It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Renewing an existing certificate for recordspreservation.org and 3 more domains
Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet.
Some challenges have failed.
My web server is (include version):
Apache
The operating system my web server runs on is (include version):
Debian 11
My hosting provider, if applicable, is:
Google Computing Platform (Virtual Machine)
The Certbot --apache authenticator that you chose uses the HTTP Challenge. You must satisfy a challenge for each domain to get a cert.
If those two domains are not managed by the same Apache as your apex and www domain that option won't work.
And, if those two domain (images and thumbnails) are not accessible from the public internet you won't be able to use any other option that uses the HTTP Challenge (or TLS-ALPN).
images is a bucket that doesn't have public permission, but I could make it temporarily available to the public to issue the certificate. thumbnails is always available to the public. I was able to add www.recordspreservation.org but the site doesn't load when I go tohttps://www.recordspreservation.org.
How do I redirect http to https if I didn't do that originally?
Thanks,
-Marcos
Your apex domain recordspreservation.org is not loading on HTTPS right now either. Looks like your port 443 is blocked perhaps by a firewall.
As for www redirecting, you'd have to review your Apache config VirtualHost configs. Check the VHost for port 80 that has a ServerName or ServerAlias for the www name. Sometimes people create multiple with the same name by accident and that can cause problems.
But are they managed by the same Apache server as your other 2 domain names? Because my test requests to those domains said the server was "UploadServer" and looks like a google service (not Apache).
I am new to this so I guess not -- if that's the case, can I have 2 certificates? How do I do that? Also, my https doesn't load. I appreciate your help.
You only have one VirtualHost for each port so each will be handling any request inbound to that Apache. Normally you would have a VirtualHost for each set of related domain names (like your apex and www in one with ServerName and ServerAlias)
In your first post the two new domains failed with a reply of "400". That is an HTTP "Bad Request". Whatever system handled that request rejected it.
I come back to an earlier question ... does this Apache system handle all 4 domain names?
www and non-www should be handled by one server. Then the images. and thumbnails. go to a different IP because there is a load balancer that serves the images and thumbnails to the client.
but images. is not. I can make images. public for awhile till I issue the certificate. Would that work? The load balancer has a different IP than my regular website as you pointed out.
Why is it timing out? It does the same thing to me. It works when using http:// but times out with https:://
Is this related to port 443? How do I open port 443?
Thanks,
-Marcos
Well, what that means is that Apache is listening on port 443
It doesn't mean that anything necessarily arrives there. If it did you would see it in your Apache access log. You don't have to look. I know it doesn't get there but go ahead to convince yourself
Something between Apache and the public internet is blocking the inbound requests. Check all the network settings in your Google Cloud. Check for any firewalls like ufw or any port forwarding going wrong.
The curl requests I showed earlier showed it failing. Another tool we use is this which shows the same thing.
nmap -p22,80,443 recordspreservation.org
rDNS record for 34.29.26.203: 203.26.29.34.bc.googleusercontent.com
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp filtered https