# Ssl Not working on "www"

**URL:** <https://community.letsencrypt.org/t/ssl-not-working-on-www/93496>\
**Category:** Help\
**Created:** [May 13, 2019, 8:08pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496 "2019-05-13T20:08:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yohaan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/yohaan/32/31823_2.png) [@yohaan](https://community.letsencrypt.org/u/yohaan)\
**Post date:** [May 13, 2019, 8:08pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/1 "2019-05-13T20:08:45Z")

</div>

My domain is:tanmayplywood.com

I ran this command: sudo certbot certonly --webroot -w /var/www/html -d [www.tanmayplywood.com](http://www.tanmayplywood.com) -d [tanmayplywood.com](http://tanmayplywood.com)

It produced this output: You have an existing certificate that has exactly the same domains or certificate name you requested and isn't close to expiry.  
(ref: /etc/letsencrypt/renewal/www.tanmayplywood.com.conf)

My web server is (include version): Apache

The operating system my web server runs on is (include version): Centos 7

My hosting provider, if applicable, is: AWS

I can login to a root shell on my machine (yes or no, or I don't know): YES i can

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):CWP7

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):certbot 0.31.0

I wrote

> "certbot certificates"

and i found this reply,

Found the following certs:

> Certificate Name: [tanmayplywood.com](http://tanmayplywood.com/)  
> Domains: [tanmayplywood.com](http://tanmayplywood.com/)  
> Expiry Date: 2019-07-25 19:03:36+00:00 (VALID: 72 days)  
> Certificate Path: /etc/letsencrypt/live/tanmayplywood.com/fullchain.pem  
> Private Key Path: /etc/letsencrypt/live/tanmayplywood.com/privkey.pem  
> Certificate Name: [www.tanmayplywood.com](http://www.tanmayplywood.com/)  
> Domains: [www.tanmayplywood.com](http://www.tanmayplywood.com/) [tanmayplywood.com](http://tanmayplywood.com/)  
> Expiry Date: 2019-07-25 18:51:28+00:00 (VALID: 72 days)  
> Certificate Path: /etc/letsencrypt/live/www.tanmayplywood.com/fullchain.pem  
> Private Key Path: /etc/letsencrypt/live/www.tanmayplywood.com/privkey.pem

On PC if i write [www.tanmayplywood.com](http://www.tanmayplywood.com/) it redirects to [tanmayplywood.com](http://tanmayplywood.com/) and no errors are seen.  
but when i open "[www.tanmayplywood.com](http://www.tanmayplywood.com/) on phone it shows “this connection is not private”

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [May 13, 2019, 8:18pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/3 "2019-05-13T20:18:02Z")

</div>

Hi @yohaan

> [@yohaan](#):
>
> On PC if i write [www.tanmayplywood.com](http://www.tanmayplywood.com) it redirects to [tanmayplywood.com](http://tanmayplywood.com) and no errors are seen.

that may be a cached result, so you don't really see / check the www-version.

But checking your domain the www version isn't secure ( [https://check-your-website.server-daten.de/?q=tanmayplywood.com](https://check-your-website.server-daten.de/?q=tanmayplywood.com) ):

| Domainname | Http-Status | redirect | Sec. | G |
| --- | --- | --- | --- | --- |
| • [http://tanmayplywood.com/](http://tanmayplywood.com/) | | | | |
| 13.234.228.103 | 301 | [https://tanmayplywood.com/](https://tanmayplywood.com/) | 0.250 | A |
| | | | | |
| • [http://www.tanmayplywood.com/](http://www.tanmayplywood.com/) | | | | |
| 13.234.228.103 | 301 | [https://www.tanmayplywood.com/](https://www.tanmayplywood.com/) | 0.270 | A |
| | | | | |
| • [https://tanmayplywood.com/](https://tanmayplywood.com/) | | | | |
| 13.234.228.103 | 200 | | 1.723 | B |
| | | | | |
| • [https://www.tanmayplywood.com/](https://www.tanmayplywood.com/) | | | | |
| 13.234.228.103 | 200 | | 1.373 | N |
| Certificate error: RemoteCertificateNameMismatch | | | | |

But: The non-www version has the wrong certificate:

```nohighlight
CN=tanmayplywood.com
	26.04.2019
	25.07.2019
expires in 73 days	tanmayplywood.com - 1 entry

```

What says

```nohighlight
apachectl -S

```

---

<div class="post-metadata">

**Author:** ![yohaan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/yohaan/32/31823_2.png) [@yohaan](https://community.letsencrypt.org/u/yohaan)\
**Post date:** [May 13, 2019, 8:20pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/4 "2019-05-13T20:20:37Z")

