x1x11x
April 2, 2019, 8:54pm
1
Hi,
i have following problem, iam using a lets encrypt certificate for my domain - but if i open up my page in all browsers it says either unknown issuer or untrusted issuer. i checked the cert on various pages like ssllabs.com and they all show no errors, but somehow this occurs
My domain is:https://kiseni.com
My web server is (include version):Microsoft-IIS/10.0
The operating system my web server runs on is (include version): Windows Server 2016 Datacenter
My hosting provider, if applicable, is: Contabo
I can login to a root shell on my machine (yes or no, or I don’t know): Yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel): Plesk Oynx
Exactly what certificate and error do you get?
Are you connecting to the right IP address? Maybe it’s set to an older IP in the hosts file, or older DNS records are cached?
1 Like
x1x11x
April 3, 2019, 3:28am
3
Hi!
I just checked the website in the different browsers, somehow it seems to work now, iam not getting any error anymore, seems like there was something cached.
Hi @x1x11x
your configuration is wrong, that's not a caching problem.
Your certificate has only one domain name ( https://check-your-website.server-daten.de/?q=kiseni.com ):
CN=kiseni.com (5145)
28.03.2019
26.06.2019
expires in 84 days kiseni.com - 1 entry
But you have a www dns entry, this isn't secure.
So if a user uses the www-version, it's wrong. Browsers cache these redirects, so it's not really possible to check that with a browser.
Create one certificate with both domain names, use that.
1 Like
x1x11x
April 3, 2019, 7:48am
5
Thanks for pointing this out to me!
I’ll do that!
Thank you!
1 Like
x1x11x
April 3, 2019, 8:48pm
6
I renewed the cert in plesk, this time with a www subdomain, but if i check the cert, it says again that the domain name is not matching the cert name - which is still issued for kiseni.com and not www.kiseni.com
Any idea how to fix this?
x1x11x:
but if i check the cert, it says again that the domain name is not matching the cert name - which is still issued for kiseni.com and not www.kiseni.com
Any idea how to fix this?
That's only your caching problem.
Rechecked your domain all is good ( https://check-your-website.server-daten.de/?q=kiseni.com ):
Your certificate is new.
CN=kiseni.com
03.04.2019
02.07.2019
expires in 90 days kiseni.com, www.kiseni.com - 2 entries
And both https connections are secure:
It's only your browser cache. You may modify your redirects, now, it's Grade E, B should be possible.
But both connections are good.
1 Like
x1x11x
April 4, 2019, 3:16am
8
Now i see!
Thank you very much for your help!
2 Likes
system
Closed
May 4, 2019, 3:16am
9
This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.