# Valid certificate :: Browser says : site not valid

**URL:** <https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765>\
**Category:** Help\
**Created:** [January 27, 2021, 9:04am UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765 "2021-01-27T09:04:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bolshii](https://avatars.discourse-cdn.com/v4/letter/b/439d5e/32.png) [@bolshii](https://community.letsencrypt.org/u/bolshii)\
**Post date:** [January 27, 2021, 9:04am UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/1 "2021-01-27T09:04:37Z")

</div>

Hi.  
today I renewed the certificate of my domain.

Everything worked fine. The certificate is valid until 27.04.2021

But if I click on the lock icoon in the URL on Firefox it says: 'connection is not secure'.

My domain is: [https://ingo-preuss.de/](https://ingo-preuss.de/)

I ran this command:

> > sudo certbot --apache

It produced this output:

> > Added an HTTP-\>HTTPS rewrite in addition to other RewriteRules; you may wish to check for overall consistency.

My web server is (include version):

> > Server version: Apache/2.4.46 (Ubuntu)

The operating system my web server runs on is (include version):

> > Ubuntu 16.04.7 LTS

greetings, Ingo

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [January 27, 2021, 9:23am UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/2 "2021-01-27T09:23:07Z")

</div>

Hi @bolshii

> [@bolshii](#):
>
> But if I click on the lock icoon in the URL on Firefox it says: 'connection is not secure'.
> 
> My domain is: [https://ingo-preuss.de/](https://ingo-preuss.de/)

please click a second time and read the additional explantations.

"Parts of this website" doesn't mean "the certificate of this website".

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 27, 2021, 6:22pm UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/3 "2021-01-27T18:22:52Z")

</div>

@JuergenAuer A whole different certificate is presented at the moment.

@bolshii I don't see a HTTP to HTTPS redirect for `ingo-preuss.de`. Also, the Apache returning your content says it is version 2.4.41. You claim it to be 2.4.46? Are you sure we're talking about the same webserver here?

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [January 27, 2021, 6:34pm UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/4 "2021-01-27T18:34:29Z")

</div>

> [@Osiris](#):
>
> @JuergenAuer A whole different certificate is presented at the moment.

Oh, that's really curious.

Checked the page - all is good - 27.1.2021, 08:15:57 - a new LE-certificate.

F5 refresh - browser warning.

`mcs247.de, www.mcs247.de`

The screenshot says "Max Scharnewsky" - [https://check-your-website.server-daten.de/?q=ingo-preuss.de#screenshots](https://check-your-website.server-daten.de/?q=ingo-preuss.de#screenshots)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 28, 2021, 2:10am UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/5 "2021-01-28T02:10:59Z")

</div>

@bolshii Ingo, Are you sure the name returns the correct IP?

How did you renew the cert?

I also noticed that at some point, after last July, the "www" was dropped from the cert.  
Even though the "www" still returns the same IP:

```nohighlight
Name: ingo-preuss.de
Address: 217.160.42.165

Name: www.ingo-preuss.de
Address: 217.160.42.165

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 1, 2021, 12:52am UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/6 "2021-02-01T00:52:31Z")

</div>

~ bump ~

The certificate was obtained but is hasn't been served correctly by your Apache server.  
See: [SSL Server Test: ingo-preuss.de (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=ingo-preuss.de)

Please show the output of:  
`apachectl -S`  
`curl -4 ifconfig.co`

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 3, 2021, 12:52am UTC](https://community.letsencrypt.org/t/valid-certificate-browser-says-site-not-valid/143765/7 "2021-03-03T00:52:48Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
