# \[Solved\] Curl error for multiple domains

**URL:** <https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060>\
**Category:** Server\
**Created:** [November 10, 2017, 7:12pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060 "2017-11-10T19:12:39Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 7:12pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/1 "2017-11-10T19:12:39Z")

</div>

I run a single server with 2 different domains. My cert request command looks something like this:

`letsencrypt certonly -a webroot --webroot-path=/var/www/foo.com/htdocs -d foo.com --webroot-path=/var/www/bar.com/htdocs -d bar.com`

In this way I generate one certificate file for both domains and include it in the main `nginx.conf` file `http { }` block once, so it applies to all `server { }` blocks, keep it short and clean. It all works, certificate is valid, no errors, pass all tests, etc.

But if you run `curl -l https://www.bar.com` you get `curl: (51) SSL: certificate subject name (foo.com) does not match target host name 'bar.com'`

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [November 10, 2017, 7:20pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/2 "2017-11-10T19:20:30Z")

</div>

Hi @ksatam,

If you tell us the domain names, we could figure out more.

It sounds like you most likely forgot to add `-d www.bar.com`, which is a distinct subject name from `bar.com`.

---

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 7:22pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/3 "2017-11-10T19:22:32Z")

</div>

I did, I added both www and non-www for both domains so total of 4.

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [November 10, 2017, 7:36pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/4 "2017-11-10T19:36:16Z")

</div>

Reiterating what schoen mentioned, without more info it’s exceptionally difficult to help troubleshoot this. Please provide the actual domain names in use. Bear in mind that these have already been publicly - and permanently - posted to the certificate transparency logs, so there’s no real increase in secrecy by not divulging them.

---

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 8:03pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/5 "2017-11-10T20:03:13Z")

</div>

Don’t want to be rude, but posting links in public forums expose them to search engines. Why not just try to guide me through the troubleshoot steps? Or I can PM links.

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [November 10, 2017, 8:30pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/6 "2017-11-10T20:30:05Z")

</div>

That’s neither rude nor the first time someone has espoused that particular concern, no worries! It’s worth noting that domains are indexable in the CT logs as well. (Although in fairness, less likely to be found in most casual search engine results.) One option if you’re concerned about this, however, is to edit the post once things are solved. It’ll still be visible in edit history of course, but this isn’t indexed by search engines to the best of my knowledge.

Thinking a bit more about this, another option would be if you could you provide the fingerprint of the certificate? That would give us the ability to look up the info in CT logs without exposing anything of value on the forum itself. EDIT: Fingerprint can be taken from the certificate with `openssl x509 -in certificatefile.pem -noout -fingerprint -sha256`, or you could look it up yourself at [https://crt.sh](https://crt.sh) and paste the fingerprint or link to the CT entry here.

Most of us are volunteers with varying skillsets, PMs to a couple people cut down the help you will get from the community and also slow down responses while those you’ve informed of your domain are the only ones most equipped to assist. The issue with just trying to walk you through steps is that it ends up taking several times as long, when as I mentioned, most people here are volunteers.

I can’t speak for Schoen’s ideas of what to look for next, but my steps would be the following: Use openssl’s s\_client to connect to the domain with an issue and see what certificate is coming back and go from there.

---

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 8:49pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/7 "2017-11-10T20:49:27Z")

</div>

Thanks for helping.

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [November 10, 2017, 9:07pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/8 "2017-11-10T21:07:57Z")

</div>

No problem! So, from everything I can tell, it’s looking good to me for the four SANs listed on that certificate. I didn’t get any validation errors. I’ll be checking redirects in a second, but in the meantime, could you verify something for me? In your example, you’re saying `bar.com` works, but `www.bar.com` does not. There are indeed four domains in that, but they’re not `www.foo.com`, `foo.com`, `www.bar.com`, `bar.com`. Rather, you have something more akin to: `d7.foo.com`, `foo.com`, `www.foo.com`, and `bar.lt`. So, if you are trying `bar.lt` and `www.bar.lt`, you’ll get a validation error on the latter.

---

<div class="post-metadata">

**Author:** ![jmorahan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jmorahan/32/1873_2.png) [@jmorahan](https://community.letsencrypt.org/u/jmorahan)\
**Post date:** [November 10, 2017, 9:10pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/9 "2017-11-10T21:10:39Z")

</div>

Looking at the [crt.sh](http://crt.sh) logs, you do seem to _have_ a certificate that covers the www and non-www versions of both domains (and some more subdomains); it’s just not the certificate that your webserver is _using_.

You might try using the `letsencrypt certificates` command (if you have a recent enough version of letsencrypt / certbot) to see if that helps you identify the correct certificate to use.

---

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 9:18pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/10 "2017-11-10T21:18:15Z")

</div>

But I deleted all of the old ones, there’s only one dir in renewal/live/archive dirs. That command does not work, I guess I need to upgrade.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [November 10, 2017, 9:20pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/11 "2017-11-10T21:20:39Z")

</div>

Conceivably, you might have deleted the new one instead of the old one by mistake.

---

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 9:34pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/12 "2017-11-10T21:34:47Z")

</div>

I deleted all letsencrypt directories and reinstalled latest version and recreated new certs and I still get same curl error. `letsencrypt certificates` finds only one certificate.

I restarted Nginx.

---

<div class="post-metadata">

**Author:** ![jmorahan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jmorahan/32/1873_2.png) [@jmorahan](https://community.letsencrypt.org/u/jmorahan)\
**Post date:** [November 10, 2017, 9:51pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/13 "2017-11-10T21:51:04Z")

</div>

Well, that certificate is missing one of the `www` subdomains (the `.lt` one). (You can see the (sub)domains that the certificate is valid for on `crt.sh` under the heading “X509v3 Subject Alternative Name”).

If you deleted all the old ones, including the one that covered the correct set of domains, you’ll just have to issue it again. This time, make sure to specify _all_ the domains you need on the certificate, in a single command.

---

<div class="post-metadata">

**Author:** ![ksatam](https://avatars.discourse-cdn.com/v4/letter/k/8491ac/32.png) [@ksatam](https://community.letsencrypt.org/u/ksatam)\
**Post date:** [November 10, 2017, 10:04pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/14 "2017-11-10T22:04:16Z")

</div>

You are right. I think it’s solved. Cheers.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 10, 2017, 10:04pm UTC](https://community.letsencrypt.org/t/solved-curl-error-for-multiple-domains/46060/15 "2017-12-10T22:04:48Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
