# SSL Renewal renewed but not activate You may need to install an Intermediate/chain certificate to link it to a trusted root certificate

**URL:** <https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809>\
**Category:** Help\
**Created:** [November 20, 2019, 10:45am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809 "2019-11-20T10:45:29Z")\
**Posts on this page:** 14\
**Page:** 2

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:30am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/22 "2019-11-20T11:30:33Z")

</div>

THEN:  
[restart/reload NGINX]  
`systemctl restart nginx`

LAST:  
[run this command]  
`/letsencrypt-auto delete --cert-name qa-ui.juvlon.in-0001`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:31am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/23 "2019-11-20T11:31:43Z")

</div>

but web site name is qa-ui.juvlon.in

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:32am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/24 "2019-11-20T11:32:27Z")

</div>

You asked for step by step instructions.  
I gave you step by step instructions.  
Please just follow the steps.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:37am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/25 "2019-11-20T11:37:29Z")

</div>

> [@adityakamble](#):
>
> Found the following certs:  
> **Certificate Name: qa-ui.juvlon.in-0001**  
> Domains: qa-ui.juvlon.in  
> Expiry Date: 2016-05-29 17:34:00+00:00 ( **INVALID: EXPIRED** )  
> Certificate Path: /etc/letsencrypt/live/qa-ui.juvlon.in-0001/fullchain.pem  
> Private Key Path: /etc/letsencrypt/live/qa-ui.juvlon.in-0001/privkey.pem  
> **Certificate Name: qa-ui.juvlon.in**  
> Domains: qa-ui.juvlon.in  
> Expiry Date: 2020-02-18 09:29:55+00:00 ( **VALID: 89 days** )  
> Certificate Path: /etc/letsencrypt/live/qa-ui.juvlon.in/fullchain.pem  
> Private Key Path: /etc/letsencrypt/live/qa-ui.juvlon.in/privkey.pem

You have two cert [in `letsencrypt-auto`]

1. Certificate Name: qa-ui.juvlon.in-0001
2. Certificate Name: qa-ui.juvlon.in

The first is expired and should be deleted.  
Use this command to delete it:  
`./letsencrypt-auto delete --cert-name qa-ui.juvlon.in-0001`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 11:48am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/26 "2019-11-20T11:48:38Z")

</div>

thanks it working

i just replace below line

`ssl_certificate /etc/letsencrypt/live/qa-ui.juvlon.in/fullchain.pem;`  
`ssl_certificate_key /etc/letsencrypt/live/qa-ui.juvlon.in/privkey.pem;`

and restart nginx

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 11:56am UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/27 "2019-11-20T11:56:02Z")

</div>

Two out of three (steps) ain’t bad.

But there are even more… steps.  
There is a cert being applied to the IP [the default vhost config] that also has the same name.  
But this cert, and the implemented use, makes NO sense to me…  
The only browsers that will ever see it, don’t support SNI.  
[they take the DNS IP of the name and just connect [https://IP.IP.IP.IP/](https://IP.IP.IP.IP/)]  
But that “site” returns a redirect to: [https://qa-ui.juvlon.in/](https://qa-ui.juvlon.in/)  
Which will only cause that broser [incapable of SNI] to get stuck in loop:

1. resolve name to IP
2. go to [https://IP.IP.IP.IP/](https://IP.IP.IP.IP/)
3. get redirected to [https://qa-ui.juvlon.in/](https://qa-ui.juvlon.in/)
4. resolve name to IP
5. go to [https://IP.IP.IP.IP/](https://IP.IP.IP.IP/)
6. get redirected to [https://qa-ui.juvlon.in/](https://qa-ui.juvlon.in/)  
….

That leaves anyone that has a newer browser [supporting SNI] and they go to [https://IP.IP.IP.IP/](https://IP.IP.IP.IP/)  
They are presented with the cert for `qa-ui.juvlon.in`  
But that cert doesn’t match the “name” they are trying to reach “IP.IP.IP.IP” and it fails to connect.

So… no one can use that cert.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 12:05pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/28 "2019-11-20T12:05:54Z")

</div>

You should delete the EXPIRED and unused cert.  
[I gave you that instruction like 4 times already]

You should review where/how the other cert is used.  
Try using:  
`nginx -T`  
or a reduced output with:  
`nginx -T | grep -Ei 'server_name|virtual|default|\*|80|listen|return|rewrite'`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 12:06pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/29 "2019-11-20T12:06:28Z")

</div>

i had deleted this certificate

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 12:07pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/30 "2019-11-20T12:07:26Z")

</div>

Good that is three out of three steps: DONE.  
Now to step four…  
[just like in life - when you think you’re done… you’re not]

You should review where/how the other cert is used.  
Try using:  
`nginx -T`  
or a reduced output with:  
`nginx -T | grep -Ei 'server_name|virtual|default|\*|80|listen|return|rewrite'`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 12:08pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/31 "2019-11-20T12:08:33Z")

</div>

nginx: the configuration file /etc/nginx/nginx.conf syntax is ok  
nginx: configuration file /etc/nginx/nginx.conf test is successful

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 12:09pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/32 "2019-11-20T12:09:14Z")

</div>

NOT:  
`nginx -t`

use:  
`nginx -T`

---

<div class="post-metadata">

**Author:** ![adityakamble](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@adityakamble](https://community.letsencrypt.org/u/adityakamble)\
**Post date:** [November 20, 2019, 12:10pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/33 "2019-11-20T12:10:05Z")

</div>

nginx -T | grep -Ei ----- same i had used got this output

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 20, 2019, 12:12pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/34 "2019-11-20T12:12:02Z")

</div>

hmm…  
maybe that version is too old for that command:  
`Server: nginx/1.9.10`

Try:  
`grep -ERi 'server_name|virtual|default|\*|80|listen|return|rewrite' /etc/nginx/`

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 20, 2019, 12:12pm UTC](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809/35 "2019-12-20T12:12:09Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.

[Previous page](https://community.letsencrypt.org/t/ssl-renewal-renewed-but-not-activate-you-may-need-to-install-an-intermediate-chain-certificate-to-link-it-to-a-trusted-root-certificate/106809.md?page=1)
