Asus Unable to apply settings. Please try again. (Ref. 5401)

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

trying to add ssl to my asustor 4004T so i can host my own website but keep getting the 'Unable to apply settings. Please try again. (Ref. 5401)' message

My domain is: artistikbymystik.co.nz

I ran this command: Create certificate from Let's Encrypt

It produced this output: Unable to apply settings. Please try again. (Ref. 5401)

My web server is (include version): Apache HTTP server 2.4.62.r19

The operating system my web server runs on is (include version): Asustor Data Master 4.3.3.ROF1

My hosting provider, if applicable, is: n/a

I can login to a root shell on my machine (yes or no, or I don't know): i dont know

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): n/a

thanks

I am not certain this is what is causing that particular problem. But, your DNS config needs work. You should make sure HTTP requests can reach your domain before trying to get a cert that way.

I get an HTTP 409 Conflict error from Cloudflare trying to reach your "home" page. Which I have never seen before and seems very odd. Mainly because I don't see any Cloudflare DNS servers in your DNS tree. In any case, this is where you should start. The Cloudflare community is probably a better place to get help for that.

If requests to your home page fail then Let's Encrypt requests to your server will also fail (if using the HTTP Challenge).

Note the "Server" response header indicates Cloudflare

curl -i http://artistikbymystik.co.nz

HTTP/1.1 409 Conflict
Content-Type: text/plain; charset=UTF-8
Content-Length: 16
Connection: close
X-Frame-Options: SAMEORIGIN
Referrer-Policy: same-origin
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Server: cloudflare
CF-RAY: 9b67227cbbde0bfe-IAD

error code: 1001

You probably see this same error when trying to reach your domain from the public internet. You could use a mobile phone with wifi switched off. Or, try https://letsdebug.net

3 Likes

could that be due to me making dns changes and it needing time to complete propagation??

I don't know. The IP address in your DNS A record looks to be controlled by Cloudflare.

The Cloudflare community is a better place to ask about proper configuration of that. See: https://community.cloudflare.com/

Also see this topic in their 409 support guide: Error 1001 · Cloudflare Support docs

4 Likes

That IP is a Shopify IP, and they use Cloudflare. You will need to have that hostname configured in your Shopify account before you can use it with that IP. You won't need to use Let's Encrypt with that hostname if you plan to use it with Shopify. They should be managing the certificates for it through Cloudflare.

3 Likes

tried to create a cert and now im getting artistikbymystik.co.nz is invalid. Please ensure that your domain name can be successfully connected to using port 80. (Ref. 5056)

I moved your post in a new thread to this one and removed duplicated info.

Please continue in this same thread with the same problem. It is easier to track the history and helps us. Thank you.

The IP address in your DNS for that domain name is managed by Shopify (which in turn uses Cloudflare).

Usually in this case the DNS IP address must be the public IP for your residence.

We are not a general purpose help site for setting up your network config. I realize you are having a problem getting a certificate. But, this is because no connections can reach your domain due to the '409' error I showed earlier. This affects every request to your domain not just the ones Let's Encrypt uses.

You must ensure HTTP connections work before trying to get the cert using your method.

The https://letsdebug.net test site is often helpful to test new setups.

Or, try connecting to your domain from outside your local network and see the failure yourself. Maybe try a mobile phone with wifi switched off.

3 Likes