# UntrustedRoot: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider

**URL:** <https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112>\
**Category:** Help\
**Created:** [January 6, 2021, 3:36pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112 "2021-01-06T15:36:26Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![olek](https://avatars.discourse-cdn.com/v4/letter/o/b2d939/32.png) [@olek](https://community.letsencrypt.org/u/olek)\
**Post date:** [January 6, 2021, 3:36pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/1 "2021-01-06T15:36:26Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:7oo8.icu

I ran this command:certbot --apache --noninteractive --agree-tos --register-unsafely-without-email --expand -d 7oo8.icu -d 7oo9.icu

It produced this output:Account registered.  
Requesting a certificate for 7oo8.icu and 7oo9.icu

* * *

Congratulations! You have successfully enabled [https://7oo8.icu](https://7oo8.icu) and  
[https://7oo9.icu](https://7oo9.icu)

* * *

IMPORTANT NOTES:

- Congratulations! Your certificate and chain have been saved at:  
/etc/letsencrypt/live/7oo8.icu/fullchain.pem  
Your key file has been saved at:  
/etc/letsencrypt/live/7oo8.icu/privkey.pem  
Your cert will expire on 2021-04-06. To obtain a new or tweaked  
version of this certificate in the future, simply run certbot again  
with the "certonly" option. To non-interactively renew _all_ of  
your certificates, run "certbot renew"

- If you like Certbot, please consider supporting our work by:

$Error:Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Plugins selected: Authenticator apache, Installer apache  
Starting new HTTPS connection (1): [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)  
Performing the following challenges:  
http-01 challenge for 7oo8.icu  
http-01 challenge for 7oo9.icu  
Waiting for verification...  
Cleaning up challenges  
Created an SSL vhost at /etc/httpd/sites-available/7oo8.icu-le-ssl.conf  
Deploying Certificate to VirtualHost /etc/httpd/sites-available/7oo8.icu-le-ssl.conf  
Enabling site /etc/httpd/sites-available/7oo8.icu-le-ssl.conf by adding Include to root configuration  
Created an SSL vhost at /etc/httpd/sites-available/7oo9.icu-le-ssl.conf  
Deploying Certificate to VirtualHost /etc/httpd/sites-available/7oo9.icu-le-ssl.conf  
Enabling site /etc/httpd/sites-available/7oo9.icu-le-ssl.conf by adding Include to root configuration  
Redirecting vhost in /etc/httpd/sites-enabled/7oo8.icu.conf to ssl vhost in /etc/httpd/sites-available/7oo8.icu-le-ssl.conf  
Redirecting vhost in /etc/httpd/sites-enabled/7oo9.icu.conf to ssl vhost in /etc/httpd/sites-available/7oo9.icu-le-ssl.conf

My web server is (include version):Server version: Apache/2.4.6 (CentOS)

The operating system my web server runs on is (include version): Operating System: CentOS Linux 7 (Core)  
Kernel: Linux 5.8.6-1.el7.elrepo.x86\_64

My hosting provider, if applicable, is:ServerPoint

I can login to a root shell on my machine (yes or no, or I don't know):yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):certbot 1.10.1

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [January 6, 2021, 4:54pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/2 "2021-01-06T16:54:55Z")

</div>

Hi @olek

> [@olek](#):
>
> I ran this command:certbot --apache --noninteractive --agree-tos --register-unsafely-without-email --expand -d 7oo8.icu -d 7oo9.icu

your second domain has the correct certificate with two domain names.

So certificate creation and installation of the second https vHost had worked.

What says

```nohighlight
apachectl -S
httpd -S

```

second row, if the first row doesn't work.

Looks like your vHost configuration is a little bit buggy.

---

<div class="post-metadata">

**Author:** ![olek](https://avatars.discourse-cdn.com/v4/letter/o/b2d939/32.png) [@olek](https://community.letsencrypt.org/u/olek)\
**Post date:** [January 6, 2021, 4:58pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/3 "2021-01-06T16:58:05Z")

</div>

Thanks Juergen 🙂  
here is the apachectl -S result:  
VirtualHost configuration:  
\*:80 is a NameVirtualHost  
default server www.7oo8.icu (/etc/httpd/sites-enabled/7oo8.icu.conf:1)  
port 80 namevhost www.7oo8.icu (/etc/httpd/sites-enabled/7oo8.icu.conf:1)  
alias 7oo8.icu  
port 80 namevhost www.7oo9.icu (/etc/httpd/sites-enabled/7oo9.icu.conf:1)  
alias 7oo9.icu  
\*:443 is a NameVirtualHost  
default server mail.7oo8.icu (/etc/httpd/conf.d/ssl.conf:56)  
port 443 namevhost mail.7oo8.icu (/etc/httpd/conf.d/ssl.conf:56)  
port 443 namevhost www.7oo8.icu (/etc/httpd/sites-available/7oo8.icu-le-ssl.conf:2)  
alias 7oo8.icu  
port 443 namevhost www.7oo9.icu (/etc/httpd/sites-available/7oo9.icu-le-ssl.conf:2)  
alias 7oo9.icu  
ServerRoot: "/etc/httpd"  
Main DocumentRoot: "/var/www/html"  
Main ErrorLog: "/etc/httpd/logs/error\_log"  
Mutex mpm-accept: using\_defaults  
Mutex authdigest-opaque: using\_defaults  
Mutex proxy-balancer-shm: using\_defaults  
Mutex rewrite-map: using\_defaults  
Mutex authdigest-client: using\_defaults  
Mutex ssl-stapling: using\_defaults  
Mutex proxy: using\_defaults  
Mutex authn-socache: using\_defaults  
Mutex ssl-cache: using\_defaults  
Mutex default: dir="/run/httpd/" mechanism=default  
PidFile: "/run/httpd/httpd.pid"  
Define: \_RH\_HAS\_HTTPPROTOCOLOPTIONS  
Define: DUMP\_VHOSTS  
Define: DUMP\_RUN\_CFG  
User: name="apache" id=48  
Group: name="apache" id=48

