# Unable to communicate securely with peer: requested domain name does not match the server’s certificate

**URL:** <https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826>\
**Category:** Server\
**Created:** [February 12, 2018, 4:26am UTC](https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826 "2018-02-12T04:26:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![meghasl](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/meghasl/32/20259_2.png) [@meghasl](https://community.letsencrypt.org/u/meghasl)\
**Post date:** [February 12, 2018, 4:26am UTC](https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826/1 "2018-02-12T04:26:26Z")

</div>

Hello,

My VPS with CentOS 6.9 / Apache 2.2 hosts several websites with vhosts and I have installed Letsencrypt using Certbot for several of them in one go.

However the domain `https://www.hrmis.health.gov.lk` doesn’t seem to work and it gives  
"Your connection is not private" warning on Chrome and  
"Unable to communicate securely with peer: requested domain name does not match the server’s certificate. HTTP Strict Transport Security: false  
HTTP Public Key Pinning: false" on Firefox.

Remaining website certificates are working fine:  
`https://www.ecpas.health.gov.lk`

Any help to sort this out is greatly appreciated!

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [February 12, 2018, 7:28am UTC](https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826/2 "2018-02-12T07:28:31Z")

</div>

It looks like you have a self-signed certificate on that domain name. You should run Certbot again with `-d www.hrmis.health.gov.lk` to get a trusted certificate for that domain.

Do you have a VirtualHost directive in your config naming that host, or is it just the default VirtualHost? If so, that could explain why it was missed in the first round.

---

<div class="post-metadata">

**Author:** ![meghasl](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/meghasl/32/20259_2.png) [@meghasl](https://community.letsencrypt.org/u/meghasl)\
**Post date:** [February 12, 2018, 9:00am UTC](https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826/3 "2018-02-12T09:00:33Z")

</div>

Thank you for your reply.

There’s a VirtualHost directive for the domain and it appeared in the list of domains when I ran Certbot. I followed the instructions as for other domains listed above but only this particular domain caused the problem. The culprit must be the self-signed certificate you mentioned (which must have been left on the server when I tried openssl some time back).

I tried to run `-d www.hrmis.health.gov.lk` but it hit a rate limit possibly because I tried reinstalling certificates several times. I’ll wait till the limit expires and let you know the result.

Thanks again!

---

<div class="post-metadata">

**Author:** ![meghasl](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/meghasl/32/20259_2.png) [@meghasl](https://community.letsencrypt.org/u/meghasl)\
**Post date:** [February 12, 2018, 1:09pm UTC](https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826/4 "2018-02-12T13:09:09Z")

</div>

Dear Jacob,

I got it solved by editing the /etc/httpd/conf.d/ssl.conf file and replacing the paths of ‘SSLCertificateFile’, ‘SSLCertificateKeyFile’ and ‘SSLCertificateChainFile’ to the relevant Letsencrypt files and restarting apache.

Earlier they were set to the self-signed certificate you mentioned which caused this problem and now everything is fine!

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 14, 2018, 1:09pm UTC](https://community.letsencrypt.org/t/unable-to-communicate-securely-with-peer-requested-domain-name-does-not-match-the-server-s-certificate/52826/5 "2018-03-14T13:09:30Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
