Late one night, a developer receives a frantic call from the operations team. On the production server, users are reporting that they canāt access the website due to a security warning: "SSL_ERROR_BAD_CERT_DOMAIN." This issue not only impacts user experience but also threatens the integrity of the service. Time is of the essence.
How Does SSL Certificate Validation Work?
When a user attempts to connect to a website over HTTPS, the browser initiates a handshake to establish a secure connection. The validation process follows these essential steps:
-
HTTPS Request Initiation: The browser sends an HTTPS request to the web server, specifying the domain in the request URL.
-
Certificate Presentation: The web server responds by presenting its SSL certificate, which includes the Common Name (CN) and optionally, Subject Alternative Names (SAN).
-
Domain Matching: The browser checks the CN or SAN of the certificate against the domain in the request URL. If they match, the process continues; if not, an error occurs.
-
Chain of Trust Verification: The browser verifies the certificateās authenticity by checking its signature against known Certificate Authorities (CAs).
-
Secure Connection Establishment: If all checks pass, a secure connection is established, allowing encrypted data transfer.
Given this flow, the "SSL_ERROR_BAD_CERT_DOMAIN" error indicates that thereās a misalignment between the domain users are accessing and the domain specified in the SSL certificate.
Failure Case Study: A Real Incident
Incident Overview
During a routine deployment on a Friday evening, the development team updated the server configuration for their web application hosted on Nginx. Initially, everything appeared to be functioning correctly, but as users began to access the site, they encountered the "SSL_ERROR_BAD_CERT_DOMAIN" error.
Symptoms
- Users reported that the website was unreachable.
- Browsers displayed the error message when trying to access www.example.com.
- The certificate was valid but associated with example.com instead of www.example.com.
Root Cause
The SSL certificate was issued for the domain example.com but not for the subdomain www.example.com. As a result, when users attempted to access the site via the subdomain, the browser couldn't validate the SSL certificate, leading to the error.
Resolution Steps
-
The team quickly identified the certificate mismatch using the command:
openssl s_client -connect www.example.com:443
This command revealed that the certificate only covered example.com.
-
They generated a new SSL certificate including both domains using Certbot:
sudo certbot --nginx -d example.com -d www.example.com
This provided the necessary coverage for both domains.
-
After reloading Nginx with sudo systemctl reload nginx, the secure connection was successfully established.
The entire resolution took approximately 30 minutes, ensuring users could access the site securely once again.
Step-by-Step Remediation Walkthrough
If you encounter the "SSL_ERROR_BAD_CERT_DOMAIN" error, follow these steps:
-
Check Current Certificate
Run the following command to check your SSL certificate:
openssl s_client -connect your_domain.com:443
Expected result: The certificate details, including CN and SAN, should display correctly.
-
Identify Domain Mismatch
Review the output for the CN and SAN sections. Ensure they match the domain you are trying to access.
Expected result: A match between the domain in your browser and the certificate details.
-
Generate a New Certificate
If there is a mismatch, generate a new SSL certificate with the necessary domains:
sudo certbot --nginx -d your_domain.com -d www.your_domain.com
Expected result: The certificate is issued successfully with both domains included.
-
Reload Nginx Configuration
After obtaining the new certificate, reload Nginx to apply the changes:
sudo systemctl reload nginx
Expected result: Nginx reloads without errors.
-
Test the New Configuration
Reconnect to your domain using openssl:
openssl s_client -connect your_domain.com:443
Expected result: The new certificate should display matching CN and SAN entries.
-
Clear Browser Cache
Clear your browser cache or use an incognito window to avoid cached certificate data.
Expected result: User can access the website without encountering any SSL errors.
-
Verify SSL Certificate with SarangAI
Use SarangAI's SSL checker to confirm the certificate installation:
Expected result: The SSL checker should indicate that the certificate is valid and covers the necessary domains.
Common Mistakes
-
Mismatched Domain Names
Wrong: Issuing a certificate for example.com when users access www.example.com.
Correct: Ensure the certificate covers all necessary subdomains.
-
Forgetting to Reload Nginx
Wrong: Generating a new certificate but not reloading the Nginx server.
Correct: Always reload or restart Nginx after changes.
-
Using Incorrect Certbot Commands
Wrong: Using certbot --nginx without specifying all domain names.
Correct: Always include all relevant domains during certificate generation.
-
Not Using Subject Alternative Names (SAN)
Wrong: Relying solely on the Common Name (CN) for subdomains.
Correct: Use SAN to include multiple domains and subdomains in a single certificate.
-
Ignoring Certificate Renewal
Wrong: Allowing SSL certificates to expire without renewal.
Correct: Schedule the certbot renew command for automatic renewal.
Key Takeaways
- "SSL_ERROR_BAD_CERT_DOMAIN" indicates a domain mismatch in the SSL certificate.
- Use
openssl to check your SSL certificate details.
- Include all necessary domains and subdomains when generating SSL certificates with Certbot.
- Regularly verify your SSL certificate using SarangAI's SSL chain checker.
Frequently Asked Questions
What causes the "SSL_ERROR_BAD_CERT_DOMAIN" error?
This error occurs when the domain specified in the URL does not align with the domain listed in the SSL certificate's CN or SAN fields.
How can I check my SSL certificate details?
You can use the command openssl x509 -in your_certificate.crt -text -noout to display details such as the CN and SAN fields directly from your certificate.
Can I use Let's Encrypt for multiple domains?
Yes, Let's Encrypt supports multiple domains and subdomains through Subject Alternative Names (SAN) in a single certificate.
What steps should I take if I still see the error after making changes?
If the issue persists, clear your browser cache or try an incognito window to ensure you are not viewing a cached version of the site.
How do I renew my Let's Encrypt certificate?
Use the command sudo certbot renew to renew your Let's Encrypt SSL certificates. Ensure your web server is reloaded afterward to apply changes.