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [January 6, 2021, 5:06pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/4 "2021-01-06T17:06:29Z")

</div>

Most looks ok.

Compare

> [@olek](#):
>
> port 443 namevhost www.7oo8.icu (/etc/httpd/sites-available/7oo8.icu-le-ssl.conf:2)  
> alias 7oo8.icu  
> port 443 namevhost www.7oo9.icu (/etc/httpd/sites-available/7oo9.icu-le-ssl.conf:2)  
> alias 7oo9.icu

these two vHosts, the first may have the wrong certificate. Use the lines of the second.

PS: No, bad idea: Your certificate doesn't have the www domain names.

May be create two certificates, one per domain, every certificate with non-www and www.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 6, 2021, 5:06pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/5 "2021-01-06T17:06:49Z")

</div>

Can you show the contents of `/etc/httpd/sites-available/7oo8.icu-le-ssl.conf`? It's a little bit weird that certbot said it succesfully enabled it in that configuration file, but it doesn't seem to work?

Also, you didn't include the `www` subdomains in your certificate, but you do have `www` subdomains configured in Apache. If you're using the `-d` command line option, you need to explicitely add the `www` subdomains yourself.

---

<div class="post-metadata">

**Author:** ![olek](https://avatars.discourse-cdn.com/v4/letter/o/b2d939/32.png) [@olek](https://community.letsencrypt.org/u/olek)\
**Post date:** [January 6, 2021, 5:20pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/7 "2021-01-06T17:20:07Z")

</div>

Hey,

i dont need or use www dont know why i put it there...probably copied the config from somewhere....

here is the file content:

"  
\<VirtualHost \*:443\>  
ServerName www.7oo8.icu  
ServerAlias 7oo8.icu

SSLCertificateFile /etc/letsencrypt/live/7oo8.icu/cert.pem  
SSLCertificateKeyFile /etc/letsencrypt/live/7oo8.icu/privkey.pem  
Include /etc/letsencrypt/options-ssl-apache.conf  
SSLCertificateChainFile /etc/letsencrypt/live/7oo8.icu/chain.pem  
  
ProxyPass [http://55.195.102.23/](http://55.195.102.23/)  
ProxyPassReverse [http://55.195.102.23/](http://55.195.102.23/)  
  
\<Location "/frontend/assets/gallery"\>  
ProxyPass "!"  
  
\<Location "/frontend/assets/files"\>  
ProxyPass "!"  
  
\<Location "/frontend/assets/img"\>  
ProxyPass "!"  
  
  
  
"

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 6, 2021, 5:35pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/8 "2021-01-06T17:35:56Z")

</div>

Are the SSL commands (and most notably the paths) exactly the same as the `7oo9.icu-le-ssl.conf` file? It _looks_ like it should have to work.. Perhaps another Apache reload fixes it?

---

<div class="post-metadata">

**Author:** ![olek](https://avatars.discourse-cdn.com/v4/letter/o/b2d939/32.png) [@olek](https://community.letsencrypt.org/u/olek)\
**Post date:** [January 6, 2021, 5:49pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/9 "2021-01-06T17:49:42Z")

</div>

this solved it:

May be create two certificates, one per domain, every certificate with non-www and www.

Thanks again juergen 🙂

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 6, 2021, 5:51pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/10 "2021-01-06T17:51:43Z")

</div>

I'd rather call it a work-around. Your previous certificate should work fine, if Apache is properly configured and reloaded.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 6, 2021, 10:18pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/11 "2021-01-06T22:18:06Z")

</div>

The failure was the site uses apex and www.

> [@olek](#):
>
> port 443 namevhost www.7oo8.icu (/etc/httpd/sites-available/7oo8.icu-le-ssl.conf:2)  
> alias 7oo8.icu  
> port 443 namevhost www.7oo9.icu (/etc/httpd/sites-available/7oo9.icu-le-ssl.conf:2)  
> alias 7oo9.icu

While the cert was only for the apex:

> [@olek](#):
>
> I ran this command:certbot --apache --noninteractive --agree-tos --register-unsafely-without-email --expand -d 7oo8.icu -d 7oo9.icu

^^^ no www was included in the certs.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 5, 2021, 10:18pm UTC](https://community.letsencrypt.org/t/untrustedroot-a-certificate-chain-processed-but-terminated-in-a-root-certificate-which-is-not-trusted-by-the-trust-provider/142112/12 "2021-02-05T22:18:08Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
