After cleaning, here is what's left in /etc/dehydrated/certs/lurey.eu :
-rw------- 1 root root 1655 13 janv. 19:09 cert-1578938955.csr
-rw------- 1 root root 2216 13 janv. 19:09 cert-1578938955.pem
lrwxrwxrwx 1 root root 19 13 janv. 19:09 cert.csr -> cert-1578938955.csr
lrwxrwxrwx 1 root root 19 13 janv. 19:09 cert.pem -> cert-1578938955.pem
-rw------- 1 root root 1680 13 janv. 19:09 chain-1578938955.pem
lrwxrwxrwx 1 root root 20 13 janv. 19:09 chain.pem -> chain-1578938955.pem
-rw------- 1 root root 3896 13 janv. 19:09 fullchain-1578938955.pem
lrwxrwxrwx 1 root root 24 13 janv. 19:09 fullchain.pem -> fullchain-1578938955.pem
-rw------- 1 root root 3243 13 janv. 19:09 privkey-1578938955.pem
lrwxrwxrwx 1 root root 22 13 janv. 19:09 privkey.pem -> privkey-1578938955.pem
it's clearer ! (compared to your example, there is no < certificate.pfx > file...)
BUT...
grep pem /etc/httpd/conf/httpd.conf
gives no answer !
...looking for "SSLCertificate" in httpd.conf gives :
[root@sme-lurey lurey.eu]# grep SSLCertificate /etc/httpd/conf/httpd.conf
SSLCertificateFile /home/e-smith/ssl.crt/sme-lurey.lurey.eu.crt
SSLCertificateKeyFile /home/e-smith/ssl.key/sme-lurey.lurey.eu.key
..editing conf-file, there are 3 lines :
# modSSL{CertificateChainFile} not set
SSLCertificateFile /home/e-smith/ssl.crt/sme-lurey.lurey.eu.crt
SSLCertificateKeyFile /home/e-smith/ssl.key/sme-lurey.lurey.eu.key
... tried to replace with :
SSLCertificateChainFile /etc/dehydrated/certs/lurey.eu/chain.pem
SSLCertificateFile /etc/dehydrated/certs/lurey.eu/cert.pem
SSLCertificateKeyFile /etc/dehydrated/certs/lurey.eu/privkey.pem
...restart httpd, and...
YES ! the LE "fake-certificat" (test-mode) is displayed for all my domains and subdomains !
I think, I found out at least wher "my" error is...
but this conf-file is made of templates.
# expand-template /etc/httpd/conf/httpd.conf
# /etc/rc7.d/S*httpd-e-smith restart
...and I lose my certificate again
"my" error is in "SSL Global Context Configuration" section, I think the 3 original lines comes from the two following templates
(in /etc/e-smith/templates/etc/httpd/conf/httpd.conf )
35SSL10SSLCertificateChainFile
35SSL10SSLCertificateFile
Is there a template (? custom) missing in my dehydrated/letsencrypt installation ?
I am not able to go further, nor to know, without the help of those who know the principles of this installation, if the error comes from my manipulations or from the installation script...