# Attempting to renew cert

**URL:** <https://community.letsencrypt.org/t/attempting-to-renew-cert/136586>\
**Category:** Help\
**Created:** [October 22, 2020, 11:13am UTC](https://community.letsencrypt.org/t/attempting-to-renew-cert/136586 "2020-10-22T11:13:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![parashuram](https://avatars.discourse-cdn.com/v4/letter/p/8c91f0/32.png) [@parashuram](https://community.letsencrypt.org/u/parashuram)\
**Post date:** [October 22, 2020, 11:13am UTC](https://community.letsencrypt.org/t/attempting-to-renew-cert/136586/1 "2020-10-22T11:13:37Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command: certbot renew --dry-run

It produced this output:  
Attempting to renew cert ([data.example.co](http://data.example.co)) from /etc/letsencrypt/renewal/data.example.co.conf produced an unexpected error: Failed authorization procedure. [data.example.co](http://data.example.co) (http-01): urn:ietf:params:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://data.example.co/.well-known/acme-challenge/uHZF3VMrM-unuyunA0gNc5oO84vUKktMW680jXDjUKM:](http://data.example.co/.well-known/acme-challenge/uHZF3VMrM-unuyunA0gNc5oO84vUKktMW680jXDjUKM:) Timeout during connect (likely firewall problem). Skipping.  
All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/data.example.co/fullchain.pem (failure)

sudo certbot renew --dry-run --preferred-challenges http(tried with this command same error)

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 22, 2020, 1:33pm UTC](https://community.letsencrypt.org/t/attempting-to-renew-cert/136586/2 "2020-10-22T13:33:06Z")

</div>

Hi @parashuram

> [@parashuram](#):
>
> My domain is:

your domain name is required if you want help.

There

> [@parashuram](#):
>
> The server could not connect to the client to verify the domain :: Fetching [http://data.example.co/.well-known/acme-challenge/uHZF3VMrM-unuyunA0gNc5oO84vUKktMW680jXDjUKM:](http://data.example.co/.well-known/acme-challenge/uHZF3VMrM-unuyunA0gNc5oO84vUKktMW680jXDjUKM:) Timeout during connect (likely firewall problem)

is your job: Your domain / server doesn't answer. Change that.

Read the part about http validation:

> **[Challenge Types - Let's Encrypt](https://letsencrypt.org/docs/challenge-types/)**
>
> When you get a certificate from Let’s Encrypt, our servers validate that you control the domain names in that certificate using “challenges,” as defined by the ACME standard. Most of the time, this validation is handled automatically by your ACME...

A working port 80 / http is required if you want to use http validation.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 21, 2020, 1:33pm UTC](https://community.letsencrypt.org/t/attempting-to-renew-cert/136586/3 "2020-11-21T13:33:06Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
