Apache + certbot

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: persona.servier.com.cn

I ran this command: certbot --apache

It produced this output:
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter ‘c’ to cancel): 2
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for persona.servier.com.cn
Waiting for verification…
Challenge failed for domain persona.servier.com.cn
http-01 challenge for persona.servier.com.cn
Cleaning up challenges
Some challenges have failed.

IMPORTANT NOTES:

  • The following errors were reported by the server:

    Domain: persona.servier.com.cn
    Type: connection
    Detail: Fetching
    http://persona.servier.com.cn/.well-known/acme-challenge/4fbjNjHnyw7o_zNrr2juws_q599rPQSvT91QCb3LhZ4:
    Timeout during connect (likely firewall problem)

    To fix these errors, please make sure that your domain name was
    entered correctly and the DNS A/AAAA record(s) for that domain
    contain(s) the right IP address. Additionally, please check that
    your computer has a publicly routable IP address and that no
    firewalls are preventing the server from communicating with the
    client. If you’re using the webroot plugin, you should also verify
    that you are serving files from the webroot path you provided.

My web server is (include version): Apache/2.4.6

The operating system my web server runs on is (include version):
centos-release-7-8.2003.0.el7.centos.x86_64

My hosting provider, if applicable, is: I don’t know

I can login to a root shell on my machine (yes or no, or I don’t know):
yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):
NO

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): certbot 1.7.0

1 Like

Hi @hijason

there

is your error:

A working port 80 / http is required if you want to use http validation.

There is only a timeout.

Works http internal?

curl http://persona.servier.com.cn/.well-known/acme-challenge/1234

from that machine? If no, fix it. If yes, it’s a routing / firewall problem.

2 Likes

Hi JuergenAuer,

I am not very clear for your discription.
Could you tell me how resolve it?
I had open rule for port 80 and port 443 in the Firewall.

This site is not accessible on port 80 at all, at least from outside China. This problem isn’t due to Let’s Encrypt; you’ll have to figure out how to address it before requesting your certificate.

1 Like

Hi Schoen,

I want to use port 443 to access the domain , not 80.
So how to change it?

Your http doesn’t answer, your https answers - see https://check-your-website.server-daten.de/?q=persona.servier.com.cn#url-checks

Domainname Http-Status redirect Sec. G
http://persona.servier.com.cn/ 139.217.112.174 -14 9.997 T
Timeout - The operation has timed out
https://persona.servier.com.cn/ 139.217.112.174 Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/858 404 Html is minified: 340,35 % 5.734 N
Not Found
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
small visible content (num chars: 13)
404 Not Found
http://persona.servier.com.cn/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 139.217.112.174 -14 10.000 T
Timeout - The operation has timed out

So it’s not a “China” problem (Great firewall), looks like your http doesn’t answer.

Please start with some basics:

Then read the basics about challenge types:

Conclusion: Using http validation -> port 80 / http is required.

Your port 443 answers and is visible, so your port 80 is missing -> change that.

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.