• We value your experience with Plesk during 2025
    Plesk strives to perform even better in 2026. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2025.
    Please take this short survey:

    https://survey.webpros.com/
  • On Plesk for Linux mod_status is disabled on upgrades to improve Apache security.
    This is a one-time operation that occurs during an upgrade. You can manually enable mod_status later if needed.

Issue Plesk Obsidian – Let’s Encrypt certificate does not include domain aliases in SAN

kicoes

New Pleskian
Server operating system version
Ubuntu 22.04.5 LTS
Plesk version and microupdate number
Plesk Obsidian Web Host Edition 18.0.74 Update #3
Hello,


I’m experiencing an issue in Plesk Obsidian Web Host Edition 18.0.74 Update #3 where domain aliases are not being included in the Let’s Encrypt certificate for the main domain.

Setup:
  • One main domain with hosting and valid Let’s Encrypt certificate.
  • Several domains configured as Domain Aliases pointing to that main domain.
  • DNS is correctly pointing to the server and HTTP works for all aliases.

Problem:
When issuing or reinstalling the Let’s Encrypt certificate, the wizard only includes the main domain (and www), and the aliases are not listed or added to the certificate SAN. As a result, accessing an alias over HTTPS serves the default server certificate and causes a certificate name mismatch.


I have already tried:
  • Reissuing the certificate.
  • Unassigning and reinstalling the certificate.
  • Recreating aliases.
  • Confirming DNS resolution is correct.
Has anyone encountered this in recent Plesk versions or found a reliable way to force aliases to be included in the certificate?

Any help or guidance would be appreciated.
 
Just to be sure, the aliases of the domain aren't listed when issuing an LE certificate, like in the example image below?

Screenshot 2026-02-02 131118.png
 
I am not sure what would cause this issue. There might be some errors/warning logged in the panel.log file. What you could try is to uninstall both the SSLit! and Let's encrypt extensions and re-installed them again. Beware that this will also delete any domain certificate configuration (but will not delete the certificates themselves).
 
Back
Top