Certbot跳过存储第二个子域名证书,执行命令后仅见api证书
Hey there, let's work through why your second subdomain's certificate is missing and Certbot is skipping its generation. I've run into similar hiccups before, so here are the most practical fixes to try:
1. Check if both subdomains are grouped in one certificate folder
Certbot often bundles multiple subdomains from the same request into a single directory, named after the first domain you specified. For example, if you ran:
certbot certonly --webroot -w /var/www/html -d api.example.com -d app.example.com
The certificates for both api.example.com and app.example.com will live in /etc/letsencrypt/live/api.example.com/. To confirm, run this command to view all domains included in the certificate:
openssl x509 -in /etc/letsencrypt/live/api.example.com/cert.pem -text -noout | grep DNS:
You should see both subdomains listed here if they were successfully added.
2. List all existing Certbot certificates
Run this command to get a full overview of every certificate Certbot has generated:
certbot certificates
This will show you each certificate's status, covered domains, and storage path. If the second subdomain exists in any entry, you'll find its location right away.
3. Dig into Certbot logs for errors
If the certificate wasn't generated at all, the logs will tell you exactly why. Open the main log file to check recent activity:
tail -n 50 /var/log/letsencrypt/letsencrypt.log
Look for error lines related to your second subdomain—common issues include:
- Failed DNS validation (the subdomain doesn't resolve correctly, or propagation isn't complete)
- Incorrect webroot path (Certbot couldn't place the validation file in the right directory)
- Firewall/SELinux blocking incoming validation requests on port 80/443
4. Re-attempt certificate generation for the missing subdomain
Fix the underlying issue first (e.g., correct DNS records, update webroot path, adjust firewall rules), then test with a dry run to avoid wasting certificate limits:
certbot certonly --webroot -w /path/to/second/subdomain/webroot -d app.example.com --dry-run
If the dry run succeeds, remove --dry-run to generate the actual certificate. If you want to combine it with the existing API certificate, use:
certbot certonly --webroot -w /var/www/html -d api.example.com -d app.example.com --force-renewal
This will renew the certificate and add the second subdomain if it's missing.
5. Check for duplicate valid certificates
Certbot might skip generating a new certificate if it detects an existing valid one for the same domain. Use the certbot certificates command to verify this—if so, you can either renew it with the missing subdomain or revoke the old (unused) certificate before reissuing.
内容的提问来源于stack exchange,提问作者Houman

