Confirming this on another server: AlmaLinux 8.10, cwpsrv-1.24.0-2 installed
2026-07-28 03:37. Same failure, but it stayed latent until a reboot the next
morning — worth adding, because others may only hit this weeks from now.
Two findings:
1) hostname.crt is a dead artifact — hostname.bundle is canonical.
The only script that writes hostname.crt is /scripts/generate_hostname_ssl
(line 137), and that runs only on install or hostname change. The renewal
chain is:
/etc/cron.daily/cwp_acme.sh -> acme.sh -> /scripts/hostname_ssl_restart_services
and that works exclusively with hostname.bundle (deriving hostname.pem from it
for postfix/dovecot/pure-ftpd). So after any AutoSSL renewal, .key/.cert/.bundle
are fresh while .crt is stale — key/cert mismatch at the next cwpsrv start.
Note that CWP's own generate_hostname_ssl (lines 171-184) sets all four cwpsrv
confs to hostname.bundle, and conf.d/api.conf already ships that way. The RPM
templates contradict CWP's own script.
2) The failure is silent until reboot.
hostname_ssl_restart_services runs "service cwpsrv reload". With a broken config
the reload fails, the exit code is ignored, and the running master keeps serving
the old certificate from memory. On my server the cert renewed on 11 July and
the panel kept working until a kernel update rebooted the box on 29 July —
then ERR_CONNECTION_REFUSED, restart counter at 602.
On the workarounds circulating in the other thread: symlinking or copying
hostname.cert gives you the leaf only, without the intermediate chain. Browsers
often mask this by caching intermediates, but API clients and curl will fail.
Use the bundle instead:
cp -a /etc/pki/tls/certs/hostname.bundle /etc/pki/tls/certs/hostname.crt
Or point the confs at hostname.bundle directly:
sed -i 's#/etc/pki/tls/certs/hostname\.crt#/etc/pki/tls/certs/hostname.bundle#g' \
/usr/local/cwpsrv/conf/cwpsrv.conf \
/usr/local/cwpsrv/conf.d/{user-api,users,webmail}.conf
/usr/local/cwpsrv/bin/cwpsrv -t && systemctl reload cwpsrv
Always verify before starting:
openssl rsa -noout -modulus -in /etc/pki/tls/private/hostname.key | openssl md5
openssl x509 -noout -modulus -in /etc/pki/tls/certs/hostname.bundle | openssl md5
And a warning: do NOT run generate_hostname_ssl as a fix. It replaces a valid
Let's Encrypt hostname certificate with a CWP self-signed one and restarts
postfix, dovecot, cwpsrv, httpd, nginx and pure-ftpd in sequence.
Requests for CWP:
- Ship the cwpsrv conf templates pointing to hostname.bundle, matching
generate_hostname_ssl.
- Mark the conf files %config(noreplace), or at minimum write .rpmsave.
- Have hostname_ssl_restart_services check the exit code of "cwpsrv -t" and
log a failure, instead of leaving a reload that silently did nothing.