# SSL certificate doesn't work

**URL:** <https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979>\
**Category:** Help\
**Created:** [July 4, 2018, 11:14pm UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979 "2018-07-04T23:14:01Z")\
**Posts on this page:** 13\
**Page:** 2

<div class="post-metadata">

**Author:** ![aeciid](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aeciid](https://community.letsencrypt.org/u/aeciid)\
**Post date:** [July 5, 2018, 12:38am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/21 "2018-07-05T00:38:07Z")

</div>

god … I’m sleepy. Of course! I just hoped that to have been the error 😅

Found the following certs:  
Certificate Name: domain  
Domains: domain  
Expiry Date: 2018-10-02 21:39:21+00:00 (VALID: 89 days)  
Certificate Path: /etc/letsencrypt/live/domain/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/domain/privkey.pem  
Certificate Name: domain  
Domains: domain domain  
Expiry Date: 2018-10-01 19:25:11+00:00 (VALID: 88 days)  
Certificate Path: /etc/letsencrypt/live/domain/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/domain/privkey.pem

I guess having two certificates for the www. might be the issue?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 5, 2018, 12:42am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/22 "2018-07-05T00:42:23Z")

</div>

I don’t see why it’d be a problem, but being that it’s redundant and I’m out of other ideas, it’s worth deleting the useless one:

```
sudo certbot delete --cert-name www.x

```

Whether it helps your installation problem or not … who knows.

---

<div class="post-metadata">

**Author:** ![aeciid](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aeciid](https://community.letsencrypt.org/u/aeciid)\
**Post date:** [July 5, 2018, 12:46am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/23 "2018-07-05T00:46:21Z")

</div>

Doesn’t seem to have done anything.

I’m not sure what to think of the fact that the whole website isn’t accessable via https. I mean, I’d be fine with an security error or something but isn’t that a bit odd? I guess I could just go back to enabling cloudflair’s dns proxy and ssl certificate and hope that it won’t bite my ass down the road. But not having a local ssl certificate in case cloudflair dies is a bit of a bummer.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 5, 2018, 12:49am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/24 "2018-07-05T00:49:06Z")

</div>

You can configure Apache by hand to listen on HTTPS for your domain, like I suggested before.

You have a perfectly usable certificate, it’s just that Certbot’s automatic Apache installer doesn’t work for some reason.

```apache
<IfModule mod_ssl.c>
<VirtualHost *:443>
    ServerAdmin admin@example.com
    ServerName x
    ServerAlias x
    DocumentRoot /var/www/html/store/
    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined

Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/x/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/x/privkey.pem
</VirtualHost>
</IfModule>

```

_/etc/letsencrypt/options-ssl-apache.conf_

```apache
# This file contains important security parameters. If you modify this file
# manually, Certbot will be unable to automatically provide future security
# updates. Instead, Certbot will print and log an error message with a path to
# the up-to-date file that you will need to refer to when manually updating
# this file.

SSLEngine on

# Intermediate configuration, tweak to your needs
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
SSLHonorCipherOrder on
SSLCompression off

SSLOptions +StrictRequire

# Add vhost name to log entries:
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-agent}i\"" vhost_combined
LogFormat "%v %h %l %u %t \"%r\" %>s %b" vhost_common

#CustomLog /var/log/apache2/access.log vhost_combined
#LogLevel warn
#ErrorLog /var/log/apache2/error.log

# Always ensure Cookies have "Secure" set (JAH 2012/1)
#Header edit Set-Cookie (?i)^(.*)(;\s*secure)??((\s*;)?(.*)) "$1; Secure$3$4"

```

---

<div class="post-metadata">

**Author:** ![aeciid](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aeciid](https://community.letsencrypt.org/u/aeciid)\
**Post date:** [July 5, 2018, 12:53am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/25 "2018-07-05T00:53:23Z")

</div>

I’ve added the virtual host part into the existing one, below the one regarding port 80 and changed the options-ssl-apache.conf and then restarted apache. Still getting the same connection refused error.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 5, 2018, 12:53am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/26 "2018-07-05T00:53:55Z")

</div>

Might need to

```
sudo a2enmod ssl

```

If that doesn’t work, show `apachectl -S` again.

---

<div class="post-metadata">

**Author:** ![aeciid](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aeciid](https://community.letsencrypt.org/u/aeciid)\
**Post date:** [July 5, 2018, 1:01am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/27 "2018-07-05T01:01:39Z")

</div>

You sir, are a legend. Thank you very much for the help. So I take it, that it actually was related to certbot’s automatic apache installer.

About 10 posts ago I was considering to ask you to remove the domain’s url from the posts once you’re done troubleshooting me but frankly, I probably wouldn’t bother myself to do that for a stranger after fixing his problem.

All in all, I’m infinitely grateful. You’re a legend! Thank you! (:

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 5, 2018, 1:04am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/28 "2018-07-05T01:04:27Z")

</div>

No problem. You can ask a moderator (e.g. @mnordhoff) to remove your domain, if you or I do it, it just shows up in the edit history anyway.

---

<div class="post-metadata">

**Author:** ![aeciid](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aeciid](https://community.letsencrypt.org/u/aeciid)\
**Post date:** [July 5, 2018, 1:05am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/29 "2018-07-05T01:05:36Z")

</div>

I’m embarassed to ask that but … how do you send people private messages in here?

Edit: Appareantly I’m not allowed to send messages to the people in the moderator group. 🤨

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [July 5, 2018, 1:58am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/30 "2018-07-05T01:58:14Z")

</div>

Hi. I hid the relevant edit history.

I also edited a link in one of your posts.

I **also** accidentally reverted one of your posts to the bad version, then reverted it again to the good version. 😓 My browser lagged and the button moved. 😓

@_az, could you edit [post 24](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/24?u=mnordhoff)? Or do you mind if someone else does?

Edit: @aeciid: This whole thread has probably been archived by search engines, though.

Edit edit:

@aeciid, I edited a second one of your posts. (On purpose.)

@_az, actually several of your posts show the domain.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [July 5, 2018, 2:08am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/31 "2018-07-05T02:08:32Z")

</div>

All done. I think. Thanks, @_az.

---

<div class="post-metadata">

**Author:** ![aeciid](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aeciid](https://community.letsencrypt.org/u/aeciid)\
**Post date:** [July 5, 2018, 2:12am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/32 "2018-07-05T02:12:32Z")

</div>

Thank you so much! 🙂

Even if it already has been archived by search engines, not having the domain actively displayed already goes a long shot in not making me appear like a total fraud to my customer 😂

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 4, 2018, 2:12am UTC](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979/33 "2018-08-04T02:12:45Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.

[Previous page](https://community.letsencrypt.org/t/ssl-certificate-doesnt-work/65979.md?page=1)
