我们用来自GoDaddy的新通配符SSL证书替换了一个旧的SSL证书。我们上周换掉了这个证书,并一直收到试图注册的客户关于以下错误的电话。

当我们在IE6,7,8,Chrome和Firefox中测试这个证书时,我们不知道到底发生了什么,而没有收到任何错误,但是我们知道,当我们继续接到电话时,存在一个问题。作为记录,我们确实在此框上安装了多个SSL证书,但是正在使用单独的IP地址来提供这些证书。
任何帮助或想法都将不胜感激。
谢谢,
发布于 2012-01-09 16:37:09
$ curl -Iv https://classes.stcharleshealthcare.org/
* About to connect() to classes.stcharleshealthcare.org port 443 (#0)
* Trying 67.59.90.121... connected
* Connected to classes.stcharleshealthcare.org (67.59.90.121) port 443 (#0)
* SSLv3, TLS handshake, Client hello (1):
* SSLv3, TLS handshake, Server hello (2):
* SSLv3, TLS handshake, CERT (11):
* SSLv3, TLS handshake, Server key exchange (12):
* SSLv3, TLS handshake, Server finished (14):
* SSLv3, TLS handshake, Client key exchange (16):
* SSLv3, TLS change cipher, Client hello (1):
* SSLv3, TLS handshake, Finished (20):
* SSLv3, TLS change cipher, Client hello (1):
* SSLv3, TLS handshake, Finished (20):
* SSL connection using DHE-RSA-AES256-SHA
* Server certificate:
* subject: serialNumber=ESKZZ-OSKRZAHAnZ8ssPXoULbrv1/Obw; C=US; ST=Oregon; L=Bend; O=St. Charles Medical Center; OU=GT14856843; CN=*.scmc.org
* start date: 2010-10-10 19:25:39 GMT
* expire date: 2012-01-13 10:20:49 GMT
* subjectAltName does not match classes.stcharleshealthcare.org
* Closing connection #0
* SSLv3, TLS alert, Client hello (1):
* SSL peer certificate or SSH remote key was not OK
curl: (51) SSL peer certificate or SSH remote key was not OK因此,用于classes.stcharleshealthcare.org的DNS将转到为*.scmc.org提供SSL证书的服务器。检查您的DNS和/或Apache中的虚拟主机定义。
发布于 2012-01-09 16:35:39
You attempted to reach classes.stcharleshealthcare.org, but instead you actually reached a server identifying itself as *.scmc.om您正在使用与您的域名不匹配的通配符证书。
https://serverfault.com/questions/348131
复制相似问题