Issue
- Liferay PaaS automatically renews the certificate when it is close to the expiration date, if there is some error in the renewing the browser alerts that there is an expired certificate when you are navigating through some of your Liferay PaaS custom domains.
Environment
-
Liferay PaaS projects using autogenerated SSL certificates.
Resolution
- Check your load balancer IP in
Liferay PaaS console > Services > WebServer > Custom domains
- Look for the custom domain that is not resolving the load balancer's IP, you can check it using different tools as for example this on-line page.
- Remove the custom domain that it is not resolving the load balancer's IP from the
Liferay PaaS console > Services > WebServer > Custom domains
. This action should unlock the certificate recreation. If this does not happen after some prudential time, contact with the Liferay Support service. - In parallel, contact your DNS provider or your DNS administrator and ask for modifying the DNS to point to the right IP, once the DNS resolves the load balancer's IP you can configure again the custom domain in
Liferay PaaS console > Services > WebServer > Custom domains
. Note that the new certificate recreation can take one hour.
Additional Information
- For more information about how to use Custom Domains, see our documentation.
- Why was my custom domain rejected by Liferay PaaS?
- Liferay PaaS is working in to improve the errors notifying about the custom domains.