AEM: 502 error after SSL certificate update missing www domain

A production Adobe Experience Manager (AEM) site can return a 502 error when an updated SSL certificate does not include the www domain. Update the certificate to include all required domain variants to resolve the issue

Description description

Environment

Adobe Experience Manager (AEM), all versions.

Symptoms

  • A production website returns a 502 Bad Gateway error and is inaccessible after an SSL certificate update.
  • The issue occurs when accessing the affected domain in a browser.
  • Other domains on the same servers are unaffected.

Cause

A new SSL certificate was applied that does not include the www subdomain, resulting in a 502 Bad Gateway error when accessing the site through the www domain.

Resolution resolution

Follow these steps to resolve the issue:

  1. Check the newly applied SSL certificate to ensure it covers all required domain variants, including the root domain and any subdomains such as www.
  2. If the new certificate is missing required domains, temporarily reapply the previous certificate, if available, to restore site accessibility.
  3. Obtain and install a new SSL certificate that includes all necessary domain names, for example both example.com and www.example.com.
  4. Ensure the certificate is valid and not expired.
  5. After updating the certificate, verify that the site loads successfully over HTTPS for all intended domains.
  6. Monitor certificate expiration dates and plan renewals in advance to avoid service disruption.
recommendation-more-help
experience-cloud-kcs-help-kbarticles