What is CA SSL Certificate (root certificate forwarded by your certificate provider)

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is*:barlokmetal.com*

I ran this command:
sudo certbot certonly --manual --preferred-challenges=dns -d barlokmetal.com
It produced this output:
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/barlokmetal.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/barlokmetal.com/privkey.pem
This certificate expires on 2021-12-21.
These files will be updated when the certificate renews.

My web server is (include version):

The operating system my web server runs on is (include version):
linux - version not available

My hosting provider, if applicable, is:
ihs.com.tr
I can login to a root shell on my machine (yes or no, or I don't know):
no
I'm using a control panel to manage my site (no, or provide the name and version of the control panel):
CLOUD PHP A - 89847 limited controlpanel, I have entered TXT record while creating certificate at above command
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):
certbot 1.19.0

After the above command:

  • I received a private key file (I viewed with sudo cat /etc/letsencrypt/live/barlokmetal.com/privkey.pem and copied and pasted in "existing certificate section at hosting panel"
  • I received 3 SSL sertificate when I cat /etc/letsencrypt/live/barlokmetal.com/fullchain.pem file and used first ----BEGIN CERTIFICATE----- -----END CERTIFICATE--- between
  • At the buttom asking CA SSL Certificate (root certificate forwarded by your certificate provider), I tried some options at the page Chain of Trust - Let's Encrypt but no luck.
    How can I retrive this provider certificate
3 Likes

Welcome to the Let's Encrypt Community, Hakan :slightly_smiling_face:

The three certificates (one leaf and two intermediate certificates) in fullchain.pem are:

The corresponding root certificate is:

3 Likes

Hello @griffin , Thank you very much for your answer. But I am not able to fix the problem yet. Still getting error message from my hosting. I will try more.
Note: I am using only first ----BEGIN CERTIFICATE----- -----END CERTIFICATE--- block. I tried all permutations w/out luck. And your supported link for of [DST Root CA X3 signed]

Still no luck. I keep trying. In case of news I will immediately inform here.

3 Likes

In order to use that root certificate, you need to use all four certificates.

Try these combinations:

  • Put all three certificates from fullchain.pem in the certificate box and leave the CA SSL Certificate (root certificate forwarded by your certificate provider) blank
  • Put the first certificate from fullchain.pem in the certificate box and the last two certificates from fullchain.pem in the CA SSL Certificate (root certificate forwarded by your certificate provider) box
3 Likes

Thanks @griffin , I tried both

  • first choice gives error : Sertificate is invalid.
  • Second choice gives: ERROR : Error Occurred While Creating Certificate!

At the both choice I entered private key at top

2 Likes

Pay very close attention to the header and footer lines of the private key you are pasting.

They probably look like this:

-----BEGIN PRIVATE KEY-----
-----END PRIVATE KEY-----

Modify them to look like this:

-----BEGIN RSA PRIVATE KEY-----
-----END RSA PRIVATE KEY-----
3 Likes

If that step fails, combine that step with using this as your CA SSL Certificate:

https://letsencrypt.org/certs/lets-encrypt-r3-cross-signed.pem

2 Likes

Hello @griffin, Thank you very much for your kind effort but when I tried both like:

  • I have changed private key header as you mentioned.
  • At : SSL Certifacate: I used first blok of certificate.
  • At CA SSL Certificate: I used both you sent.
    also I tried SSL Certifiacate section I tried first blok and all block. But not solved yet.
2 Likes

Please paste the certificate you are using here (just the first one). Do not paste the private key!

