Nginx SNI and Letsencrypt on FreeBSD; Wrong certificate?

NuLL3rr0r nginx-forum at
Sun Sep 4 10:50:30 UTC 2016

Tahnk you Maxim for the answer and sorry for my tardy response. I'm sure
that's not the case since I have a server block with redirect to www. Here
is the actual config:

server {
    server_tokens   off;

    listen          80;
    listen          [::]:80;

    location / {
        return 301 https://www.$server_name$request_uri;  # enforce https /

    # Error Pages
    include /path/to/snippets/error;

    # Anti-DDoS
    include /path/to/snippets/anti-ddos;

    # letsencrypt acme challenges
    include /path/to/snippets/letsencrypt-acme-challenge;

server {
    server_tokens   off;

    listen          80;
    listen          [::]:80;
    server_name     *;

    location / {
        return 301 https://$host$request_uri;  # enforce https

    # Error Pages
    include /path/to/snippets/error;

    # Anti-DDoS
    include /path/to/snippets/anti-ddos;

    # letsencrypt acme challenges
    include /path/to/snippets/letsencrypt-acme-challenge;

server {
    server_tokens   off;

    listen          443 ssl http2;
    listen          [::]:443 ssl http2;

    # Hardened SSL
    include                 /path/to/snippets/hardened-ssl;
    ssl_certificate         /path/to/certs/;
    ssl_certificate_key     /path/to/keys/;
    ssl_trusted_certificate /path/to/certs/;

    #error_log      /path/to/;
    #access_log     /path/to/;

    root            /path/to/;
    index           index.html;

    # Error Pages
    include         /path/to/snippets/error;

    # Anti-DDoS
    include         /path/to/snippets/anti-ddos;

    # letsencrypt acme challenges
    include /path/to/snippets/letsencrypt-acme-challenge;

    # Compression
    include         /path/to/snippets/compression;

    # Static Resource Caching
    include         /path/to/snippets/static-resource-caching;

Posted at Nginx Forum:,269263,269380#msg-269380

More information about the nginx mailing list