You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CentOS Apache的httpd.conf中用单IP配置多SSL通配符证书

Fixing the SSL Certificate Mismatch for admin1.app.com

Let's break down this SSL error and get it resolved—this is a classic certificate mismatch issue, and it's straightforward to fix once we target the root cause.

Why You're Seeing the Error

The error message spells it out clearly: your server is serving the *.app.fr wildcard certificate when someone tries to access admin1.app.com. Wildcard certificates only cover subdomains of their base domain—so *.app.fr works perfectly for admin.app.fr and other app.fr subdomains, but it’s completely invalid for app.com or any of its subdomains.

Step-by-Step Troubleshooting & Fixes

1. Confirm You Have a Valid Certificate for app.com

First, make sure you’ve obtained a wildcard SSL certificate for *.app.com (or a SAN certificate that explicitly includes admin1.app.com). If you only have a certificate for app.fr, you’ll need to request/generate one for app.com from your certificate authority (CA).

2. Check Your Web Server Configuration

Next, verify your web server (Nginx, Apache, etc.) is set to use the correct certificate for app.com subdomains. Here’s how to check for the two most common servers:

For Nginx:

Locate the server block handling admin1.app.com or *.app.com. It should point to your app.com wildcard certificate, not the app.fr one:

server {
    listen 443 ssl;
    server_name admin1.app.com *.app.com;

    # These paths must point to your *.app.com certificate files
    ssl_certificate /etc/ssl/certs/app_com_wildcard.crt;
    ssl_certificate_key /etc/ssl/private/app_com_wildcard.key;

    # Rest of your server configuration...
}
For Apache:

Find the <VirtualHost> block for admin1.app.com and confirm the SSL directives use the app.com certificate files:

<VirtualHost *:443>
    ServerName admin1.app.com
    ServerAlias *.app.com

    # Correct paths to your app.com certificate
    SSLCertificateFile /etc/ssl/certs/app_com_wildcard.crt
    SSLCertificateKeyFile /etc/ssl/private/app_com_wildcard.key

    # Rest of your virtual host configuration...
</VirtualHost>

3. Validate Your app.com Certificate

If you already have the *.app.com certificate, double-check it actually covers the subdomains you need. Run this terminal command to inspect the certificate details:

openssl x509 -in /path/to/your/app_com_wildcard.crt -text -noout

Look for the Subject Alternative Name section—you should see DNS:*.app.com listed here. If it’s missing, you’ll need to reissue the certificate with the correct wildcard entry.

4. Check CDN/Reverse Proxy Settings

If you’re using a CDN (like Cloudflare) or reverse proxy, ensure it’s configured to use the app.com certificate too. These services sometimes cache old SSL configurations, so you may need to refresh their settings or re-upload the correct certificate.

5. Clear Browser SSL Cache

Browsers often cache SSL certificate data. After fixing your server config, test admin1.app.com in incognito/private mode first—if that works, clear your regular browser’s SSL cache to ensure it picks up the new certificate.

Final Summary

The core issue is that each base domain (app.fr and app.com) needs its own valid wildcard/SAN certificate, and your server must serve the right certificate for each domain’s traffic. Once you align these pieces, the HTTPS error will disappear.

内容的提问来源于stack exchange,提问作者Keerthana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:08:02