It's amazing to have this integration with Let's Encrypt!

I discovered a bizaro issue, whereby say I have created the site www.domain.com. I then set an alias of domain.com to redirect to www.domain.com

During the Let's Encrypt authentication is always attempts to authenticate with domain.com and not www.domain.com. Therefore, it fails each time unless I remove the alias, recreate the certificate, and then add the alias.

Thoughts? This would appear to me to be a bug but I'm not certain where or how to fix this?

Comments

ShaneOnABike created an issue. See original summary.

colan’s picture

Status: Active » Postponed (maintainer needs more info)

If you add the alias before you enable HTTPS, does that help? This always worked for me. Otherwise, LE won't know about the alias when the cert is first generated.

I suppose we could be explicit about this in the docs.

shaneonabike’s picture

I can give that a shot. So to test this out I would need to disable the certs completely, add the alias, and then re-enable SSL.

The thing though is that this is still kind of a bug. I have had situation where people add aliases afterwards because they buy other domains or whatever and want to add. It's a big step to go through and disable and then re-enable.

I do know that with Let's Encrypt you can easily tag another domain onto the existing from the command-line. I wonder if there is a way to integrate this as well.

I'll test my bit and get back to you.

colan’s picture

I can give that a shot. So to test this out I would need to disable the certs completely, add the alias, and then re-enable SSL.

Not just disable, but actually delete them to force regeneration. I just wanted to see if you're running into the problem I think you're running into. ;)

If so, yes, the real solution here is to do the following after a site is edited: If aliases were changed, force certificate regeneration from LE. IIRC, we never implemented this. But let's verify that's the problem first.