# Si the certificate generate here can be used for both www and non-www?

**URL:** <https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019>\
**Category:** Server\
**Created:** [December 2, 2018, 5:32pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019 "2018-12-02T17:32:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 2, 2018, 5:32pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/1 "2018-12-02T17:32:15Z")

</div>

is the certificate generated from this can be used for both www and non-www?

This normally will "work"

> \<VirtualHost \*:80\>  
> ServerName [domain.com](http://domain.com)  
> ServerAlias \*.domain.com
> 
> ```
> DocumentRoot /home/domain/public_html
> <Directory "/home/domain/public_html">
> Require all granted
> </Directory>
> 
> ```
> 
> RewriteEngine on  
> RewriteCond %{SERVER\_NAME} =[www.domain.com](http://www.domain.com) [OR]  
> RewriteCond %{SERVER\_ALIAS} =[domain.com](http://domain.com)  
> RewriteRule ^ https://%{SERVER\_NAME}%{REQUEST\_URI} [END,NE,R=permanent]

I run certbot --apache -d [www.domain.com](http://www.domain.com)

type the domain in the browser and if the domain is typed without www in it it will redirect to an url that has a www in it, but if you remove www after it loads and enter I got an error saying that the website is not secure . . . if I tried to generate a cert for the domain without www in it

certbot --apache -d [domain.com](http://domain.com)

and do the same thing, open a browser type in [www.domain.com](http://www.domain.com), it will show an error saying that the website is not secure and a url that has no www in it just type [domain.com](http://domain.com) will load without a problem.

the rewrite condition is set by certbot automatically, So I didn't touch those.

what could be possibly wrong here? is the free certificate only applicable for either [www.domain.com](http://www.domain.com) or [domain.com](http://domain.com) only?

I disable ssl on this domain that I used this, because of this issue.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [December 2, 2018, 5:35pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/2 "2018-12-02T17:35:08Z")

</div>

Hi @blackwing

your both commands are wrong. You must add both domain names with the -d option

> [@blackwing](#):
>
> I run certbot --apache d [www.domain.com](http://www.domain.com)

Instead:

```nohighlight
certbot --apache -d www.domain.com -d domain.com

```

So you order **one** certificate with **two** domain names.

This has nothing to do with your redirects.

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 2, 2018, 5:39pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/3 "2018-12-02T17:39:27Z")

</div>

yes may mistake that was with “-d” in the command. @JuergenAuer. at some point I did tried to use that command. But end-up with the same issue, but I will try again and see if it will work.

I also use

certbot --apache

and choose on the list of domain

1. [domain.com](http://domain.com)
2. [www.domain.com](http://www.domain.com)

In which I did both. is that also wrong?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [December 2, 2018, 5:45pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/4 "2018-12-02T17:45:46Z")

</div>

No, choosing domains from the interactive list works about the same as using `-d` arguments.

Can you tell us your domain, Certbot’s output, the output of “`sudo certbot certificates`”, and what’s going wrong?

Be mindful of Let’s Encrypt’s rate limits and don’t generate too many duplicate certificates while working on this.

> **[Rate Limits - Let's Encrypt - Free SSL/TLS Certificates](https://letsencrypt.org/docs/rate-limits/)**
>
> Last updated: August 1, 2018 | See all Documentation
> Let’s Encrypt provides rate limits to ensure fair usage by as many people as possible. We believe these rate limits are high enough to work for most people by default. We’ve also designed them so...

* * *

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 2, 2018, 6:00pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/5 "2018-12-02T18:00:03Z")

</div>

My domain is: [http://www.growingstrongergame.com](http://www.growingstrongergame.com)

I ran this command: certbot --apache

It produced this output:

1. [growingstrongergame.com](http://growingstrongergame.com)
2. [Www.growingstrongergame.com](http://Www.growingstrongergame.com)

Then . .

1. No redirect . . .
2. Redirect . . .

Then all is good

My web server is (include version): httpd

The operating system my web server runs on is (include version): centos 7

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

Again I disable ssl for now. Since thebproblem is when I type [growingstrongergame.com](http://growingstrongergame.com) it will redirect to [https://www.growingstrongergame.com](https://www.growingstrongergame.com) which is perfect, but if I remove www on that url that loads it will say website is not fully secure its immitating [www.growingstrongergame.com](http://www.growingstrongergame.com) something like that.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [December 2, 2018, 6:54pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/6 "2018-12-02T18:54:40Z")

</div>

> [@blackwing](#):
>
> Again I disable ssl for now.

