Apache log: [warn] RSA server certificate CommonName (CN) `plesk' does NOT match server name!?

Refers to:

  • Plesk for Linux
  • Web Presence Builder for Linux

Created:

2016-11-16 13:21:05 UTC

Modified:

2017-02-24 10:29:26 UTC

3

Was this article helpful?


Have more questions?

Submit a request

Apache log: [warn] RSA server certificate CommonName (CN) `plesk' does NOT match server name!?

Symptoms

Apache error log ' /var/log/httpd/error_log ' contains the following warnings:

[Mon Sep 04 15:12:13 2006] [warn] RSA server certificate CommonName (CN) `plesk' does NOT match server name!?

Cause

This warning means that CN parameter of the certificate installed on one of domains does not match value of ' ServerName ' directive specified in the corresponding ' VirtualHost ' configuration. Additional information about SNI (Server Name Indication) could be obtained here .

Resolution

This warning can be safely ignored.

Alternatively, the certificate may be regenerated to make its subject match the domain it is aimed to secure.

In Plesk: /en/213402729
In PPA: /en/213920865

To obtain subjects of all installed certificates please use the following command:

 # for i in `ls /usr/local/psa/var/certificates/`; do echo -n $i": "; openssl x509 -in /usr/local/psa/var/certificates/$i -subject -noout; done

Also, the attached script can be downloaded to obtain subjects. It runs the same command as above. To use the script:

# cd ~
# wget http://kb.plesk.com/Attachments/kcs-15116/cert.tar
# tar -xvf cert.tar
# chmod +x cert.sh
# ./cert.sh

NOTE: In Plesk Automation it is needed to execute this command on the Management Node.

As a result, the script will give output like the following:

subject= /C=US/ST=Virginia/L=Herndon/O=Parallels/OU=Parallels Panel/CN=Parallels Panel/emailAddress=info@domain.tld
subject= /C=RU/ST=Oregon/L=Springfield/O=Customer1, Inc/CN=www.testlog.test/emailAddress=admin@example.com
Have more questions? Submit a request
Please sign in to leave a comment.