Adding subdomains where subdomains are directed load balancing

I am ttrying to add more subdomains to an existing certificate. images.recordspreservation.org, thumbnails.recordspreservation.org, and www.recordspreservation.org. The images and thumbnails are directed to a load balancer by GCP. images is not a public bucket.
How do I do that?
My domain is: recordspreservation.org

I ran this command:
sudo certbot certonly --expand --apache -d recordspreservation.org -d www.recordspreservation.org -d thumbnails.recordspreservation.org -d images.recordspreservation.org

It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Renewing an existing certificate for recordspreservation.org and 3 more domains

Certbot failed to authenticate some domains (authenticator: apache). The Certificate Authority reported these problems:
Domain: images.recordspreservation.org
Type: unauthorized
Detail: 34.49.27.86: Invalid response from http://images.recordspreservation.org/.well-known/acme-challenge/nJm4EwQq8mEp0VYufCHO-ePF2v4UZ6SItjZym21iAb4: 400

Domain: thumbnails.recordspreservation.org
Type: unauthorized
Detail: 34.49.27.86: Invalid response from http://thumbnails.recordspreservation.org/.well-known/acme-challenge/i8WoluPP5lfgWLtSO9l-KyoUXVkeDbEjiFEnkLLsquY: 400

Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet.

Some challenges have failed.

My web server is (include version):
Apache

The operating system my web server runs on is (include version):
Debian 11

My hosting provider, if applicable, is:
Google Computing Platform (Virtual Machine)

The Certbot --apache authenticator that you chose uses the HTTP Challenge. You must satisfy a challenge for each domain to get a cert.

If those two domains are not managed by the same Apache as your apex and www domain that option won't work.

And, if those two domain (images and thumbnails) are not accessible from the public internet you won't be able to use any other option that uses the HTTP Challenge (or TLS-ALPN).

That leaves you with the DNS Challenge. I'm not exactly sure how well that works since the SquareSpace takeover. But, you could check the Certbot docs and try it: Welcome to certbot-dns-google’s documentation! — certbot-dns-google 0 documentation

Certbot does not allow mixing --apache authentication with --google-dns but if the 2 new ones work with DNS Challenge the 2 older should too.

Other ACME Clients may allow mixing multiple challenge types (I think acme.sh does this)

Do those names need to be in the same cert?

I see IP discrepancies with those names:

Name:    recordspreservation.org
Address: 34.29.26.203
Aliases: www.recordspreservation.org
Name:    images.recordspreservation.org
Address: 34.49.27.86

Name:    thumbnails.recordspreservation.org
Address: 34.49.27.86

images is a bucket that doesn't have public permission, but I could make it temporarily available to the public to issue the certificate. thumbnails is always available to the public. I was able to add www.recordspreservation.org but the site doesn't load when I go tohttps://www.recordspreservation.org.
How do I redirect http to https if I didn't do that originally?
Thanks,
-Marcos

34.29.26.203 is the IP for the website
34.49.27.86 is the IP for the load balancer

Ok...

But what about?:

Your apex domain recordspreservation.org is not loading on HTTPS right now either. Looks like your port 443 is blocked perhaps by a firewall.

As for www redirecting, you'd have to review your Apache config VirtualHost configs. Check the VHost for port 80 that has a ServerName or ServerAlias for the www name. Sometimes people create multiple with the same name by accident and that can cause problems.

But are they managed by the same Apache server as your other 2 domain names? Because my test requests to those domains said the server was "UploadServer" and looks like a google service (not Apache).

I am new to this so I guess not -- if that's the case, can I have 2 certificates? How do I do that? Also, my https doesn't load. I appreciate your help.

I think we cross-posted so see my post just prior to your latest

Here is what I see

curl -i -m8 https://recordspreservation.org
curl: (28) Connection timed out after 8001 milliseconds

curl -i -m8 https://www.recordspreservation.org
curl: (28) Connection timed out after 8000 milliseconds

It is blocked to all IP except mine so it won't show. I can load with http in my computer but not with https.

