You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Certbot跳过存储第二个子域名证书,执行命令后仅见api证书

Troubleshooting Missing Certbot Certificate for Second Subdomain

Hey there, let's work through why your second subdomain's certificate is missing and Certbot is skipping its generation. I've run into similar hiccups before, so here are the most practical fixes to try:

1. Check if both subdomains are grouped in one certificate folder

Certbot often bundles multiple subdomains from the same request into a single directory, named after the first domain you specified. For example, if you ran:

certbot certonly --webroot -w /var/www/html -d api.example.com -d app.example.com

The certificates for both api.example.com and app.example.com will live in /etc/letsencrypt/live/api.example.com/. To confirm, run this command to view all domains included in the certificate:

openssl x509 -in /etc/letsencrypt/live/api.example.com/cert.pem -text -noout | grep DNS:

You should see both subdomains listed here if they were successfully added.

2. List all existing Certbot certificates

Run this command to get a full overview of every certificate Certbot has generated:

certbot certificates

This will show you each certificate's status, covered domains, and storage path. If the second subdomain exists in any entry, you'll find its location right away.

3. Dig into Certbot logs for errors

If the certificate wasn't generated at all, the logs will tell you exactly why. Open the main log file to check recent activity:

tail -n 50 /var/log/letsencrypt/letsencrypt.log

Look for error lines related to your second subdomain—common issues include:

  • Failed DNS validation (the subdomain doesn't resolve correctly, or propagation isn't complete)
  • Incorrect webroot path (Certbot couldn't place the validation file in the right directory)
  • Firewall/SELinux blocking incoming validation requests on port 80/443

4. Re-attempt certificate generation for the missing subdomain

Fix the underlying issue first (e.g., correct DNS records, update webroot path, adjust firewall rules), then test with a dry run to avoid wasting certificate limits:

certbot certonly --webroot -w /path/to/second/subdomain/webroot -d app.example.com --dry-run

If the dry run succeeds, remove --dry-run to generate the actual certificate. If you want to combine it with the existing API certificate, use:

certbot certonly --webroot -w /var/www/html -d api.example.com -d app.example.com --force-renewal

This will renew the certificate and add the second subdomain if it's missing.

5. Check for duplicate valid certificates

Certbot might skip generating a new certificate if it detects an existing valid one for the same domain. Use the certbot certificates command to verify this—if so, you can either renew it with the missing subdomain or revoke the old (unused) certificate before reissuing.


内容的提问来源于stack exchange,提问作者Houman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:49:36