# Acme: error: 400 :: urn:ietf:params:acme:error:connection :: Timeout

**URL:** <https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651>\
**Category:** Help\
**Created:** [February 24, 2022, 12:03pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651 "2022-02-24T12:03:23Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![FrankRidder](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/frankridder/32/58699_2.png) [@FrankRidder](https://community.letsencrypt.org/u/FrankRidder)\
**Post date:** [February 24, 2022, 12:03pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/1 "2022-02-24T12:03:23Z")

</div>

My domain is: [photos.frankridder.com](http://photos.frankridder.com)

I ran this command: sudo docker-compose up -d

It produced this output:  
time="2022-02-24T11:37:02Z" level=error msg="Unable to obtain ACME certificate for domains "[photos.frankridder.com](http://photos.frankridder.com)": unable to generate a certificate for the domains [[photos.frankridder.com](http://photos.frankridder.com)]: error: one or more domains had a problem:\n[[photos.frankridder.com](http://photos.frankridder.com)] acme: error: 400 :: urn:ietf:params:acme:error:connection :: Fetching [http://photos.frankridder.com/.well-known/acme-challenge/bOF8hG7aT-RsO2UZpOLzJRhUbJyChs5DGrcDOqFgd84:](http://photos.frankridder.com/.well-known/acme-challenge/bOF8hG7aT-RsO2UZpOLzJRhUbJyChs5DGrcDOqFgd84:) Error getting validation data\n" ACME CA="[https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)" routerName=whoami@docker rule="Host(`photos.frankridder.com`)" providerName=myresolver.acme

My web server is (include version):  
traefik and whoami as for this example:

> **[HTTP Challenge - Traefik](https://doc.traefik.io/traefik/user-guides/docker-compose/acme-http/)**
>
> Traefik Documentation

The operating system my web server runs on is (include version):  
Ubuntu server 20.04

My hosting provider, if applicable, is: Self-hosted

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): traefik2.6

I can reach my site but [Let's Debug](https://letsdebug.net/photos.frankridder.com/925455) shows letsencrypt can not. I am unsure why this is. For background, I'm trying to get a certificate for my photoprism server. Running the photoprism traefik example generated the same error so I tried to simplify by just running the traefik example.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 24, 2022, 12:10pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/2 "2022-02-24T12:10:47Z")

</div>

> [@FrankRidder](#):
>
> I can reach my site but [Let's Debug](https://letsdebug.net/photos.frankridder.com/925455) shows letsencrypt can not.

Neither can I.

Do you have some kind of firewall filtering, or did you forget to enable port forwarding on your router? Are your DNS records ok? (I mean, is your IPv4 address really `84.107.153.151` and your IPv6 `2001:1c04:3c22:cd00:e3c:5e87:2bd5:346a` -- this is really important: the ipv6 of your server is _different_ from the one of your router, and there is no port forwarding, just a firewall.)

---

<div class="post-metadata">

**Author:** ![FrankRidder](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/frankridder/32/58699_2.png) [@FrankRidder](https://community.letsencrypt.org/u/FrankRidder)\
**Post date:** [February 24, 2022, 12:53pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/3 "2022-02-24T12:53:43Z")

</div>

Thank you for the fast response.

I have changed the IPv6 address in the DNS record to the servers IPv6.  
I have ufw enabled the following ports are open:  
 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/1/9/19f110c7f40dc3fe697e3627836a44bf4b8434c4.png)

Could there be another firewall I'm missing?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 24, 2022, 12:55pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/4 "2022-02-24T12:55:42Z")

</div>

> [@FrankRidder](#):
>
> Could there be another firewall I'm missing?

The one on your router. (IPv4 also needs port forwarding)

---

<div class="post-metadata">

**Author:** ![FrankRidder](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/frankridder/32/58699_2.png) [@FrankRidder](https://community.letsencrypt.org/u/FrankRidder)\
**Post date:** [February 24, 2022, 1:09pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/5 "2022-02-24T13:09:18Z")

</div>

Forgot to mention, I have forwarded port 80, 443, 8080 and 25565 (For an mc server). Forwarding does work for the mc server. Since I'm using my ISP's router could it be that they block the ports even though they have been forwarded? However, 80 and 443 are only open for TCP could that be an issue?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 24, 2022, 1:13pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/6 "2022-02-24T13:13:45Z")

</div>

All of them? It could be.

I think it might be that your ISP changed your IP addresses. Double check your `A` record. (Let's Encrypt will use `AAAA` if it exists, so if it exists it needs to be working)

```nohighlight
# nmap -6 photos.frankridder.com -Pn
Starting Nmap 7.80 ( https://nmap.org ) at 2022-02-24 14:10 CET
Nmap scan report for photos.frankridder.com (2001:1c04:3c22:cd00:4216:7eff:feaa:b055)
Host is up.
Other addresses for photos.frankridder.com (not scanned): 84.107.153.151
rDNS record for 2001:1c04:3c22:cd00:4216:7eff:feaa:b055: 2001-1c04-3c22-cd00-4216-7eff-feaa-b055.cable.dynamic.v6.ziggo.nl
All 1000 scanned ports on photos.frankridder.com (2001:1c04:3c22:cd00:4216:7eff:feaa:b055) are filtered

Nmap done: 1 IP address (1 host up) scanned in 201.38 seconds

```

(Ignore it saying it's up, I told it to say it.)

