# Cannot renew certificate: tcp port 80 is already used by (("nginx",pid=

**URL:** <https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854>\
**Category:** Help\
**Created:** [February 6, 2024, 8:16pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854 "2024-02-06T20:16:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![chris492](https://avatars.discourse-cdn.com/v4/letter/c/87869e/32.png) [@chris492](https://community.letsencrypt.org/u/chris492)\
**Post date:** [February 6, 2024, 8:16pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/1 "2024-02-06T20:16:46Z")

</div>

My domain is: [erdwerk-bioladen.de](http://erdwerk-bioladen.de)

I ran this command: acme.sh --renew -d [cloud.erdwerk-bioladen.de](http://cloud.erdwerk-bioladen.de)

It produced this output:

```nohighlight
[Tue 06 Feb 2024 07:02:07 PM CET] Renew: 'cloud.erdwerk-bioladen.de'
[Tue 06 Feb 2024 07:02:07 PM CET] Using CA: https://acme-v02.api.letsencrypt.org/directory
[Tue 06 Feb 2024 07:02:07 PM CET] Standalone mode.
[Tue 06 Feb 2024 07:02:07 PM CET] LISTEN 0 128 0.0.0.0:80 0.0.0.0:* users:(("nginx",pid=25772,fd=8),("nginx",pid=25771,fd=8),("nginx",pid=733,fd=8))
LISTEN 0 128 [::]:80 [::]:* users:(("nginx",pid=25772,fd=9),("nginx",pid=25771,fd=9),("nginx",pid=733,fd=9))
[Tue 06 Feb 2024 07:02:07 PM CET] tcp port 80 is already used by (("nginx",pid=25772,fd=8),("nginx",pid=25771,fd=8),("nginx",pid=733,fd=8))
80 [
[Tue 06 Feb 2024 07:02:07 PM CET] Please stop it first
[Tue 06 Feb 2024 07:02:07 PM CET] _on_before_issue.

```

My web server is (include version): nginx/1.14.2

The operating system my web server runs on is (include version): "Debian GNU/Linux 10

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): /acme.sh v2.8.8

I have two certificates on that server one for [cloud.erdwerk-bioladen.de](http://cloud.erdwerk-bioladen.de) and another for [mail.erdwerk-bioladen.de](http://mail.erdwerk-bioladen.de) with the SAN domains [imap.erdwerk-bioladen.de](http://imap.erdwerk-bioladen.de) and [smtp.erdwerk-bioladen.de](http://smtp.erdwerk-bioladen.de).

`acme.sh --list` gives me:

```nohighlight
Main_Domain KeyLength SAN_Domains CA Created Renew
cloud.erdwerk-bioladen.de "" no LetsEncrypt.org Sat 19 Nov 2022 09:30:22 AM UTC Wed 18 Jan 2023 09:30:22 AM UTC
mail.erdwerk-bioladen.de "" imap.erdwerk-bioladen.de,smtp.erdwerk-bioladen.de LetsEncrypt.org Tue 06 Feb 2024 06:01:13 PM UTC Sat 06 Apr 2024 06:01:13 PM UTC

```

I am pretty sure this setup worked in the past. But since Januray 2023 the certificate for [cloud.erdwerk-bioladen.de](http://cloud.erdwerk-bioladen.de) won't renew while it works fine for [mail.erdwerk-bioladen.de](http://mail.erdwerk-bioladen.de).

Am I doing anything wrong?

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [February 6, 2024, 8:22pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/2 "2024-02-06T20:22:16Z")

</div>

Hello @chris492, welcome to the Let's Encrypt community. 🙂

More `acme.sh` support is here [Issues · acmesh-official/acme.sh · GitHub](https://github.com/acmesh-official/acme.sh/issues)

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [February 6, 2024, 9:37pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/3 "2024-02-06T21:37:34Z")

</div>

Or we could ping @Neilpang for a leg up!

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 6, 2024, 10:46pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/4 "2024-02-06T22:46:49Z")

</div>

Why are you using standalone mode instead of webroot mode? Did you add (or reconfigure) nginx recently?

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [February 7, 2024, 1:29am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/5 "2024-02-07T01:29:55Z")

</div>

Webroot would be good.

---

<div class="post-metadata">

**Author:** ![Neilpang](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/neilpang/32/20232_2.png) [@Neilpang](https://community.letsencrypt.org/u/Neilpang)\
**Post date:** [February 7, 2024, 2:24am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/6 "2024-02-07T02:24:43Z")

</div>

Thanks for Ping me.

@chris492 you first issued the cert with standalone mode, which used your 80 port. and later you started your nginx server, which is listening on 80 port now. So, when you renew your cert, it tries to use the 80 port, but it's used by nginx already.

please issue the cert again with webroot mode.

---

<div class="post-metadata">

**Author:** ![chris492](https://avatars.discourse-cdn.com/v4/letter/c/87869e/32.png) [@chris492](https://community.letsencrypt.org/u/chris492)\
**Post date:** [February 9, 2024, 4:54pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/7 "2024-02-09T16:54:14Z")

</div>

Hi Neilpang, thanks for your advice.

It works with using `acme.sh --issue -d cloud.erdwerk-bioladen.de -w /var/www/nextcloud/`. Let's see if the certificate will be renewed after two month.

I tried with `acme.sh --issue --nginx -d cloud.erdwerk-bioladen.de -w /var/www/nextcloud/`  
but got the error  
`cloud.erdwerk-bioladen.de:Verify error:93.104.208.86: Invalid response from https://cloud.erdwerk-bioladen.de/.well-known/acme-challenge/MQrnPaHXmSiYp2GIC6vywpcA5uXagHR0Pvfgf1bPoWU: 404`

Just to clarify what has been installed on that server:

- I first used it just as a mail server. But I installed Nginx right from the beginning for the certificate and Rspamd. I issued the certificate for [mail.erdwerk-bioladen.de](http://mail.erdwerk-bioladen.de) with the SAN domains [imap.erdwerk-bioladen.de](http://imap.erdwerk-bioladen.de) and [smtp.erdwerk-bioladen.de](http://smtp.erdwerk-bioladen.de).
- Later I added a Nextcloud server. I issued a second certificate again using the Nginx mode. That worked fine at least one time as I gto a certifica. But that certificate was not renewed.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 10, 2024, 4:55pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate-tcp-port-80-is-already-used-by-nginx-pid/212854/8 "2024-03-10T16:55:02Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
