Can´t renew certificate

Hi can´t renew the certificate. Until now the certificate renews automatically. i use a synology DS114 with DSM 6.1.
I use the AVM Fritzbox DYNDNS Service. If i report this is the result. I covered my original Domain for security.

Startzeit: Tue, 13 Jun 2017 15:47:29 GMT
Stoppzeit: Tue, 13 Jun 2017 15:47:30 GMT
Aktueller Status: 0
DEBUG: Issuer name of certificate. [Let’s Encrypt]->[/usr/syno/etc/certificate/_archive/eQmDlw/cert.pem]
DEBUG: start to renew [/usr/syno/etc/certificate/_archive/eQmDlw].
DEBUG: setup acme url
DEBUG: szUserAgent: [synology_armada370_114 DSM6.1-15101 Update 4 (DDNS)]
DEBUG: GET Request:
] Body: [{
DEBUG: strat to do new-authz for
DEBUG: ==> start new authz.
DEBUG: new authz: do new-authz.
DEBUG: Curl Reply: [429] Header: [HTTP/1.1 429 Unknown
“type”: “urn:acme:error:rateLimited”,
“detail”: “Error creating new authz :: Too many invalid authorizations recently.”,
“status”: 429
DEBUG: Not synology DDNS.
DEBUG: DNS challenge failed, reason: {“error”:108,“file”:“challenge.cpp”,“msg”:“Not synology DDNS.”}

DEBUG: Normal challenge failed, reason: {“error”:200,“file”:“client.cpp”,“msg”:“new_aut hz: unexpect httpcode.”}

Hi @rici,

This is not the useful error message about why this is failing because this error message simply says that you’ve been trying too often with a broken configuration.

Could you wait a bit and try again, and then show us the more specific error? Or do you have older logs that will show the underlying reason?

Does your Fritzbox have an IPv6 address, by any chance?

today i tried it again and got the following message :

] Body: [{
“type”: “urn:acme:error:unauthorized”,
“detail”: “Error creating new cert :: authorizations for these names not found or expired:”,
“status”: 403

I’m still wondering if your Fritzbox has an IPv6 address.

Are all of these errors coming from your Synology client? You might end up needing to ask Synology for help with that if there isn’t something straightforward to fix in the Fritzbox.

yes, my fritzbox has an ipv6 adress. this was the problem, but why ?

A few weeks ago Let’s Encrypt switched to prefer IPv6 to IPv4 for validation purposes when both are offered. This has exposed a lot of incompatibilities and bugs because a lot of people advertise an IPv6 address yet can’t properly receive incoming connections on it.

It’s likely that there’s a bug either in the Fritzbox or in the Synology client that means that it can’t support Let’s Encrypt validations over IPv6. I don’t know exactly what that bug would be, but it’s been very typical of other people’s experiences with validations over IPv6, unfortunately. It would be great to let them know about this in the hope that they can fix it for everyone.

It looks like you have to set up port forwarding for IPv6 separately from IPv4 on many fritzbox models.

If you Google fritzbox <model #> IPv6 port forwarding you’ll find instructions on how to set that up. (It seems to vary by model or I would just link one.) Just forward the same ports to your Synology box as you do over IPv4 and things should start working again.