</div>

> [centos@ip-172-31-29-237 ~]$ sudo apachectl -S  
> AH00558: httpd: Could not reliably determine the server's fully qualified domain name, using ip-172-31-29-237.ap-south-1.compute.internal. Set the 'ServerName' directive globally to suppress this message  
> VirtualHost configuration:  
> \*:80 [tanmayplywood.com](http://tanmayplywood.com) (/etc/httpd/conf.d/le-redirect-tanmayplywood.com.conf:1)  
> \*:443 [tanmayplywood.com](http://tanmayplywood.com) (/etc/httpd/conf.d/ssl.conf:56)  
> ServerRoot: "/etc/httpd"  
> Main DocumentRoot: "/var/www/html"  
> Main ErrorLog: "/etc/httpd/logs/error\_log"  
> Mutex proxy-balancer-shm: using\_defaults  
> Mutex rewrite-map: using\_defaults  
> Mutex authdigest-client: using\_defaults  
> Mutex ssl-stapling: using\_defaults  
> Mutex proxy: using\_defaults  
> Mutex authn-socache: using\_defaults  
> Mutex ssl-cache: using\_defaults  
> Mutex default: dir="/run/httpd/" mechanism=default  
> Mutex mpm-accept: using\_defaults  
> Mutex authdigest-opaque: using\_defaults  
> PidFile: "/run/httpd/httpd.pid"  
> Define: \_RH\_HAS\_HTTPPROTOCOLOPTIONS  
> Define: DUMP\_VHOSTS  
> Define: DUMP\_RUN\_CFG  
> User: name="apache" id=48  
> Group: name="apache" id=48

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [May 13, 2019, 8:27pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/5 "2019-05-13T20:27:39Z")

</div>

> [@yohaan](#):
>
> \*:80 [tanmayplywood.com](http://tanmayplywood.com) (/etc/httpd/conf.d/le-redirect-tanmayplywood.com.conf:1)  
> \*:443 [tanmayplywood.com](http://tanmayplywood.com) (/etc/httpd/conf.d/ssl.conf:56)

Looks like you don't have a ServerAlias.

```nohighlight
ServerName tanmayplywood.com
ServerAlias www.tanmayplywood.com

```

Add the alias to both vHosts.

Then change the SSLCertificateFile + key line to your other certificate:

```nohighlight
Certificate Path: /etc/letsencrypt/live/www.tanmayplywood.com/fullchain.pem
Private Key Path: /etc/letsencrypt/live/www.tanmayplywood.com/privkey.pem

```

and restart your server.

---

<div class="post-metadata">

**Author:** ![yohaan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/yohaan/32/31823_2.png) [@yohaan](https://community.letsencrypt.org/u/yohaan)\
**Post date:** [May 13, 2019, 8:30pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/6 "2019-05-13T20:30:07Z")

</div>

I am a newbie 😛

can you guide me how do i “add the alias to both vhost” and the following task.  
you can provide me any tutorial link or something.

Thanks

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [May 13, 2019, 8:38pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/7 "2019-05-13T20:38:33Z")

</div>

> [@JuergenAuer](#):
>
> /etc/httpd/conf.d/ssl.conf

That's one of your configuration file, the SSL version.

Open it and add / change the lines. Save it and restart your server.

---

<div class="post-metadata">

**Author:** ![yohaan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/yohaan/32/31823_2.png) [@yohaan](https://community.letsencrypt.org/u/yohaan)\
**Post date:** [May 13, 2019, 8:58pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/8 "2019-05-13T20:58:58Z")

</div>

You are awesome..!!! Thanks a ton. IT WORKED 🤩🤩🤩  
i love that you replied within few mins and i was in this problem from weeks.

I would like to know what did i do wrong while using certbot .  
What should i do.

This below mentioned way i installed SSL .

> yum -y install yum-utils

> sudo yum install certbot python2-certbot-apache

> In cpanel change webserver to “ngnix & apache” . and back to “apache only”

> This will make the root folder from usr/local/apache/htdocs to var/www/html because previous folder is not accesible by cerbot or freessl to verify the server

> sudo certbot certonly --webroot -w /var/www/html -d [www.tanmayplywood.com](http://www.tanmayplywood.com) -d [tanmayplywood.com](http://tanmayplywood.com)

> Sudo certbot

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 13, 2019, 12:10pm UTC](https://community.letsencrypt.org/t/ssl-not-working-on-www/93496/10 "2019-06-13T12:10:05Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
