# SSL Renewal renewed but not activate You may need to install an Intermediate/chain certificate to link it to a trusted root certificate

**URL:** <https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809>\
**Category:** Help\
**Created:** [November 20, 2019, 10:45am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809 "2019-11-20T10:45:29Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 10:45am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/1 "2019-11-20T10:45:29Z")

</div>

My domain is: [https://qa-ui.juvlon.in](https://qa-ui.juvlon.in)

I ran this command: ./letsencrypt-auto --force-renewal -nvv certonly --standalone -d qa-ui.juvlon.in -d qa-ui.juvlon.in

It produced this output:- Congratulations! Your certificate and chain have been saved at:  
/etc/letsencrypt/live/qa-ui.juvlon.in/fullchain.pem  
Your key file has been saved at:  
/etc/letsencrypt/live/qa-ui.juvlon.in/privkey.pem  
Your cert will expire on 2020-02-09. To obtain a new or tweaked  
version of this certificate in the future, simply run  
letsencrypt-auto again. To non-interactively renew _all_ of your  
certificates, run “letsencrypt-auto renew”

- If you like Certbot, please consider supporting our work by:

My web server is (include version): nginx

The operating system my web server runs on is (include version): linux

certificate not getting renewed showing that

The certificate is not trusted in all web browsers. You may need to install an Intermediate/chain certificate to link it to a trusted root certificate. [Learn more about this error](https://www.sslshopper.com/ssl-certificate-not-trusted-error.html). The fastest way to fix this problem is to contact your SSL provider.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 10:52am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/2 "2019-11-20T10:52:49Z")

</div>

You used `--certonly` - this doesn’t update the use of the cert [it only gets a cert].  
But you also used `--standalone` which means you had to stop the server to get the new cert [which you did - Congrats!] and then had to restart the server.  
Not sure why you had to use `--force-renewal` - probably an attempt to force the use of the new cert [but that is NOT what that parameter does]

So… how can you have a new cert and have restarted the server while still using an old cert?  
Let’s find out.  
Please show the following information:  
`ls -l /etc/letsencrypt/live/qa-ui.juvlon.in/`  
`ls -l /etc/letsencrypt/archive/qa-ui.juvlon.in/`  
`./letsencrypt-auto certificates`  
`./letsencrypt-auto version`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 10:54am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/3 "2019-11-20T10:54:36Z")

</div>

lrwxrwxrwx 1 root root 39 Nov 20 15:59 cert.pem -\> …/…/archive/qa-ui.juvlon.in/cert8.pem  
lrwxrwxrwx 1 root root 40 Nov 20 15:59 chain.pem -\> …/…/archive/qa-ui.juvlon.in/chain8.pem  
lrwxrwxrwx 1 root root 44 Nov 20 15:59 fullchain.pem -\> …/…/archive/qa-ui.juvlon.in/fullchain8.pem  
lrwxrwxrwx 1 root root 42 Nov 20 15:59 privkey.pem -\> …/…/archive/qa-ui.juvlon.in/privkey8.pem

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 10:55am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/4 "2019-11-20T10:55:20Z")

</div>

-rw-r–r-- 1 root root 1797 Feb 11 2016 cert1.pem  
-rw-r–r-- 1 root root 1911 Aug 8 11:47 cert2.pem  
-rw-r–r-- 1 root root 1911 Nov 11 12:30 cert3.pem  
-rw-r–r-- 1 root root 1911 Nov 11 13:58 cert4.pem  
-rw-r–r-- 1 root root 1911 Nov 11 15:03 cert5.pem  
-rw-r–r-- 1 root root 1911 Nov 11 15:04 cert6.pem  
-rw-r–r-- 1 root root 1911 Nov 11 15:46 cert7.pem  
-rw-r–r-- 1 root root 1915 Nov 20 15:59 cert8.pem  
-rw-r–r-- 1 root root 1675 Feb 11 2016 chain1.pem  
-rw-r–r-- 1 root root 1647 Aug 8 11:47 chain2.pem  
-rw-r–r-- 1 root root 1647 Nov 11 12:30 chain3.pem  
-rw-r–r-- 1 root root 1647 Nov 11 13:58 chain4.pem  
-rw-r–r-- 1 root root 1647 Nov 11 15:03 chain5.pem  
-rw-r–r-- 1 root root 1647 Nov 11 15:04 chain6.pem  
-rw-r–r-- 1 root root 1647 Nov 11 15:46 chain7.pem  
-rw-r–r-- 1 root root 1647 Nov 20 15:59 chain8.pem  
-rw-r–r-- 1 root root 3472 Feb 11 2016 fullchain1.pem  
-rw-r–r-- 1 root root 3558 Aug 8 11:47 fullchain2.pem  
-rw-r–r-- 1 root root 3558 Nov 11 12:30 fullchain3.pem  
-rw-r–r-- 1 root root 3558 Nov 11 13:58 fullchain4.pem  
-rw-r–r-- 1 root root 3558 Nov 11 15:03 fullchain5.pem  
-rw-r–r-- 1 root root 3558 Nov 11 15:04 fullchain6.pem  
-rw-r–r-- 1 root root 3558 Nov 11 15:46 fullchain7.pem  
-rw-r–r-- 1 root root 3562 Nov 20 15:59 fullchain8.pem  
-rw-r–r-- 1 root root 1704 Feb 11 2016 privkey1.pem  
-rw-r–r-- 1 root root 1704 Aug 8 11:47 privkey2.pem  
-rw-r–r-- 1 root root 1704 Nov 11 12:30 privkey3.pem  
-rw-r–r-- 1 root root 1708 Nov 11 13:58 privkey4.pem  
-rw-r–r-- 1 root root 1704 Nov 11 15:03 privkey5.pem  
-rw-r–r-- 1 root root 1708 Nov 11 15:04 privkey6.pem  
-rw-r–r-- 1 root root 1704 Nov 11 15:46 privkey7.pem  
-rw-r–r-- 1 root root 1704 Nov 20 15:59 privkey8.pem

