# Two Questions: (a) Renewal (b) Invalid Intermediate

**URL:** <https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011>\
**Category:** Help\
**Created:** [October 1, 2020, 1:48pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011 "2020-10-01T13:48:09Z")\
**Posts on this page:** 7\
**Page:** 2

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2020, 7:09pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/21 "2020-10-01T19:09:43Z")

</div>

> [@Cheddar](#):
>
> certbot certonly

That won't actually install the cert(s).  
It ONLY gets the cert(s).

So this is expected:

> [@Cheddar](#):
>
> the domain fails to work with https

Start your troubleshooting with:  
`sudo apachectl -S`

---

<div class="post-metadata">

**Author:** ![Cheddar](https://avatars.discourse-cdn.com/v4/letter/c/ba9def/32.png) [@Cheddar](https://community.letsencrypt.org/u/Cheddar)\
**Post date:** [October 1, 2020, 7:25pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/22 "2020-10-01T19:25:09Z")

</div>

Thx for the info'. I'm actually attempting this on a different server to the previous stuff I was doing, which I'd kinda used as a trial-run, where I eventually got it all working okay, so I figured it should be fairly straightforward, with the same version of CentOS and the same version of Apache, but guess I'm missing something.

Yeah, I was only trying to get the certs, rather than install them, and I manually added the code-block to the vhost in the same manner as before. Also restarted the server, after I tried a couple of different domains, each time, but same problemo. Curious. I'm just trying to do one domain at a time for now, but seems to make little difference.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 1, 2020, 7:29pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/23 "2020-10-01T19:29:50Z")

</div>

> [@rg305](#):
>
> Start your troubleshooting with:  
> `sudo apachectl -S`

I bow to Rudy's (@rg305) excellent suggestion. Post the output of that command with three backticks on the lines above and below the output.

---

<div class="post-metadata">

**Author:** ![Cheddar](https://avatars.discourse-cdn.com/v4/letter/c/ba9def/32.png) [@Cheddar](https://community.letsencrypt.org/u/Cheddar)\
**Post date:** [October 1, 2020, 7:56pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/24 "2020-10-01T19:56:19Z")

</div>

Okay, well, please excuse the slight obfuscation of unrelated domains in the output, but the one I'm attempting this with is [shopviews.com](http://shopviews.com), the information of which I've kept as-is. Other than domain names everything is precisely as output.

Actually, I needed to do "`httpd -S`" on the CentOS server, as `apachectl -S` didn't produce anything:

```
$ sudo httpd -S
VirtualHost configuration:
10.0.0.5:* xyz.com (/etc/httpd/conf/httpd.conf:396)
10.0.0.5:443 xyz.com (/etc/httpd/conf/httpd.conf:428)
51.141.109.36:443 shopviews.com (/etc/httpd/conf/httpd.conf:824)
*:443 dgbvm.internal.cloudapp.net (/etc/httpd/conf.d/ssl.conf:56)
*:80 is a NameVirtualHost
         default server xxx.net (/etc/httpd/conf/httpd.conf:464)
         port 80 namevhost xxx.net (/etc/httpd/conf/httpd.conf:464)
                 alias www.xxx.net
                 alias yyy.com
                 alias www.yyy.com
                 alias dpp.com
                 alias www.dpp.com
         port 80 namevhost sbs.co.uk (/etc/httpd/conf/httpd.conf:509)
                 alias www.sbs.co.uk
         port 80 namevhost www.aaa.co.uk (/etc/httpd/conf/httpd.conf:544)
                 alias aaa.co.uk
         port 80 namevhost www.bbb.us (/etc/httpd/conf/httpd.conf:574)
                 alias bbb.us
         port 80 namevhost www.shopviews.com (/etc/httpd/conf/httpd.conf:796)
                 alias shopviews.com
ServerRoot: "/etc/httpd"
Main DocumentRoot: "/var/www/html"
Main ErrorLog: "/etc/httpd/logs/error_log"
Mutex proxy-balancer-shm: using_defaults
Mutex rewrite-map: using_defaults
Mutex authdigest-client: using_defaults
Mutex ssl-stapling: using_defaults
Mutex proxy: using_defaults
Mutex authn-socache: using_defaults
Mutex ssl-cache: using_defaults
Mutex default: dir="/run/httpd/" mechanism=default
Mutex mpm-accept: using_defaults
Mutex authdigest-opaque: using_defaults
PidFile: "/run/httpd/httpd.pid"
Define: _RH_HAS_HTTPPROTOCOLOPTIONS
Define: DUMP_VHOSTS
Define: DUMP_RUN_CFG
Define: MODSEC_2.5
Define: MODSEC_2.9
User: name="apache" id=48
Group: name="apache" id=48

```

I've tried using a vhost both as (a) and then as (b) below, but same result with each.

```
<VirtualHost 51.141.109.36:443>
ServerName shopviews.com
ServerAlias www.shopviews.com
...
</VirtualHost>

<VirtualHost *:443>
ServerName shopviews.com
ServerAlias www.shopviews.com
...
</VirtualHost>

```

FYI, note that the 10.0.0.5 IP address is mapped to a secondary public IP address, and is separate to all the others. That is, all the other domains listed share a completely different IP (as given). (and, as already noted, the domain with the GoDaddy cert, [xyz.com](http://xyz.com), works fine).

Thank you in advance for any help in the right direction.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 1, 2020, 11:45pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/25 "2020-10-01T23:45:33Z")

</div>

How is this working?  
`10.0.0.5:* xyz.com (/etc/httpd/conf/httpd.conf:396)`  
Are you really trying to bind `httpd` to every single port on that IP?

This will only bind if this address is actual on the local system:  
`51.141.109.36:443 shopviews.com (/etc/httpd/conf/httpd.conf:824)`  
Please show:  
`sudo ifconfig | grep -Ei 'add|inet'`

Please show the server block that contains: `/etc/httpd/conf/httpd.conf:796`

---

<div class="post-metadata">

**Author:** ![Cheddar](https://avatars.discourse-cdn.com/v4/letter/c/ba9def/32.png) [@Cheddar](https://community.letsencrypt.org/u/Cheddar)\
**Post date:** [October 2, 2020, 3:59pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/27 "2020-10-02T15:59:37Z")

</div>

Okay, got it working. Thx.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 1, 2020, 3:59pm UTC](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011/28 "2020-11-01T15:59:45Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.

[Previous page](https://community.letsencrypt.org/t/two-questions-a-renewal-b-invalid-intermediate/135011.md?page=1)
