Cannot obtain certificates. Cannot verify Domain


#1

Please fill out the fields below so we can help you better.

My domain is: external-portal.dyndns.org

I ran this command: ./letsencrypt-auto certonly -a manual --rsa-key-size 4096 -d external-portal.dyndns.org -d www.external-portal.dyndns.org

It produced this output:Failed authorization procedure. www.external-portal.dyndns.org (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: DNS problem: NXDOMAIN looking up A for www.external-portal.dyndns.org

IMPORTANT NOTES:

  • The following errors were reported by the server:

    Domain: www.external-portal.dyndns.org
    Type: connection
    Detail: DNS problem: NXDOMAIN looking up A for
    www.external-portal.dyndns.org

    To fix these errors, please make sure that your domain name was
    entered correctly and the DNS A record(s) for that domain
    contain(s) the right IP address. Additionally, please check that
    your computer has a publicly routable IP address and that no
    firewalls are preventing the server from communicating with the
    client. If you’re using the webroot plugin, you should also verify
    that you are serving files from the webroot path you provided.

My operating system is (include version): Mac OSX 10.11.6 El Capitan

My web server is (include version):Mac OSX 10.11.6 El Capitan

My hosting provider, if applicable, is: This is a MacMini on my LAN

I can login to a root shell on my machine (yes or no, or I don’t know): I think so, yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):NO


#2

Just to add a little more flesh to the query:

I am using DYNDNS to point to my IP address. The MacMini I am using as a webserver is inside the LAN and I have a Draytek Router redirecting port 80 and 443 to my internal ip address. I have tried setting the MacMini inside a DMZ (temporarily as a troubleshooting idea) but I still cannot connect.

As I am by no means an expert in this area I would really appreciate some help here. I am trying to serve a Filemaker Database to fellow colleagues externally. The database was accessible under http: but I would like to have the dataflow encrypted for security reasons. Thinking that it could be the Filemaker Server that was causing the problem, I uninstalled it and started from scratch with a newly formatted HDD. So now I have nothing on the MacMini except the OS, Xcode and command line tools, Homebrew and the LetsEncrypt software.

Really I would appreciate some help getting the certificates issued so I can move on an install Filemaker again.

Very many thanks

Duncan


#3

Are you certain your domain name is www.external-portal.dyndns.org ? as that doesn’t appear to exist. or is it just external-portal.dyndns.org ?


#4

Hi thanks for responding

It appears to be just external-portal.dyndns.org (at least that is how it is shown in My Hosts section of DYNDNS.

To be honest I am not overly knowledgeable about the difference.

Thanks

Duncan


#5

Hi

Thanks

I appear to have got it working. I have my certificates at least!

The problem was that I hadn’t started the Apache webserver!

sudo apachectl start

Thanks

D


#6

That’s interesting, because starting Apache will never fix a DNS problem :grin:


#7

No, but I am guessing that it couldn’t connect because the server wasn’t running. One of the suggestions was that the DNS wasn’t correct?

Thanks for your interest.

D


#8

Why yes… The error message DNS problem: NXDOMAIN looking up A for (...) does makes you think about a DNS problem, no?


#9

It may even be a coincidence that the Apache server wasn’t running; the DNS issue related to www.external-portal would be enough to produce this error message all by itself, while that issue would go away if you ran Certbot without the second -d.


#10

I am sure you are right and it was just a co-incidence.

Anyway, the good thing is that I now have some certificates!

Thanks all

D


#11

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.