That makes it difficult to get a cert using HTTP Challenge then :slight_smile:

And also hard to help debug if we can't see what is happening.

Would you show output of this command? Might make clear why your redirect is failing

sudo apache2ctl -t -D DUMP_VHOSTS

root@linux-web-server:~# sudo apache2ctl -t -D DUMP_VHOSTS
VirtualHost configuration:
*:443 recordspreservation.org (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2)
*:80 linux-web-server.us-central1-c.c.records-preservation.internal (/etc/apache2/sites-enabled/000-default.conf:1)

You only have one VirtualHost for each port so each will be handling any request inbound to that Apache. Normally you would have a VirtualHost for each set of related domain names (like your apex and www in one with ServerName and ServerAlias)

In your first post the two new domains failed with a reply of "400". That is an HTTP "Bad Request". Whatever system handled that request rejected it.

I come back to an earlier question ... does this Apache system handle all 4 domain names?

www and non-www should be handled by one server. Then the images. and thumbnails. go to a different IP because there is a load balancer that serves the images and thumbnails to the client.

thumbnails. is public so I can see it here:


but images. is not. I can make images. public for awhile till I issue the certificate. Would that work? The load balancer has a different IP than my regular website as you pointed out.

Why is it timing out? It does the same thing to me. It works when using http:// but times out with https:://
Is this related to port 443? How do I open port 443?
Thanks,
-Marcos

Please review my post #2.

Yes, related to port 443. I don't know how your network is configured. Whatever you did for port 80 you should do for 443

OK. Thanks for the help. I will investigate.
-Marcos

I have this in my ports.config

<IfModule ssl_module>
        Listen 443
</IfModule>

Then I issued this command which means port 443 is open:
sudo netstat -tulpn | grep :443
tcp6 0 0 :::443 :::* LISTEN 2761825/apache2

Then I tried to enable ssl but is already enabled:
a2enmod ssl

Considering dependency setenvif for ssl:
Module setenvif already enabled
Considering dependency mime for ssl:
Module mime already enabled
Considering dependency socache_shmcb for ssl:
Module socache_shmcb already enabled
Module ssl already enabled

apachectl -S

VirtualHost configuration:
*:443 recordspreservation.org (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2)
*:80 linux-web-server.us-central1-c.c.records-preservation.internal (/etc/apache2/sites-enabled/000-default.conf:1)
ServerRoot: "/etc/apache2"
Main DocumentRoot: "/var/www/html"
Main ErrorLog: "/var/log/apache2/error.log"
Mutex ssl-stapling: using_defaults
Mutex ssl-cache: using_defaults
Mutex default: dir="/var/run/apache2/" mechanism=default
Mutex mpm-accept: using_defaults
Mutex watchdog-callback: using_defaults
Mutex rewrite-map: using_defaults
Mutex ssl-stapling-refresh: using_defaults
PidFile: "/var/run/apache2/apache2.pid"
Define: DUMP_VHOSTS
Define: DUMP_RUN_CFG
Define: ENABLE_GITWEB
Define: ENABLE_USR_LIB_CGI_BIN
User: name="www-data" id=33
Group: name="www-data" id=33

Thanks again!

Well, what that means is that Apache is listening on port 443

It doesn't mean that anything necessarily arrives there. If it did you would see it in your Apache access log. You don't have to look. I know it doesn't get there but go ahead to convince yourself :slight_smile:

Something between Apache and the public internet is blocking the inbound requests. Check all the network settings in your Google Cloud. Check for any firewalls like ufw or any port forwarding going wrong.

The curl requests I showed earlier showed it failing. Another tool we use is this which shows the same thing.

nmap -p22,80,443 recordspreservation.org
rDNS record for 34.29.26.203: 203.26.29.34.bc.googleusercontent.com

PORT    STATE    SERVICE
22/tcp  open     ssh
80/tcp  open     http
443/tcp filtered https