# Ssl\_error\_bad\_cert\_domain

**URL:** <https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458>\
**Category:** Help\
**Created:** [September 20, 2023, 1:39pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458 "2023-09-20T13:39:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![dzhus](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dzhus](https://community.letsencrypt.org/u/dzhus)\
**Post date:** [September 20, 2023, 1:39pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/1 "2023-09-20T13:39:44Z")

</div>

The operating system my web server runs on is (include version): DSM 7.2-64570 Update 3  
I can login to a root shell on my machine (yes or no, or I don't know): yes

**Problem:**  
Most applications, including PLEX, ... say that the certificate is not reliable or is self-signed, and it is not possible to continue working.  
Basically I see the error "SSL\_ERROR\_BAD\_CERT\_DOMAIN".  
or  
"has a security policy called HTTP Forced Secure Connection (HSTS), which means that Firefox can only connect to it through a secure connection. You cannot add an exception to visit this site."  
.....

Although I renewed the certificate several times and sent requests for certificate verification to letsencrypt.

I'm trying to understand what the problem is and how it can be solved.  
This has never happened before and everything worked fine for several years.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [September 20, 2023, 1:54pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/2 "2023-09-20T13:54:50Z")

</div>

> [@dzhus](#):
>
> [https://dzhus.synology.me/](https://dzhus.synology.me/)

I can open this just fine. [SSL Server Test: dzhus.synology.me (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=dzhus.synology.me&hideResults=on&latest)

My suspect is that somebody is messing with your internet connection. (Or NAT hairpinning doesn't work on your LAN, try accessing from mobile data)

---

<div class="post-metadata">

**Author:** ![dzhus](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dzhus](https://community.letsencrypt.org/u/dzhus)\
**Post date:** [September 20, 2023, 2:43pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/3 "2023-09-20T14:43:41Z")

</div>

> [@9peppe](#):
>
> My suspect is that somebody is messing with your internet connection. (Or NAT hairpinning doesn't work on your LAN, try accessing from mobile data)

Everything is fine with access to the site, the problem is mainly when working through applications that say that the certificate is not reliable. And they lose access.  
I can’t open Plex at all, through the Firefox browser, it says has a security policy called HTTP Forced Secure Connection (HSTS), which means that Firefox can only connect to it through a secure connection. You cannot add an exception to visit this site" and there is no access.

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [September 20, 2023, 3:12pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/4 "2023-09-20T15:12:31Z")

</div>

what cerifitace it sees when error is happening?  
openssl s-client to there?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 20, 2023, 3:29pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/5 "2023-09-20T15:29:41Z")

</div>

What domain name are you using in the apps and Firefox? Because you used to get a wildcard cert that would cover many names but now only two names are in your cert - your `dzhus.synology.me` and the `mail` subdomain of that.

You need to use the wildcard cert if you will be using other subdomain names

> **[SSL Checker](https://decoder.link/sslchecker/dzhus.synology.me/443)**
>
> Verify that your SSL certificate is installed correctly, identify installation issues if any.

[https://tools.letsdebug.net/cert-search?m=domain&q=dzhus.synology.me&d=2160](https://tools.letsdebug.net/cert-search?m=domain&q=dzhus.synology.me&d=2160)

---

<div class="post-metadata">

**Author:** ![dzhus](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dzhus](https://community.letsencrypt.org/u/dzhus)\
**Post date:** [September 20, 2023, 7:06pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/6 "2023-09-20T19:06:14Z")

</div>

Everything seems to be fine here, thank you.

---

<div class="post-metadata">

**Author:** ![dzhus](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dzhus](https://community.letsencrypt.org/u/dzhus)\
**Post date:** [September 20, 2023, 7:09pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/7 "2023-09-20T19:09:49Z")

</div>

Seems to have fixed all the problems.  
The only problem left is with Plex, when I launch from my domain, all browsers write SSL\_ERROR\_BAD\_CERT\_DOMAIN

has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can only go there using a secure connection. You cannot add an exception to visit this site.  
Subdomains don't help

Ports are open.  
Any ideas what can be done?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 20, 2023, 7:17pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/8 "2023-09-20T19:17:12Z")

</div>

You need to review your Plex config then because it is not using the Let's Encrypt cert. You could try the Synology forum

See the Plex cert with a site like this

> **[SSL Checker](https://decoder.link/sslchecker/dzhus.synology.me/32400)**
>
> Verify that your SSL certificate is installed correctly, identify installation issues if any.

If you don't want to use HSTS you can turn it off. That's totally up to you. It is not part of the cert and it is not part of DNS. It is set in the response headers for HTTPS requests.  
I don't know how you configure Synology for that but in nginx you set response headers in the server block for the HTTPS port(s). After disabling it you would need to empty the HSTS cache in any browser.

---

<div class="post-metadata">

**Author:** ![dzhus](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dzhus](https://community.letsencrypt.org/u/dzhus)\
**Post date:** [September 20, 2023, 7:34pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/9 "2023-09-20T19:34:44Z")

</div>

Thank you very much, everything worked. I turned it on before but didn't clear the cache. I cleared the cache and everything worked. Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 20, 2023, 7:34pm UTC](https://community.letsencrypt.org/t/ssl-error-bad-cert-domain/205458/10 "2023-10-20T19:34:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