Now you have a special problem - Grade Q in my ranking system ( [https://check-your-website.server-daten.de/?q=growingstrongergame.com](https://check-your-website.server-daten.de/?q=growingstrongergame.com) ):

* * *

| Domainname | Http-Status | redirect | Sec. | G |
| --- | --- | --- | --- | --- |
| • [http://growingstrongergame.com/](http://growingstrongergame.com/) | | | | |
| 207.29.229.39 | 200 | | 0.344 | H |
| | | | | |
| • [http://www.growingstrongergame.com/](http://www.growingstrongergame.com/) | | | | |
| 207.29.229.39 | 200 | | 0.347 | H |
| | | | | |
| • [https://growingstrongergame.com/](https://growingstrongergame.com/) | | | | |
| 207.29.229.39 | -4 | | 0.677 | W |
| SendFailure - The underlying connection was closed: An unexpected error occurred on a send. The handshake failed due to an unexpected packet format. | | | | |
| | | | | |
| • [https://www.growingstrongergame.com/](https://www.growingstrongergame.com/) | | | | |
| 207.29.229.39 | -4 | | 0.673 | W |
| SendFailure - The underlying connection was closed: An unexpected error occurred on a send. The handshake failed due to an unexpected packet format. | | | | |
| | | | | |
| • [http://growingstrongergame.com:443/](http://growingstrongergame.com:443/) | | | | |
| 207.29.229.39 | 200 | | 0.347 | Q |
| | | | | |
| • [http://www.growingstrongergame.com:443/](http://www.growingstrongergame.com:443/) | | | | |
| 207.29.229.39 | 200 | | 0.343 | Q |

* * *

Your https doesn't work - with a special error message:

> SendFailure - The underlying connection was closed: An unexpected error occurred on a send. The handshake failed due to an unexpected packet format.

Reason: You send http over port 443. This is checked - and there is a http status 200 sent.

Http over port 443 is always bad.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 2, 2018, 8:25pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/7 "2018-12-02T20:25:31Z")

</div>

> [@blackwing](#):
>
> I ran this command: certbot --apache
> 
> It produced this output:
> 
> 1. [growingstrongergame.com](http://growingstrongergame.com)
> 2. [Www.growingstrongergame.com](http://Www.growingstrongergame.com)

This happens when the names are in two vhost configs.  
if both names go to the same folder, then combine them into just one vhost config:  
`servername growingstrongergame.com`  
`serveralias www.growingstrongergame.com`  
(or whatever the syntax is for your web server software)

If the two names do two different things (separate folders), then you will have to treat them as completely separate sites and issues them certs individually.

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 3, 2018, 12:50am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/8 "2018-12-03T00:50:07Z")

</div>

This is in just 1 vhost config

Servername [growingstrongergame.com](http://growingstrongergame.com)  
ServerAlias [www.growingstrongergame.com](http://www.growingstrongergame.com)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 3, 2018, 12:53am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/9 "2018-12-03T00:53:30Z")

</div>

Please show:  
`grep -Eri 'growingstrongergame|servername|serveralias|sslcertificate' /etc/apache2/`  
`ls -l /etc/apache2/sites-enabled/`

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 3, 2018, 5:54am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/10 "2018-12-03T05:54:11Z")

</div>

/etc/httpd/conf/httpd.conf:# ServerName gives the name and port that the server uses to identify itself.  
/etc/httpd/conf/httpd.conf:#ServerName [www.example.com:80](http://www.example.com:80)  
/etc/httpd/conf/httpd.conf:#Include /etc/httpd/sites-available/growingstrongergame.com-le-ssl.conf  
/etc/httpd/sites-available/growingstrongergame.com.conf: ServerName [growingstrongergame.com](http://growingstrongergame.com)  
/etc/httpd/sites-available/growingstrongergame.com.conf: ServerAlias [www.growingstrongergame.com](http://www.growingstrongergame.com)  
/etc/httpd/sites-available/growingstrongergame.com.conf: ErrorLog logs/growingstrongergame.com-error\_log  
/etc/httpd/sites-available/growingstrongergame.com.conf: CustomLog logs/growingstrongergame.com-access\_log common

ls -l /etc/httpd/sites-available/  
-rw-r–r-- 1 root root 378 Dec 2 11:47 growingstrongergame.com.conf

