Im now seeing this.... i tried to run it with sudo and then acme spit out a link and I went to the link and it said "dont do that".
[Sat Feb 13 01:27:18 UTC 2021] Changing owner/group of .well-known to root:root
[Sat Feb 13 01:27:18 UTC 2021] chown: changing ownership of ‘/usr/share/nginx/html/.well-known/acme-challenge/Y8pndb4_Ke4v6sfANxV_CP1QPzfoi_Eu5MpE96whgUM’: Operation not permitted
chown: changing ownership of ‘/usr/share/nginx/html/.well-known/acme-challenge/7zA3B4p3P6Unz7dZbKWKBQzJnWt5fxpGZhZpB1lvCIQ’: Operation not permitted
chown: changing ownership of ‘/usr/share/nginx/html/.well-known/acme-challenge/sB7PXIrlNqAKD7uS5PU5A7_cqbsNWbEDJP4kZxxpWQM’: Operation not permitted
chown: changing ownership of ‘/usr/share/nginx/html/.well-known/acme-challenge/BsOne8G2R6LvsgPHrfjTfvnMM5o2M9mUEt4ifeF5-LI’: Operation not permitted
chown: changing ownership of ‘/usr/share/nginx/html/.well-known/acme-challenge/9mQ3sdYsiIT4sVo0ETUxmypPogGrlgDCRnM3BULV18o’: Operation not permitted
chown: changing ownership of ‘/usr/share/nginx/html/.well-known/acme-challenge’: Operation not permitted
chown: changing ownership of ‘/usr/share/nginx/html/.well-known’: Operation not permitted
Well, I've always been of the opinion that it makes sense to run acme.sh as root. It needs to be able to reload your webserver after a certificate renewal, which is a privileged operation. Without root, you need to do a bunch of other things to make it work.
The wiki page describes how can you can escalate to root (sudo su and then run acme.sh) without breaking acme.sh. That's what I would do personally.
Well... the permission issues have gone away... but its still throwing the following. I dont see any other obvious bad things up stream in the log. And unfortunately its such a generic error.