1 Like

-----BEGIN CERTIFICATE-----
MIIFIzCCBAugAwIBAgISBMdiFfQZWR+d/q6q2SqzblfCMA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yMTA5MjIwODA5MTNaFw0yMTEyMjEwODA5MTJaMBoxGDAWBgNVBAMT
D2Jhcmxva21ldGFsLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
AKB6pyflolV03s4PChSRmzsW5FUq/rgoQsh9LURRfWQh7X3H+OKQka8id4rF/WUV
R7cJFxQGpJU9JSIWvO/MBTTjpWuPsY1ojv8UaSH9d0iXMD6Ik/m2r/Js+nvWDWQr
VQdi4xZG0PsyvHqRHcGi2ySD+vyCVkx//A1W3agoATIWC6XxfZEmKBIx6mF+0zI4
TQZ7LoBHR+DgSvXj+RiiW8ri+HWn5ojghSvRhwOpcQWnn2hbuftOimnm5x6/76SG
7+fzMSiq3tLmC3XAKI9Bl6l4JFjDb77B69cs6TyJILPCjAH8TcXJbCHnYVxwq6MC
KPXbfbERF0ry3ChS38nV30MCAwEAAaOCAkkwggJFMA4GA1UdDwEB/wQEAwIFoDAd
BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNV
HQ4EFgQUWm4pGZ+FavnaUbHU/qa9Q+IjpMwwHwYDVR0jBBgwFoAUFC6zF7dYVsuu
UAlA5h+vnYsUwsYwVQYIKwYBBQUHAQEESTBHMCEGCCsGAQUFBzABhhVodHRwOi8v
cjMuby5sZW5jci5vcmcwIgYIKwYBBQUHMAKGFmh0dHA6Ly9yMy5pLmxlbmNyLm9y
Zy8wGgYDVR0RBBMwEYIPYmFybG9rbWV0YWwuY29tMEwGA1UdIARFMEMwCAYGZ4EM
AQIBMDcGCysGAQQBgt8TAQEBMCgwJgYIKwYBBQUHAgEWGmh0dHA6Ly9jcHMubGV0
c2VuY3J5cHQub3JnMIIBAwYKKwYBBAHWeQIEAgSB9ASB8QDvAHYAlCC8Ho7VjWyI
cx+CiyIsDdHaTV5sT5Q9YdtOL1hNosIAAAF8DMQj4gAABAMARzBFAiEAwO6TSvyB
XJZIZcCPv0dby18G/Vq4QVDJEEqE6c2sAdYCIE21cKr2ey+haGr1P0jcRc32+ygz
wJjMrpfgB7cpmGx6AHUAfT7y+I//iFVoJMLAyp5SiXkrxQ54CX8uapdomX4i8NcA
AAF8DMQkVwAABAMARjBEAiBMavcDhJgoN4oFwKGe8WNRFXrTH/hyyLHsfqrku5+m
nwIgMin36R2M/wlO918erLY5NlOoMbCgf6krWH/9AzUAmL4wDQYJKoZIhvcNAQEL
BQADggEBACHGAAfKHVVCSm+IiEoFXnR/fvEA84Br7/ZZ7BFmg+7qiJ/yWGq0u1ff
272csgK9jMfPgO//LoFmZJzhVeb6prj8v1XlF5q3To6E8TZ7SKKMoXUQX8lvUzQb
n6mZ1a0tkIdAklLHluWUj+S4AhD1FxG5rDenkVg5kPLi4S8zaYmPQs8yuat0aNxO
Owy6CX5PeYLdsKLu9KIpYx0OTU+eSbZ4vKS0S6TUwxt0DK6tnuKgMeVjGyMIu+Ly
B/s7f13HmO8XrXRNhxmu2326cZaTvNmc/Z5/eksJ/fGMAWzCqk/eqYmxAMoJxUG2
i4nLApEZ2lnQNkLI4R2phhkG8H8CduY=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw
WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg
RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP
R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx
sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm
NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg
Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG
/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC
AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB
Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA
FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw
AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw
Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB
gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W
PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl
ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz
CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm
lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4
avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2
yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O
yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids
hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+
HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv
MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX
nLRbwHOoq7hHwg==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/
MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB
AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC
ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL
wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D
LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK
4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5
bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y
sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ
Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4
FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc
SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql
PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND
TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw
SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1
c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx
+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB
ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu
b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E
U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu
MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC
5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW
9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG
WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O
he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC
Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5
-----END CERTIFICATE-----

2 Likes

this is the 3 of them. cat of fullchain.pem

2 Likes

If you provide email, I can share hosting website. I do not mind to share the password.

1 Like

You can just private message the credentials to me. Click on my username then click the Message button.

2 Likes

You actually need to create a certificate that covers both barlokmetal.com and www.barlokmetal.com.

sudo certbot certonly --manual --preferred-challenges=dns -d "barlokmetal.com,www.barlokmetal.com"

You will need to create two TXT records in this case.

3 Likes

Got it. I'm flagging your post to prevent leakage.

2 Likes

ok. I will

3 Likes

I ask to hosting company to add a new TXT record for new domain . (Waiting answer. Generally they reply 5-10 min)

2 Likes

I'm logged in. Just a minute. Go ahead with getting the new cert.

2 Likes

This issue is now being handled privately.

2 Likes

@cappittall, Make sure you change your password after this is all said and done :slight_smile:

4 Likes