# Ghost SSL Problems

**URL:** <https://forum.ghost.org/t/ghost-ssl-problems/39374>\
**Category:** Installation\
**Created:** [June 22, 2023, 1:05pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374 "2023-06-22T13:05:49Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 1:05pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/1 "2023-06-22T13:05:49Z")

</div>

If you’re looking for some help, it’s important to provide as much context as possible so that people are able to assist you. Try to always mention:

- What’s your URL? [kisacabilgi.net](http://kisacabilgi.net)
- What version of Ghost are you using? 5.47.1
- What configuration? ubuntu 20
- What browser? chrome
- What errors or information do you see in the console?  
 ![fwee](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/3X/a/2/a2380087617a0db61c1856075f98ee4e7f259280.png)  
log:

```auto
Debug Information:
    OS: Ubuntu, v20.04.6 LTS
    Node Version: v16.20.0
    Ghost Version: 5.47.1
    Ghost-CLI Version: 1.24.0
    Environment: production
    Command: 'ghost install 5.47.1'
Message: Failed to restart Nginx.
Stack: Error: Failed to restart Nginx.
    at NginxExtension.restartNginx (/usr/lib/node_modules/ghost-cli/extensions/nginx/index.js:262:19)
    at runMicrotasks (<anonymous>)
    at processTicksAndRejections (node:internal/process/task_queues:96:5)

Original Error Message:
Message: Command failed: /bin/sh -c sudo -S -p '#node-sudo-passwd#' nginx -s reload
nginx: [emerg] cannot load certificate "/etc/letsencrypt/kisacabilgi.net/fullchain.cer": BIO_new_file() failed (SSL: error:02001002:system libra>

Stack: Error: Command failed: /bin/sh -c sudo -S -p '#node-sudo-passwd#' nginx -s reload
nginx: [emerg] cannot load certificate "/etc/letsencrypt/kisacabilgi.net/fullchain.cer": BIO_new_file() failed (SSL: error:02001002:system libra>

    at makeError (/usr/lib/node_modules/ghost-cli/node_modules/execa/index.js:174:9)
    at /usr/lib/node_modules/ghost-cli/node_modules/execa/index.js:278:16
    at runMicrotasks (<anonymous>)
    at processTicksAndRejections (node:internal/process/task_queues:96:5)
    at async NginxExtension.restartNginx (/usr/lib/node_modules/ghost-cli/extensions/nginx/index.js:260:13)

```

- What steps could someone else take to reproduce the issue you’re having?

---

<div class="post-metadata">

**Author:** ![Cathy\_Sarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/cathy_sarisky/32/25750_2.png) [@Cathy\_Sarisky](https://forum.ghost.org/u/Cathy_Sarisky)\
**Post date:** [June 22, 2023, 3:38pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/2 "2023-06-22T15:38:40Z")

</div>

You might try running `ghost setup ssl` again and post the output, please?

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 3:55pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/3 "2023-06-22T15:55:36Z")

</div>

![IMG_20230622_185503](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/3X/4/c/4c0d610bca9a4fc348c98482a3e371382247e1fe.jpeg)

---

<div class="post-metadata">

**Author:** ![Cathy\_Sarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/cathy_sarisky/32/25750_2.png) [@Cathy\_Sarisky](https://forum.ghost.org/u/Cathy_Sarisky)\
**Post date:** [June 22, 2023, 4:07pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/4 "2023-06-22T16:07:17Z")

</div>

> [@wleksion](#):
>
> `BIO_new_file() failed (SSL: error:02001002`

The error above is truncated, but can you check that you actually do have a certificate at /etc/letsencrypt/kisacabilgi.net/fullchain.cer? I think that’s a missing file error…?

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 4:11pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/5 "2023-06-22T16:11:48Z")

</div>

![IMG_20230622_190940](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/3X/6/c/6c23015ab243afedf94652fb8be2d099fb312a4c.jpeg)

These files exist

---

<div class="post-metadata">

**Author:** ![Cathy\_Sarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/cathy_sarisky/32/25750_2.png) [@Cathy\_Sarisky](https://forum.ghost.org/u/Cathy_Sarisky)\
**Post date:** [June 22, 2023, 4:42pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/6 "2023-06-22T16:42:56Z")

</div>

well, the folder exists, anyway - might want to go into it and look for the actual file.