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 10:55am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/5 "2019-11-20T10:55:51Z")

</div>

Also:  
`./letsencrypt-auto certificates`  
`./letsencrypt-auto --version`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 10:56am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/6 "2019-11-20T10:56:46Z")

</div>

Found the following certs:  
Certificate Name: qa-ui.juvlon.in-0001  
Domains: qa-ui.juvlon.in  
Expiry Date: 2016-05-29 17:34:00+00:00 (INVALID: EXPIRED)  
Certificate Path: /etc/letsencrypt/live/qa-ui.juvlon.in-0001/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/qa-ui.juvlon.in-0001/privkey.pem  
Certificate Name: qa-ui.juvlon.in  
Domains: qa-ui.juvlon.in  
Expiry Date: 2020-02-18 09:29:55+00:00 (VALID: 89 days)  
Certificate Path: /etc/letsencrypt/live/qa-ui.juvlon.in/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/qa-ui.juvlon.in/privkey.pem

* * *

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 10:58am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/7 "2019-11-20T10:58:08Z")

</div>

./letsencrypt-auto --version  
certbot 0.40.1

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 10:58am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/8 "2019-11-20T10:58:23Z")

</div>

Delete this cert:

> [@adityakamble](#):
>
> Certificate Name: qa-ui.juvlon.in-0001

`./letsencrypt-auto delete --cert-name qa-ui.juvlon.in-0001`

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [November 20, 2019, 10:58am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/9 "2019-11-20T10:58:30Z")

</div>

Well, at least you don’t need to renew and issue any **more** certificates. You have at least one, it’s just not being used for some reason.

This is odd:

[https://www.ssllabs.com/ssltest/analyze.html?d=qa-ui.juvlon.in&hideResults=on](https://www.ssllabs.com/ssltest/analyze.html?d=qa-ui.juvlon.in&hideResults=on)

SSL Labs sees multiple configurations when accessing your site. One with an expired certificate and missing certificate chain, and one with a valid certificate from September and a correctly configured chain.

Do you have multiple servers behind a load balancer or something?

What does “`ps aux | grep nginx`” show?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:01am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/10 "2019-11-20T11:01:05Z")

</div>

Also show:  
`grep -Ri ssl_cert /etc/nginx/`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:03am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/11 "2019-11-20T11:03:22Z")

</div>

If any files are found to be using this path:  
`/etc/letsencrypt/live/qa-ui.juvlon.in-0001/`  
replace that entry with the valid cert path:  
`/etc/letsencrypt/live/qa-ui.juvlon.in/`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:06am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/12 "2019-11-20T11:06:49Z")