---

<div class="post-metadata">

**Author:** ![FrankRidder](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/frankridder/32/58699_2.png) [@FrankRidder](https://community.letsencrypt.org/u/FrankRidder)\
**Post date:** [February 24, 2022, 1:27pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/7 "2022-02-24T13:27:10Z")

</div>

Is there a better way to check my IP than checking sites like [whatsmyip.org](http://whatsmyip.org). They all show my IPv4 address as `84.107.153.151`. I also found a firewall option in my router and completely turned it off for now.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 24, 2022, 1:29pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/8 "2022-02-24T13:29:28Z")

</div>

that's probably your correct ipv4.

> [@FrankRidder](#):
>
> I also found a firewall option in my router and completely turned it off for now.

Indeed, I can now see your services over ipv6:

```nohighlight
# nmap -6 photos.frankridder.com -Pn
Starting Nmap 7.80 ( https://nmap.org ) at 2022-02-24 14:27 CET
Nmap scan report for photos.frankridder.com (2001:1c04:3c22:cd00:4216:7eff:feaa:b055)
Host is up (0.062s latency).
Other addresses for photos.frankridder.com (not scanned): 84.107.153.151
rDNS record for 2001:1c04:3c22:cd00:4216:7eff:feaa:b055: 2001-1c04-3c22-cd00-4216-7eff-feaa-b055.cable.dynamic.v6.ziggo.nl
Not shown: 996 filtered ports
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
8080/tcp open http-proxy

Nmap done: 1 IP address (1 host up) scanned in 11.15 seconds

```

and ipv4:

```nohighlight
# nmap -4 photos.frankridder.com -Pn
Starting Nmap 7.80 ( https://nmap.org ) at 2022-02-24 14:28 CET
Nmap scan report for photos.frankridder.com (84.107.153.151)
Host is up (0.023s latency).
Other addresses for photos.frankridder.com (not scanned): 2001:1c04:3c22:cd00:4216:7eff:feaa:b055
rDNS record for 84.107.153.151: 84-107-153-151.cable.dynamic.v4.ziggo.nl
Not shown: 991 closed ports
PORT STATE SERVICE
22/tcp open ssh
53/tcp open domain
80/tcp filtered http
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
443/tcp open https
445/tcp filtered microsoft-ds
8080/tcp open http-proxy
8443/tcp open https-alt

Nmap done: 1 IP address (1 host up) scanned in 6.55 seconds

```

---

<div class="post-metadata">

**Author:** ![FrankRidder](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/frankridder/32/58699_2.png) [@FrankRidder](https://community.letsencrypt.org/u/FrankRidder)\
**Post date:** [February 24, 2022, 1:34pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/9 "2022-02-24T13:34:05Z")

</div>

I guess I just completely missed the firewall option. I'll ask the community page of my ISP if there is a way to enable the firewall but actually forward the ports. Thank you for the help. It now seems to be able to use HTTP challenge to generate a certificate.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 24, 2022, 1:36pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/10 "2022-02-24T13:36:35Z")

</div>

Remember that port forwarding only applies to IPv4, but firewall applies to _both_ IPv4 and IPv6.

With IPv4 doesn't really matter if your firewall is on or off, with IPv6 each device should have their own, if your router doesn't.

(But the firewall, I mean, it needs to be configurable. I have no hope it is, though)

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 24, 2022, 1:38pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/11 "2022-02-24T13:38:29Z")

</div>

> [@FrankRidder](#):
>
> It now seems to be able to use HTTP challenge to generate a certificate.

About this: you can absolutely get away with exposing port 80 on IPv6 only, if you need to validate only. (The redirect http-\>https will only work for IPv6 clients, if you set it up, but that's it.)

---

<div class="post-metadata">

**Author:** ![FrankRidder](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/frankridder/32/58699_2.png) [@FrankRidder](https://community.letsencrypt.org/u/FrankRidder)\
**Post date:** [February 24, 2022, 1:44pm UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/12 "2022-02-24T13:44:24Z")

</div>

> [@9peppe](#):
>
> (But the firewall, I mean, it needs to be configurable. I have no hope it is, though)

Seems like it isn't sadly. But I have re-enabled it for IPv4. Thank you for the tips as well. I will try to reduce the amount of open ports now that I have it working.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 25, 2022, 2:44am UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/13 "2022-02-25T02:44:11Z")

</div>

> [@FrankRidder](#):
>
> Is there a better way to check my IP

I like this

```nohighlight
curl -4 ifconfig.co
curl -6 ifconfig.co

```

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 27, 2022, 2:44am UTC](https://community.letsencrypt.org/t/acme-error-400-urnparamserror-connection-timeout/172651/14 "2022-03-27T02:44:35Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
