Authorization result: invalid

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

Plugin Manual generated source mail.bpi.si with 1 identifiers
Plugin Single created 1 order
[mail.bpi.si] Authorizing...
[mail.bpi.si] Authorizing using http-01 validation (SelfHosting)
[mail.bpi.si] Authorization result: invalid
[mail.bpi.si] {"type":"urn:ietf:params:acme:error:connection","detail":"86.58.124.130: Fetching http://mail.bpi.si/.well-known/acme-challenge/RRxVQZmcMOqKd6YWAScENhW1_srS4Bvddh8hqILpesw: Timeout during connect (likely firewall problem)","status":400,"instance":null}
[mail.bpi.si] Deactivating pending authorization

Welcome @andrej

The HTTP validation method you chose requires the Let's Encrypt servers to query your domain using HTTP on port 80.

That connection fails. You should check for any firewalls blocking that port. If this is a residence check your router and check that your ISP allows port 80.

If you need further help please answer more of the questions from the form you were shown. The more you can answer the better we can help

============================

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my ACME client is:

3 Likes

Hello I have tryied another verification and it fails. I haveno idea what do I do wrong.
here is a result from Win Acme

omain: autodiscover.png.si
Record: _acme-challenge.autodiscover.png.si
Type: TXT
Content: "yTUqgm1HXyJkFaRcggAJlVuN45e4oH9bE9ftsS3cHJs"
Note: Some DNS managers add quotes automatically. A single set
is needed.

Please press after you've created and verified the record

[autodiscover.png.si] Preliminary validation succeeded
[autodiscover.png.si] Record yTUqgm1HXyJkFaRcggAJlVuN45e4oH9bE9ftsS3cHJs successfully created
[autodiscover.png.si] Preliminary validation succeeded
[autodiscover.png.si] Authorization result: invalid
[autodiscover.png.si] {"type":"urn:ietf:params:acme:error:dns","detail":"DNS problem: NXDOMAIN looking up TXT for _acme-challenge.autodiscover.png.si - check that a DNS record exists for this domain","status":400,"instance":null}

Domain: autodiscover.png.si
Record: _acme-challenge.autodiscover.png.si
Type: TXT
Content: "yTUqgm1HXyJkFaRcggAJlVuN45e4oH9bE9ftsS3cHJs"

Please press after you've deleted the record

[autodiscover.png.si] Record yTUqgm1HXyJkFaRcggAJlVuN45e4oH9bE9ftsS3cHJs deleted
[autodiscover.png.si] Deactivating pending authorization
[mail.png.si] Deactivating pending authorization

There are two parts to that request:

  • create
  • verify

How did you verify the entry?

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.