# Apache + certbot

**URL:** https://community.letsencrypt.org/t/apache-certbot/133990
**Category:** Help
**Created:** [September 18, 2020, 7:14am UTC](https://community.letsencrypt.org/t/apache-certbot/133990 "2020-09-18T07:14:58Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![hijason](https://avatars.discourse-cdn.com/v4/letter/h/71c47a/32.png) [@hijason](https://community.letsencrypt.org/u/hijason)
#### Post date: [September 18, 2020, 7:14am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/1 "2020-09-18T07:14:58Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [persona.servier.com.cn](http://persona.servier.com.cn)

I ran this command: certbot --apache

It produced this output:  
Select the appropriate numbers separated by commas and/or spaces, or leave input  
blank to select all options shown (Enter ‘c’ to cancel): 2  
Obtaining a new certificate  
Performing the following challenges:  
http-01 challenge for [persona.servier.com.cn](http://persona.servier.com.cn)  
Waiting for verification…  
Challenge failed for domain [persona.servier.com.cn](http://persona.servier.com.cn)  
http-01 challenge for [persona.servier.com.cn](http://persona.servier.com.cn)  
Cleaning up challenges  
Some challenges have failed.

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): Apache/2.4.6

The operating system my web server runs on is (include version):  
centos-release-7-8.2003.0.el7.centos.x86\_64

My hosting provider, if applicable, is: I don’t know

I can login to a root shell on my machine (yes or no, or I don’t know):  
yes  
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):  
NO

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot): certbot 1.7.0

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [September 18, 2020, 7:53am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/2 "2020-09-18T07:53:36Z")

</div>

Hi @hijason

there

> [@hijason](#):
>
> Domain: [persona.servier.com.cn](http://persona.servier.com.cn)  
> Type: connection  
> Detail: Fetching  
> [http://persona.servier.com.cn/.well-known/acme-challenge/4fbjNjHnyw7o\_zNrr2juws\_q599rPQSvT91QCb3LhZ4:](http://persona.servier.com.cn/.well-known/acme-challenge/4fbjNjHnyw7o_zNrr2juws_q599rPQSvT91QCb3LhZ4:)  
> Timeout during connect (likely firewall problem)

is your error:

A working port 80 / http is required if you want to use http validation.

There is only a timeout.

Works http internal?

```nohighlight
curl http://persona.servier.com.cn/.well-known/acme-challenge/1234

```

from that machine? If no, fix it. If yes, it's a routing / firewall problem.

---

<div class="post-metadata">

### Author: ![hijason](https://avatars.discourse-cdn.com/v4/letter/h/71c47a/32.png) [@hijason](https://community.letsencrypt.org/u/hijason)
#### Post date: [September 18, 2020, 8:00am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/3 "2020-09-18T08:00:15Z")

</div>

Hi JuergenAuer,

I am not very clear for your discription.  
Could you tell me how resolve it?  
I had open rule for port 80 and port 443 in the Firewall.

---

<div class="post-metadata">

### Author: ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)
#### Post date: [September 18, 2020, 8:08am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/4 "2020-09-18T08:08:11Z")

</div>

This site is not accessible on port 80 at all, at least from outside China. This problem isn’t due to Let’s Encrypt; you’ll have to figure out how to address it before requesting your certificate.

---

<div class="post-metadata">

### Author: ![hijason](https://avatars.discourse-cdn.com/v4/letter/h/71c47a/32.png) [@hijason](https://community.letsencrypt.org/u/hijason)
#### Post date: [September 18, 2020, 8:11am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/5 "2020-09-18T08:11:30Z")

</div>

Hi Schoen,

I want to use port 443 to access the domain , not 80.  
So how to change it?

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [September 18, 2020, 8:16am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/6 "2020-09-18T08:16:43Z")

</div>

> [@hijason](#):
>
> I had open rule for port 80 and port 443 in the Firewall.

Your http doesn't answer, your https answers - see [persona.servier.com.cn - Make your website better - DNS, redirects, mixed content, certificates](https://check-your-website.server-daten.de/?q=persona.servier.com.cn#url-checks)

| Domainname | Http-Status | redirect | Sec. | G |
| --- | --- | --- | --- | --- |
| • [http://persona.servier.com.cn/](http://persona.servier.com.cn/) 139.217.112.174 | -14 | | 9.997 | T |
| Timeout - The operation has timed out | | | | |
| | | | | |
| • [https://persona.servier.com.cn/](https://persona.servier.com.cn/) 139.217.112.174 Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/858 | 404 | Html is minified: 340,35 % | 5.734 | N |
| Not Found | | | | |
| Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors | | | | |
| small visible content (num chars: 13) | | | | |
| 404 Not Found | | | | |
| | | | | |
| • [http://persona.servier.com.cn/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](http://persona.servier.com.cn/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) 139.217.112.174 | -14 | | 10.000 | T |
| Timeout - The operation has timed out | | | | |

So it's not a "China" problem (Great firewall), looks like your http doesn't answer.

> [@hijason](#):
>
> I want to use port 443 to access the domain , not 80.

Please start with some basics:

> **[How It Works - Let's Encrypt](https://letsencrypt.org/how-it-works/)**
>
> The objective of Let’s Encrypt and the ACME protocol is to make it possible to set up an HTTPS server and have it automatically obtain a browser-trusted certificate, without any human intervention. This is accomplished by running a certificate...

Then read the basics about challenge types:

> **[Challenge Types - Let's Encrypt](https://letsencrypt.org/docs/challenge-types/)**
>
> When you get a certificate from Let’s Encrypt, our servers validate that you control the domain names in that certificate using “challenges,” as defined by the ACME standard. Most of the time, this validation is handled automatically by your ACME...

Conclusion: Using http validation -\> port 80 / http is required.

Your port 443 answers and is visible, so your port 80 is missing -\> change that.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [October 18, 2020, 8:17am UTC](https://community.letsencrypt.org/t/apache-certbot/133990/7 "2020-10-18T08:17:02Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