But assuming it’s there, you need a more useful error message. Try starting nginx on the command line, maybe?

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 4:45pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/7 "2023-06-22T16:45:55Z")

</div>

![IMG_20230622_194536](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/3X/b/d/bd916e1f949464694c1c65bc237b2081d1674c7e.jpeg)

---

<div class="post-metadata">

**Author:** ![Cathy\_Sarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/cathy_sarisky/32/25750_2.png) [@Cathy\_Sarisky](https://forum.ghost.org/u/Cathy_Sarisky)\
**Post date:** [June 22, 2023, 5:04pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/8 "2023-06-22T17:04:44Z")

</div>

Oh, sorry, that wasn’t a command. Try `sudo nginx reload` – maybe, depending on how you installed it.

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 5:16pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/9 "2023-06-22T17:16:58Z")

</div>

![IMG_20230622_201632](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/3X/e/3/e3513f34a1eea158fda7b773d999dc0771354a78.jpeg)

---

<div class="post-metadata">

**Author:** ![Cathy\_Sarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/cathy_sarisky/32/25750_2.png) [@Cathy\_Sarisky](https://forum.ghost.org/u/Cathy_Sarisky)\
**Post date:** [June 22, 2023, 5:32pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/10 "2023-06-22T17:32:12Z")

</div>

It specifically told you what to do to see the problem details. Did you do that?

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 8:48pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/11 "2023-06-22T20:48:07Z")

</div>

I did this setup on 3 different VDS providers, I got the same error in all of them.

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 22, 2023, 8:48pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/12 "2023-06-22T20:48:43Z")

</div>

Could it be a problem on the ghost cli side?

---

<div class="post-metadata">

**Author:** ![wleksion](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/wleksion/32/24987_2.png) [@wleksion](https://forum.ghost.org/u/wleksion)\
**Post date:** [June 23, 2023, 5:44pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/13 "2023-06-23T17:44:53Z")

</div>

Let’s encrypt the rate limit for the second time, I’m about to go crazy now.

---

<div class="post-metadata">

**Author:** ![Theo](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/theo/32/2432_2.png) [@Theo](https://forum.ghost.org/u/Theo)\
**Post date:** [July 4, 2023, 3:48am UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/14 "2023-07-04T03:48:09Z")

</div>

Does this post help?

> [@Ghost new installation - CliError - Setting up SSL](https://forum.ghost.org/t/ghost-new-installation-clierror-setting-up-ssl/37847/5):
>
> Hey, In my case I’ve did: Check the certificates in folder: /etc/letsencrypt ls /etc/letsencrypt Certificate was generated as example.com\_ecc Then go to /etc/nginx/sites-available Find file for the site: example.com-ssl.conf Update the paths on lines starting with: ssl\_certificate by adding \_ecc: ssl\_certificate /etc/letsencrypt/example.com\_ecc/fullchain.cer; ssl\_certificate\_key /etc/letsencrypt/example.com\_ecc/vanthletic.com.key; This is working fine for me. Not sure if th…

It worked for me when I was setting up a new server and it crashed and burned after installing the Let’s Encrypt cert.

---

<div class="post-metadata">

**Author:** ![Russell\_Jones](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/russell_jones/32/25159_2.png) [@Russell\_Jones](https://forum.ghost.org/u/Russell_Jones)\
**Post date:** [July 4, 2023, 5:23pm UTC](https://forum.ghost.org/t/ghost-ssl-problems/39374/15 "2023-07-04T17:23:34Z")

</div>

I ran into the same issue and through my post - I wasn’t aware of the one Theo mentions - we were able to resolve the issue. Looks like the same problem caused by a recent difference in the way that a DigitalOcean 1 click install names the folders that include the SSL certs.

> [@Ghost Install Error - Failed Setting Up SSL: Failed to restart Nginx](https://forum.ghost.org/t/ghost-install-error-failed-setting-up-ssl-failed-to-restart-nginx/39482/7):
>
> So i’ve enabled development mode and checked the ports 80 and 443 are allowed. When I run ghost setup ssl I get SSL has already been set up, skipping information_source Setting up SSL [skipped]. I’ve tried stopping the server and running but it made no difference. I ran it as ghost setup --ssl based on something I saw when returning ghost ssl help, that seemed to work. All good for the naked (non www) domain. I then had the issue of www not redirecting always or having an SSL cert. I eventually read that Ghost…
