安装在子域名的单域名SSL证书异常显示于其他子域名的问题
Alright, let's break down why you're seeing that certificate error and how to fix it step by step.
What's Causing the Issue?
- First off, your RapidSSL single-domain certificate is only valid for sub1.domain.ltd—it doesn't cover any other subdomains like sub2.domain.ltd. That's a core limitation of single-domain SSL certificates; they're locked to one specific hostname.
- Since all your domains share a single IP address, when a browser tries to connect to
sub2.domain.ltdover HTTPS, Apache is likely serving up the default SSL certificate (which is sub1's) because it doesn't have a specific SSL config for sub2. Browsers flag this immediately because the certificate's common name doesn't match the requested domain.
Fixes to Try
Option 1: Switch to a Wildcard SSL Certificate
If you need SSL coverage for all subdomains under domain.ltd, the cleanest solution is to replace your single-domain cert with a wildcard SSL certificate (e.g., *.domain.ltd). This one certificate will work for sub1.domain.ltd, sub2.domain.ltd, and any future subdomains you add.
Option 2: Install a Separate SSL Certificate for sub2.domain.ltd
If you prefer sticking with single-domain certs, you can purchase and install a dedicated certificate for sub2.domain.ltd, then configure Apache (via ISPConfig or manually) to use it for that subdomain:
- Grab the SSL certificate files (certificate, private key, and CA chain) for
sub2.domain.ltdfrom RapidSSL. - In ISPConfig 3.1, navigate to the site settings for
sub2.domain.ltd, enable SSL, and upload the new certificate files. If you're configuring manually, create an Apache SSL virtual host config like this:
<VirtualHost *:443> ServerName sub2.domain.ltd DocumentRoot /var/www/sub2.domain.ltd/web SSLEngine on SSLCertificateFile /path/to/your/sub2-cert.crt SSLCertificateKeyFile /path/to/your/sub2-private.key SSLCertificateChainFile /path/to/your/sub2-chain.crt # Add your usual logging, PHP, and security directives here </VirtualHost>
- Enable the site and restart Apache to apply changes:
a2ensite sub2.domain.ltd-ssl.conf systemctl restart apache2
Option 3: Tweak Apache's Default SSL Virtual Host (Temporary Fix)
If you need a quick band-aid while getting a new certificate, you can set Apache's default SSL host to a domain that doesn't get much traffic, or use a self-signed cert for the default. This won't fix the error for sub2, but it will stop Apache from serving sub1's cert to sub2's visitors. Note: This is not a long-term solution—users will still get an SSL error for sub2, just a different one.
Quick Check for ISPConfig Users
Double-check your ISPConfig 3.1 settings: Make sure each subdomain's SSL configuration is assigned its own certificate (or the wildcard cert, if you go that route). It's easy to accidentally reuse the wrong cert across sites when they share an IP.
内容的提问来源于stack exchange,提问作者Sam fas

