SSL not safe on subdomain (other server)


I have 2 servers, one main server
and the second where the subdomain points to…

The main certificate on server one is working perfect.
I asked for a new one on the second server
but it gives an error in the browser (unsafe).

Is there some solution to get it working?

You’re not using Let’s Encrpyt certificates on either of these domains. has a certificate from GlobalSign, and has a self-signed certificate. Are you sure your web server is set to use these, and that you reloaded its configuration to have the Let’s Encrypt certificate take effect on them?

Normally yes i think… they were generated in /etc/letsencrypt/live/
To be shure i also restarted the vps…

I also checked the main domain
Issuer Name
commonName=Let’s Encrypt Authority X3
organizationName=Let’s Encrypt

This was the command i used on the vps.
letsencrypt-auto certonly --webroot --webroot-path /var/www/html -d -d

openssl x509 -in /etc/letsencrypt/live/ -text -noout returns
Issuer: C=US, O=Let’s Encrypt, CN=Let’s Encrypt Authority X3
Not Before: Aug 15 13:16:00 2017 GMT
Not After : Nov 13 13:16:00 2017 GMT

Authority Information Access:
CA Issuers - URI:

        X509v3 Subject Alternative Name:
        X509v3 Certificate Policies:

When you use “certonly”, that means “only obtain the certificate, don’t install it”. That means that it obtained the certificate (in that PEM file that you saw) but it didn’t do anything to tell any software on your system to use the new certificate.

Hm, something strange happened in my test environment’s DNS for this - you’re right that has a Let’s Encrypt certificate.

You definitely have a self-signed certificate in place for, though. Schoen already mentioned the need to explicitly install this certificate to your webserver, not just having it present there.

certbot-auto --apache -d -d
it’s working :slight_smile:

