# Another failed authorization issue

**URL:** <https://community.letsencrypt.org/t/another-failed-authorization-issue/85399>\
**Category:** Help\
**Created:** [February 6, 2019, 9:05am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399 "2019-02-06T09:05:47Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 9:05am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/1 "2019-02-06T09:05:47Z")

</div>

Got the “Action required: Let’s Encrypt certificate renewals” email. So I did the steps described in [How to stop using TLS-SNI-01 with Certbot](https://community.letsencrypt.org/t/how-to-stop-using-tls-sni-01-with-certbot/83210)  
I never ran into an issue like that before.

My domain is: [ok.fahmed.de](http://ok.fahmed.de)

I ran this command: sudo certbot renew --dry-run

It produced this output: Processing /etc/letsencrypt/renewal/ok.fahmed.de.conf

* * *

Cert not due for renewal, but simulating renewal for dry run  
Plugins selected: Authenticator apache, Installer apache  
Renewing an existing certificate  
Performing the following challenges:  
http-01 challenge for [ok.fahmed.de](http://ok.fahmed.de)  
Waiting for verification…  
Cleaning up challenges  
Attempting to renew cert ([ok.fahmed.de](http://ok.fahmed.de)) from /etc/letsencrypt/renewal/ok.fahmed.de.conf produced an unexpected error: Failed authorization procedure. [ok.fahmed.de](http://ok.fahmed.de) (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://ok.fahmed.de/.well-known/acme-challenge/G1Gf7h2lhuipYcRa7T6wKpgDvrR\_caZnrFeIsjbV7uU:](http://ok.fahmed.de/.well-known/acme-challenge/G1Gf7h2lhuipYcRa7T6wKpgDvrR_caZnrFeIsjbV7uU:) “\n\n403 Forbidden\n\n

# Forbidden
\n\<p”. Skipping.  
All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/ok.fahmed.de/fullchain.pem (failure)
* * *

\*\* DRY RUN: simulating ‘certbot renew’ close to cert expiry  
\*\* (The test certificates below have not been saved.)

All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/ok.fahmed.de/fullchain.pem (failure)  
\*\* DRY RUN: simulating ‘certbot renew’ close to cert expiry  
\*\* (The test certificates above have not been saved.)

* * *

1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): Apache2 2.4.25-3+deb9u6

The operating system my web server runs on is (include version): Debian 9

My hosting provider, if applicable, is: PixelX

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): Yes

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot): certbot 0.28.0

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 6, 2019, 9:10am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/2 "2019-02-06T09:10:20Z")

</div>

Could you please show the output of the following?

```
apachectl -t -D DUMP_VHOSTS
```

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 9:17am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/3 "2019-02-06T09:17:03Z")

</div>

output shows:  
AH00558: apache2: Could not reliably determine the server’s fully qualified domain name, using 127.0.1.1. Set the ‘ServerName’ directive globally to suppress this message  
VirtualHost configuration:  
\*:443 [ok.fahmed.de](http://ok.fahmed.de) (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2)  
\*:80 127.0.1.1 (/etc/apache2/sites-enabled/000-default.conf:1)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 6, 2019, 9:21am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/4 "2019-02-06T09:21:57Z")

</div>

Assuming that’s the full output, that’s looks OK.

Something is causing Certbot’s Apache authenticator to not combine well with how your port 80 virtual host is configured.

Would you be able to show the contents of `/etc/apache2/sites-enabled/000-default.conf` ?

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 9:23am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/5 "2019-02-06T09:23:12Z")

</div>

first of all, thanks for your help!

content is:

\<VirtualHost \*:80\>  
# The ServerName directive sets the request scheme, hostname and port that  
# the server uses to identify itself. This is used when creating  
# redirection URLs. In the context of virtual hosts, the ServerName  
# specifies what hostname must appear in the request’s Host: header to  
# match this virtual host. For the default virtual host (this file) this  
# value is not decisive as it is used as a last resort host regardless.  
# However, you must set it for any further virtual host explicitly.  
#ServerName [www.example.com](http://www.example.com)

```
    ServerAdmin webmaster@localhost
    DocumentRoot /var/www/html

    # Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
    # error, crit, alert, emerg.
    # It is also possible to configure the loglevel for particular
    # modules, e.g.
    #LogLevel info ssl:warn

    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined

    # For most configuration files from conf-available/, which are
    # enabled or disabled at a global level, it is possible to
    # include a line for only one particular virtual host. For example the
    # following line enables the CGI configuration for this host only
    # after it has been globally disabled with "a2disconf".
    #Include conf-available/serve-cgi-bin.conf

```

RewriteEngine on  
RewriteCond %{SERVER\_NAME} =[ok.fahmed.de](http://ok.fahmed.de)  
RewriteRule ^ https://%{SERVER\_NAME}%{REQUEST\_URI} [END,NE,R=permanent]

# vim: syntax=apache ts=4 sw=4 sts=4 sr noet

\<Directory /var/www/html/\>  
Options +FollowSymlinks  
AllowOverride All

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [February 6, 2019, 9:25am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/6 "2019-02-06T09:25:53Z")

</div>

Is that the full file? Seems to have been cut off a little bit at the end.

Also how about this:

```
grep -Ri "Strict-Transport" /etc/apache2
```

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 6, 2019, 9:34am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/7 "2019-02-06T09:34:31Z")

</div>

Hi @wawawa

> [@wawawa](#):
>
> My domain is: [ok.fahmed.de](http://ok.fahmed.de)

I see, you have already tested your domain via [https://check-your-website.server-daten.de/?q=ok.fahmed.de](https://check-your-website.server-daten.de/?q=ok.fahmed.de)

But your domain has a CNAME entry:

| Host | T | IP-Address | is auth. | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| [ok.fahmed.de](http://ok.fahmed.de) | C | [ahmed.spdns.de](http://ahmed.spdns.de) | yes | 1 | 0 |
| | A | 87.172.167.104 | yes | | |
| [www.ok.fahmed.de](http://www.ok.fahmed.de) | | Name Error | yes | 1 | 0 |

So [ahmed.spdns.de](http://ahmed.spdns.de) is used. Loading this domain manual, there is a nextcloud login.

So this configuration and the webserver there is relevant to validate your domain name.

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 9:47am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/8 "2019-02-06T09:47:06Z")

</div>

It is indeed the full file.  
Command shows: /etc/apache2/apache2.conf:Header always set Strict-Transport-Security “max-age=15768000; includeSubDomains; preload”

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 6, 2019, 9:53am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/9 "2019-02-06T09:53:21Z")

</div>

PS: Sorry, I should read the complete output of your test:

| Domainname | Http-Status | redirect | Sec. | G |
| --- | --- | --- | --- | --- |
| • [http://ok.fahmed.de/](http://ok.fahmed.de/) | | | | |
| 87.172.167.104 | 301 | [https://ok.fahmed.de/](https://ok.fahmed.de/) | 0.080 | A |
| | | | | |
| • [https://ok.fahmed.de/](https://ok.fahmed.de/) | | | | |
| 87.172.167.104 | 302 | [https://ok.fahmed.de/index.php/login](https://ok.fahmed.de/index.php/login) | 5.937 | A |
| | | | | |
| • [https://ok.fahmed.de/index.php/login](https://ok.fahmed.de/index.php/login) | 200 | | 1.990 | A |
| | | | | |
| • [http://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](http://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | | | | |
| 87.172.167.104 | 301 | [https://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](https://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | 0.077 | A |
| | | | | |
| • [https://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](https://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | 302 | [https://ok.fahmed.de/index.php/login](https://ok.fahmed.de/index.php/login) | 1.667 | A |

If you use http-01 - validation, Certbot creates a file in /.well-known/acme-challenge, Letsencrypt checks this file.

Port 80 is open. But there is a redirect to your login page. Your login page doesn’t know something about this test file.

So remove the redirect if the path starts with /.well-known/acme-challenge.

---

<div class="post-metadata">

**Author:** ![jmorahan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jmorahan/32/1873_2.png) [@jmorahan](https://community.letsencrypt.org/u/jmorahan)\
**Post date:** [February 7, 2019, 12:38am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/10 "2019-02-07T00:38:56Z")

</div>

A post was split to a new topic: [Failed authorization](https://community.letsencrypt.org/t/failed-authorization/85469)

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 11:18am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/11 "2019-02-06T11:18:03Z")

</div>

hmm…  
.htaccess already has an exceptional case for .well-known… :  
RewriteCond %{REQUEST\_URI} !^/.well-known/(acme-challenge|pki-validation)/.\*

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 6, 2019, 11:23am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/12 "2019-02-06T11:23:45Z")

</div>

> [@wawawa](#):
>
> .htaccess already has an exceptional case for .well-known… :  
> RewriteCond %{REQUEST\_URI} !^/.well-known/(acme-challenge|pki-validation)/.\*

Then there must be an error. The tool sees a redirect:

| [https://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](https://ok.fahmed.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | 302 | [Login – Okkocloud](https://ok.fahmed.de/index.php/login) | 1.667 | A |
| --- | --- | --- | --- | --- |
| | | | | |

So share the content your your .htaccess

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 11:23am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/13 "2019-02-06T11:23:46Z")

</div>

I also upgraded before from 0.18 to 0.28

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 6, 2019, 11:26am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/14 "2019-02-06T11:26:45Z")

</div>

This is the content of my .htaccess file:

```
<IfModule mod_headers.c>
  <IfModule mod_setenvif.c>
<IfModule mod_fcgid.c>
   SetEnvIfNoCase ^Authorization$ "(.+)" XAUTHORIZATION=$1
   RequestHeader set XAuthorization %{XAUTHORIZATION}e env=XAUTHORIZATION
</IfModule>
<IfModule mod_proxy_fcgi.c>
   SetEnvIfNoCase Authorization "(.+)" HTTP_AUTHORIZATION=$1
</IfModule>
  </IfModule>

  <IfModule mod_env.c>
# Add security and privacy related headers
Header set X-Content-Type-Options "nosniff"
Header set X-XSS-Protection "1; mode=block"
Header set X-Robots-Tag "none"
Header set X-Download-Options "noopen"
Header set X-Permitted-Cross-Domain-Policies "none"
Header set Referrer-Policy "no-referrer"
SetEnv modHeadersAvailable true
  </IfModule>

  # Add cache control for static resources
  <FilesMatch "\.(css|js|svg|gif)$">
Header set Cache-Control "max-age=15778463"
  </FilesMatch>

  # Let browsers cache WOFF files for a week
  <FilesMatch "\.woff2?$">
Header set Cache-Control "max-age=604800"
  </FilesMatch>
</IfModule>
<IfModule mod_php5.c>
  php_value upload_max_filesize 10G
  php_value post_max_size 10G
  php_value memory_limit 512M
  php_value mbstring.func_overload 0
  php_value always_populate_raw_post_data -1
  php_value default_charset 'UTF-8'
  php_value output_buffering 0
  <IfModule mod_env.c>
SetEnv htaccessWorking true
  </IfModule>
</IfModule>
<IfModule mod_php7.c>
  php_value upload_max_filesize 10G
  php_value post_max_size 10G
  php_value memory_limit 512M
  php_value mbstring.func_overload 0
  php_value default_charset 'UTF-8'
  php_value output_buffering 0
  <IfModule mod_env.c>
SetEnv htaccessWorking true
  </IfModule>
</IfModule>
<IfModule mod_rewrite.c>
  RewriteEngine on
  RewriteCond %{HTTP_USER_AGENT} DavClnt
  RewriteRule ^$ /remote.php/webdav/ [L,R=302]
  RewriteRule .* - [env=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
  RewriteRule ^\.well-known/host-meta /public.php?service=host-meta [QSA,L]
  RewriteRule ^\.well-known/host-meta\.json /public.php?service=host-meta-json [QSA,L]
  RewriteRule ^\.well-known/webfinger /public.php?service=webfinger [QSA,L]
  RewriteRule ^\.well-known/carddav /remote.php/dav/ [R=301,L]
  RewriteRule ^\.well-known/caldav /remote.php/dav/ [R=301,L]
  RewriteRule ^remote/(.*) remote.php [QSA,L]
  RewriteRule ^(?:build|tests|config|lib|3rdparty|templates)/.* - [R=404,L]
  RewriteCond %{REQUEST_URI} !^/\.well-known/(acme-challenge|pki-validation)/.*
  RewriteRule ^(?:\.|autotest|occ|issue|indie|db_|console).* - [R=404,L]
</IfModule>
<IfModule mod_mime.c>
  AddType image/svg+xml svg svgz
  AddEncoding gzip svgz
</IfModule>
<IfModule mod_dir.c>
  DirectoryIndex index.php index.html
</IfModule>
AddDefaultCharset utf-8
Options -Indexes
<IfModule pagespeed_module>
  ModPagespeed Off
</IfModule>
#### DO NOT CHANGE ANYTHING ABOVE THIS LINE ####

ErrorDocument 403 //
ErrorDocument 404 //
```

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [February 6, 2019, 12:17pm UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/15 "2019-02-06T12:17:30Z")

</div>

> [@wawawa](#):
>
> ```nohighlight
> RewriteRule ^\.well-known/host-meta /public.php?service=host-meta [QSA,L]
> RewriteRule ^\.well-known/host-meta\.json /public.php?service=host-meta-json [QSA,L]
> RewriteRule ^\.well-known/webfinger /public.php?service=webfinger [QSA,L] 
> RewriteRule ^\.well-known/carddav /remote.php/dav/ [R=301,L] 
> RewriteRule ^\.well-known/caldav /remote.php/dav/ [R=301,L] 
> RewriteRule ^remote/(.*) remote.php [QSA,L] 
> RewriteRule ^(?:build|tests|config|lib|3rdparty|templates)/.* - [R=404,L] 
> RewriteCond %{REQUEST_URI} !^/\.well-known/(acme-challenge|pki-validation)/.*
> 
> ```

You have other RewriteRules with L at the end and no / at the beginning.

So use the same rule with your .well-known/acme-challenge directory.

But I don't see there a redirect to your login page. So this place may be wrong.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 7, 2019, 12:40am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/16 "2019-02-07T00:40:21Z")

</div>

> [@wawawa](#):
>
> `RewriteCond %{REQUEST_URI} !^/\.well-known/(acme-challenge|pki-validation)/.*`

Perhaps that should read:  
`RewriteCond %{REQUEST_URI} !^/\.well-known/(acme-challenge|pki-validation)/(.*)`

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 9, 2019, 9:16am UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/17 "2019-02-09T09:16:22Z")

</div>

Is it possible that the directory ./well-known/acme-challenge was not created? I searched for it, but can’t find it.

---

<div class="post-metadata">

**Author:** ![wawawa](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@wawawa](https://community.letsencrypt.org/u/wawawa)\
**Post date:** [February 9, 2019, 4:57pm UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/18 "2019-02-09T16:57:36Z")

</div>

I was able to renew the certificate. Mea culpa. I had a Geo-IP lock installed which prevented the challenge file from being accessed by the authority.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 11, 2019, 4:57pm UTC](https://community.letsencrypt.org/t/another-failed-authorization-issue/85399/19 "2019-03-11T16:57:42Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
