# SSL cert not working on main Discourse site

**URL:** https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745
**Category:** Support
**Created:** [October 29, 2020, 12:49pm UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745 "2020-10-29T12:49:39Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![Desray](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/desray/32/197950_2.png) [@Desray](https://meta.discourse.org/u/Desray)
#### Post date: [October 29, 2020, 12:42pm UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/1 "2020-10-29T12:42:57Z")

</div>

That’s odd. This is the first I saw this. But thanks for informing me. Try this link: [https://avdisco.com/](https://avdisco.com/) instead.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [October 29, 2020, 12:49pm UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/2 "2020-10-29T12:49:39Z")

</div>

Yup that works fine … looks like you either need to stop advertising the other link, or generate a certificate for it.

I did that on one of my sites, see: [Set up Let’s Encrypt with multiple domains / redirects](https://meta.discourse.org/t/setting-up-let-s-encrypt-with-multiple-domains/56685)

---

<div class="post-metadata">

### Author: ![justin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/justin/32/157614_2.png) [@justin](https://meta.discourse.org/u/justin)
#### Post date: [October 29, 2020, 3:37pm UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/3 "2020-10-29T15:37:20Z")

</div>

> [@merefield](#):
>
> Yup that works fine … looks like you either need to stop advertising the other link, or generate a certificate for it.

Or redirect `www` to the apex 😃 that might be simpler.

---

<div class="post-metadata">

### Author: ![JimPas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimpas/32/148179_2.png) [@JimPas](https://meta.discourse.org/u/JimPas)
#### Post date: [October 30, 2020, 6:43am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/5 "2020-10-30T06:43:06Z")

</div>

@Desray, You have 3 links in the html in your www version. Use your browser inspector. One is a Mozilla link and two are I3C links. Change them to https and that should do the trick.

---

<div class="post-metadata">

### Author: ![Desray](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/desray/32/197950_2.png) [@Desray](https://meta.discourse.org/u/Desray)
#### Post date: [October 30, 2020, 7:16am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/6 "2020-10-30T07:16:12Z")

</div>

Thanks Jim. Anyway, I already added “www” to as a ‘A’ record to my DNS manager. This should fix the problem. Can try [https://www.avdisco.com](https://www.avdisco.com) again.

BTW I’m using cloudflare DNS instead of my original domain hosting DNS manager for all my DNS needs. Furthermore it is also more secured and also faster.

---

<div class="post-metadata">

### Author: ![JimPas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimpas/32/148179_2.png) [@JimPas](https://meta.discourse.org/u/JimPas)
#### Post date: [October 30, 2020, 7:17am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/7 "2020-10-30T07:17:53Z")

</div>

Nope. Still insecure. You have to change those 3 links from http to https.

---

<div class="post-metadata">

### Author: ![Desray](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/desray/32/197950_2.png) [@Desray](https://meta.discourse.org/u/Desray)
#### Post date: [October 30, 2020, 7:18am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/8 "2020-10-30T07:18:46Z")

</div>

Hmmn any step by step guide? TIA.

---

<div class="post-metadata">

### Author: ![JimPas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimpas/32/148179_2.png) [@JimPas](https://meta.discourse.org/u/JimPas)
#### Post date: [October 30, 2020, 7:25am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/9 "2020-10-30T07:25:32Z")

</div>

I’ll PM you in a couple of minutes and we can take this to [community.letsencrypt.org](http://community.letsencrypt.org). There’s two guys on there right now who can guide you through it quickly. One other thing… you have TlS 1.0 & 1.0 enabled. Those encryption are outdated and should be disabled also.  
This is off-topic so we can move the discussion in a few minutes.

---

<div class="post-metadata">

### Author: ![Desray](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/desray/32/197950_2.png) [@Desray](https://meta.discourse.org/u/Desray)
#### Post date: [October 30, 2020, 7:29am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/10 "2020-10-30T07:29:28Z")

</div>

Thanks. Just a normal user and not trained in this web security field.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [October 30, 2020, 7:46am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/11 "2020-10-30T07:46:23Z")

</div>

Use my link. It will ensure your certificate is renewed on rebuild. You can achieve this on the command line too (that’s what the script ultimately does) but that will not renew you automatically.

---

<div class="post-metadata">

### Author: ![JimPas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jimpas/32/148179_2.png) [@JimPas](https://meta.discourse.org/u/JimPas)
#### Post date: [October 30, 2020, 8:03am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/12 "2020-10-30T08:03:26Z")

</div>

I also found out he didn’t include his www in his certificate. I let two guys know he was showing up and filled them in on what I found. He’s getting help right now as we speak. 😃

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [October 30, 2020, 8:05am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/13 "2020-10-30T08:05:43Z")

</div>

I’m not convinced you’ve understood my point.

---

<div class="post-metadata">

### Author: ![Desray](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/desray/32/197950_2.png) [@Desray](https://meta.discourse.org/u/Desray)
#### Post date: [October 30, 2020, 8:07am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/14 "2020-10-30T08:07:53Z")

</div>

I’m confused. So what is the correct advice for me? LoL

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [October 30, 2020, 8:15am UTC](https://meta.discourse.org/t/ssl-cert-not-working-on-main-discourse-site/168745/15 "2020-10-30T08:15:51Z")

</div>

Use the how-to I linked. It’s specifically for Discourse. It will embed automatic renewal in your rebuild process so whenever you `./launcher rebuild app`. Sure you can use the command line and letsencrypt guys will be able to direct you to do that but then you will forget and it will expire again.
