Expired certificates for custom domains are not being renewed
								
							
								
								
									
									How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!
									While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.
								 
								 
							 
						 
					 
						
							
								
							
							
								
Legacy Article								
You are viewing an article from our legacy "FastTrack"
publication program, made available for informational purposes. Articles
in this program were published without a requirement for independent
editing or verification and are provided"as is" without
guarantee. 
Before using any information from this article, independently verify its
suitability for your situation and project.							
 
						 
				 
				
						
  Note: please note that Liferay has renamed its Liferay Experience
  Could offerings to Liferay SaaS (formerly LXC) and
  Liferay PaaS (formerly LXC-SM).
Issue
- Liferay PaaS automatically renews the certificate when it is close to the expiration date, if there is some error in the renewing the browser alerts that there is an expired certificate when you are navigating through some of your Liferay PaaS custom domains.
 
 
Environment
- 
Liferay PaaS projects using autogenerated SSL certificates.
 
 
Resolution
- Check your load balancer IP in Liferay PaaS console > Services > WebServer > Custom domains
- Look for the custom domain that is not resolving the load balancer's IP, you can check it using different tools as for example this on-line page.
- Remove the custom domain that it is not resolving the load balancer's IP from the Liferay PaaS console > Services > WebServer > Custom domains. This action should unlock the certificate recreation. If this does not happen after some prudential time, contact with the Liferay Support service.
- In parallel, contact your DNS provider or your DNS administrator and ask for modifying the DNS to point to the right IP, once the DNS resolves the load balancer's IP you can configure again the custom domain in Liferay PaaS console > Services > WebServer > Custom domains. Note that the new certificate recreation can take one hour.
 
 
 
				
				
				
				
					
Did this article resolve your issue ?