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 3, 2018, 2:30pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/11 "2018-12-03T14:30:50Z")

</div>

> [@blackwing](#):
>
> I ran this command: certbot --apache
> 
> It produced this output:
> 
> 1. [growingstrongergame.com](http://growingstrongergame.com)
> 2. [Www.growingstrongergame.com](http://Www.growingstrongergame.com)
> 
> Then . .
> 
> 1. No redirect . . .
> 2. Redirect . . .

For now, I would try:  
1,2 [at first prompt]  
1 [at second prompt]

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 3, 2018, 2:31pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/12 "2018-12-03T14:31:56Z")

</div>

> [@blackwing](#):
>
> `ls -l /etc/httpd/sites-available/`

I asked for the sites-ENABLED:

> [@rg305](#):
>
> `ls -l /etc/apache2/sites-enabled/`

So, please show:  
`ls -l /etc/httpd/sites-enabled/`

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 3, 2018, 3:58pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/13 "2018-12-03T15:58:17Z")

</div>

growingstrongergame.com.conf -\> /etc/httpd/sites-available/growingstrongergame.com.conf

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 3, 2018, 3:59pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/14 "2018-12-03T15:59:14Z")

</div>

I actually did this, but still in the same problem

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 3, 2018, 4:07pm UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/15 "2018-12-03T16:07:18Z")

</div>

Did you try them together in one request (as @JuergenAuer suggested)?:

> [@JuergenAuer](#):
>
> `certbot --apache -d www.domain.com -d domain.com`

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 4, 2018, 3:19am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/16 "2018-12-04T03:19:39Z")

</div>

yup I did and still end up with the same issue.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [December 4, 2018, 8:01am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/17 "2018-12-04T08:01:33Z")

</div>

> [@blackwing](#):
>
> yup I did and still end up with the same issue.

There is no certificate with two domain names:

[https://transparencyreport.google.com/https/certificates?cert\_search\_auth=&cert\_search\_cert=&cert\_search=include\_expired:false;include\_subdomains:false;domain:growingstrongergame.com&lu=cert\_search](https://transparencyreport.google.com/https/certificates?cert_search_auth=&cert_search_cert=&cert_search=include_expired:false;include_subdomains:false;domain:growingstrongergame.com&lu=cert_search)

Three with the non-www - version (pre- and leaf-certificate), one

[https://transparencyreport.google.com/https/certificates?cert\_search\_auth=&cert\_search\_cert=&cert\_search=include\_expired:false;include\_subdomains:false;domain:www.growingstrongergame.com&lu=cert\_search](https://transparencyreport.google.com/https/certificates?cert_search_auth=&cert_search_cert=&cert_search=include_expired:false;include_subdomains:false;domain:www.growingstrongergame.com&lu=cert_search)

with the www-version.

No certificate with two domain names.

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 6, 2018, 6:08am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/18 "2018-12-06T06:08:26Z")

</div>

> [@JuergenAuer](#):
>
> certbot --apache -d [www.domain.com](http://www.domain.com) -d [domain.com](http://domain.com)

I was able to make it work in a different domain and server this time using the above command.

domain: racequeen.ph

both [https://racequeen.ph](https://racequeen.ph) and [https://www.racequeen.ph](https://www.racequeen.ph) work.

---

<div class="post-metadata">

**Author:** ![blackwing](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@blackwing](https://community.letsencrypt.org/u/blackwing)\
**Post date:** [December 6, 2018, 8:33am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/19 "2018-12-06T08:33:14Z")

</div>

will this work on a server that has multiple domain in one IP?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 6, 2018, 8:58am UTC](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019/20 "2018-12-06T08:58:13Z")

</div>

> [@blackwing](#):
>
> will this work on a server that has multiple domain in one IP?

Will "what" work?  
If you mean, can certbot handle multiple domains in one IP? YES  
If you mean, can my system (web server) handle multiple domains in one IP?  
That depends on your web server version and your configuration.

[Next page](https://community.letsencrypt.org/t/si-the-certificate-generate-here-can-be-used-for-both-www-and-non-www/79019.md?page=2)
