An error occurred creating certificates with Let's Encrypt:

When I try to do an SSL certificate in my domain I am getting this error:

An error occurred creating certificates with Let's Encrypt:

private keys obtained from Let's Encrypt so making regular
backups of this folder is ideal.
2024/10/18 17:22:26 No key found for account Generating a
P256 key.
2024/10/18 17:22:26 Saved key to
2024/10/18 17:22:26 [INFO] acme: Registering account for
2024/10/18 17:22:27 [INFO] [,] acme: Obtaining bundled SAN certificate
2024/10/18 17:22:28 [INFO] [] AuthURL:
2024/10/18 17:22:28 [INFO] [] AuthURL:
2024/10/18 17:22:28 [INFO] [] acme: use tls-alpn-01
2024/10/18 17:22:28 [INFO] [] acme: use
tls-alpn-01 solver
2024/10/18 17:22:28 [INFO] [] acme: Trying to solve
Press [Enter] to continue:
2024/10/18 17:22:40 [INFO] [] The server validated
our request
2024/10/18 17:22:40 [INFO] [] acme: Trying to
solve TLS-ALPN-01
2024/10/18 17:22:47 [INFO] Skipping deactivating of valid auth:
2024/10/18 17:22:47 [INFO] Deactivating auth:
2024/10/18 17:22:47 Could not obtain certificates:
error: one or more domains had a problem:
[] acme: error: 403 ::
urn:ietf:params:acme:error:unauthorized :: Cannot negotiate ALPN protocol
"acme-tls/1" for tls-alpn-01 challenge

Please check our documentation and support forums, we'll be happy to help!

Hello @doyle,

Let’s Debug give for results.

The domain is being served through Cloudflare CDN. Any Let's Encrypt certificate installed on the origin server will only encrypt traffic between the server and Cloudflare. It is strongly recommended that the SSL option 'Full SSL (strict)' be enabled.

This is the important part “It is strongly recommended that the SSL option 'Full SSL (strict)' be enabled.”


Thanks for the response, does this mean that I can't certify it with SSL anymore? Or do we have a certain command to run to overwrite it?

So the scenario is, I am planning to route the domain to another Server by setting up the static IP to its DNS settings, however in that new server that I have its not yet SSL certified.

1 Like

Your DNS settings when you ran the command shown in your first post are different than the ones you have now.

For that request your apex name pointed to a server at AWS. And, the TLS-ALPN challenge for that worked.

But, your www subdomain pointed to Cloudflare edge locations. This is because you had a CNAME for your www subdomain that does this 10 IN CNAME

Why do you point your www name to wpenginepowered? Did they give you these instructions?


Yes Mike, I have reverted the DNS settings back to the old server, the new server that I have is running in AWS Lightsail with a new Name Server.

And for the wpenginepowered, this was set up by the previous dev, the site is currently running in wpengine. My goal is to totally transfer it to the new AWS Lightsail server

Then your DNS settings for both names should point to your new AWS server.

You need to modify the CNAME for your www domain and point it to your apex.


Thanks Mike, I'll give it a try


This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.