Unable to setup SSL correctly with VestaCP


Last few days I’ve been struggling to setup SSL for my new server.

I tried multiple things for generating the CSR:

A lot of info there! Without digging too deeply into it, could it be to do with the fact that the Universal SSL certificates only cover *.yourdomain.com, but not *. *.yourdomain.com.

i.e. it covers {REDACTED} but not {REDACTED} .

Even if you add that to the origin cert, as it appears you have done, it doesn’t add it to the Universal Certificate. You would need to buy a dedicated certificate for that.

That makes sense, however I can’t confirm this fact you state about Universal SSL certificates coverage.

From the Help:
Hosts: Hosts is the set of hostnames covered by the certificates in the certificate pack. For custom and Keyless certificate packs, the set of hostnames is determined by the hostnames present in the common name (CN) and subject alternative name (SAN) fields on the first certificate added to the pack.

Is this what you mean?