</div>

/etc/nginx/snippets/snakeoil.conf:ssl\_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;  
/etc/nginx/snippets/snakeoil.conf:ssl\_certificate\_key /etc/ssl/private/ssl-cert-snakeoil.key;  
/etc/nginx/sites-enabled/qa-hsbcmf-dm.juvlon.in: # ssl\_certificate;  
/etc/nginx/sites-enabled/qa-hsbcmf-dm.juvlon.in: # ssl\_certificate\_key;  
/etc/nginx/sites-enabled/app7.e-juvlon.com: # ssl\_certificate;  
/etc/nginx/sites-enabled/app7.e-juvlon.com: # ssl\_certificate\_key;  
/etc/nginx/sites-enabled/qa-ui.juvlon.in: #ssl\_certificate /etc/nginx/ssl/qa-ui.juvlon.in/147195/server.crt;  
/etc/nginx/sites-enabled/qa-ui.juvlon.in: #ssl\_certificate\_key /etc/nginx/ssl/qa-ui.juvlon.in/147195/server.key;  
/etc/nginx/sites-enabled/qa-ui.juvlon.in: ssl\_certificate /etc/letsencrypt/archive/qa-ui.juvlon.in/cert2.pem;  
/etc/nginx/sites-enabled/qa-ui.juvlon.in: ssl\_certificate\_key /etc/letsencrypt/archive/qa-ui.juvlon.in/privkey2.pem;  
/etc/nginx/sites-available/qa-hsbcmf-dm.juvlon.in: # ssl\_certificate;  
/etc/nginx/sites-available/qa-hsbcmf-dm.juvlon.in: # ssl\_certificate\_key;  
/etc/nginx/sites-available/qa-ui.juvlon.in\_bkp\_1: ssl\_certificate /etc/nginx/ssl/qa-ui.juvlon.in/59536/server.crt;  
/etc/nginx/sites-available/qa-ui.juvlon.in\_bkp\_1: ssl\_certificate\_key /etc/nginx/ssl/qa-ui.juvlon.in/59536/server.key;  
/etc/nginx/sites-available/app7.e-juvlon.com: # ssl\_certificate;  
/etc/nginx/sites-available/app7.e-juvlon.com: # ssl\_certificate\_key;  
/etc/nginx/sites-available/qa-ui.juvlon.in: #ssl\_certificate /etc/nginx/ssl/qa-ui.juvlon.in/147195/server.crt;  
/etc/nginx/sites-available/qa-ui.juvlon.in: #ssl\_certificate\_key /etc/nginx/ssl/qa-ui.juvlon.in/147195/server.key;  
/etc/nginx/sites-available/qa-ui.juvlon.in: ssl\_certificate /etc/letsencrypt/archive/qa-ui.juvlon.in/cert2.pem;  
/etc/nginx/sites-available/qa-ui.juvlon.in: ssl\_certificate\_key /etc/letsencrypt/archive/qa-ui.juvlon.in/privkey2.pem;  
/etc/nginx/forge-conf/qa-ui.juvlon.in/before/ssl\_redirect.conf: ssl\_certificate /etc/nginx/ssl/qa-ui.juvlon.in/147195/server.crt;  
/etc/nginx/forge-conf/qa-ui.juvlon.in/before/ssl\_redirect.conf: ssl\_certificate\_key /etc/nginx/ssl/qa-ui.juvlon.in/147195/server.key;

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:08am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/13 "2019-11-20T11:08:01Z")

</div>

qa-ui.juvlon.in/ qa-ui.juvlon.in-0001/

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:09am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/15 "2019-11-20T11:09:37Z")

</div>

./letsencrypt-auto delete --cert-name qa-ui.juvlon.in-0001 i need to delete this certificate ??? from which location

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:10am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/16 "2019-11-20T11:10:59Z")

</div>

If any files are found to be using this path:  
`/etc/letsencrypt/live/qa-ui.juvlon.in-0001/`  
replace that entry with the valid cert path:  
`/etc/letsencrypt/live/qa-ui.juvlon.in/`

both certificate are available on this path `/etc/letsencrypt/live

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:11am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/17 "2019-11-20T11:11:35Z")

</div>

Edit file:  
`/etc/nginx/sites-enabled/qa-ui.juvlon.in`  
Replace:  
`ssl_certificate /etc/letsencrypt/archive/qa-ui.juvlon.in/cert2.pem;`  
`ssl_certificate_key /etc/letsencrypt/archive/qa-ui.juvlon.in/privkey2.pem;`  
with:  
`ssl_certificate /etc/letsencrypt/live/qa-ui.juvlon.in/fullchain.pem;`  
`ssl_certificate_key /etc/letsencrypt/live/qa-ui.juvlon.in/privkey.pem;`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:15am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/18 "2019-11-20T11:15:06Z")

</div>

> [@adityakamble](#):
>
> ./letsencrypt-auto delete --cert-name qa-ui.juvlon.in-0001

That command will delete it from ever being renewed again [the files will remain in the /archive/ folder].

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:26am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/19 "2019-11-20T11:26:35Z")

</div>

can i run below command

./letsencrypt-auto delete --cert-name qa-ui.juvlon.in-0001

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:28am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/20 "2019-11-20T11:28:14Z")

</div>

please help me and let me know step by step what is the process

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:28am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/21 "2019-11-20T11:28:54Z")

</div>

START HERE:

> [@rg305](#):
>
> Edit file:  
> `/etc/nginx/sites-enabled/qa-ui.juvlon.in`  
> Replace:  
> `ssl_certificate /etc/letsencrypt/archive/qa-ui.juvlon.in/cert2.pem;`  
> `ssl_certificate_key /etc/letsencrypt/archive/qa-ui.juvlon.in/privkey2.pem;`  
> with:  
> `ssl_certificate /etc/letsencrypt/live/qa-ui.juvlon.in/fullchain.pem;`  
> `ssl_certificate_key /etc/letsencrypt/live/qa-ui.juvlon.in/privkey.pem;`

[Next page](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809.md?page=2)
