processs I looked up if plugin says anything but it was in the same state as now.


looks like it's permission problem where that plugin supporse to save its key, ( on level above wp-content, ssl dir) , can you delete that dir?

4 Likes

yes, I deleted it, The plugin looks the same though

than I think using web client is only option now, zerossl.com?

4 Likes