Cannot renew certificate

My domain is: nextcloud.martinschmitz.de

I ran this command:

I use ownyourbits / nextcloud image and I requested a cert renewal from the GUI
If I go to the URL that has failed, I get an certificate error (who would have thought that?!?! ) :slight_smile:

It fine worked a long time, no changes to firewall rules made?!?

It produced this output:

[ letsencrypt ]
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator webroot, Installer None
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for nextcloud.martinschmitz.de
Using the webroot path /var/www/nextcloud for all unmatched domains.
Waiting for verification…
Cleaning up challenges
Failed authorization procedure. nextcloud.martinschmitz.de (http-01): urn:ietf:params:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching http://nextcloud.martinschmitz.de/.well-known/acme-challenge/CmIdWobANfPY_-xxxxxxxxxx: Connection refused
IMPORTANT NOTES:

  • The following errors were reported by the server:

Domain: nextcloud.martinschmitz.de
Type: connection
Detail: Fetching
http://nextcloud.martinschmitz.de/.well-known/acme-challenge/CmIdWobANfPY_-XXXXXXXXXXXXXXXXXXXXX:
Connection refused

To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address. Additionally, please check that
your computer has a publicly routable IP address and that no
firewalls are preventing the server from communicating with the
client. If you’re using the webroot plugin, you should also verify
that you are serving files from the webroot path you provided.

Cannot access

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): yes

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): 0.31.0

Any help appreciated!!!
Thanks
Miles

Your port 80 needs to be open (and forwarded appropriately) for the http-01 challenge to work. And I see nothing responding on your port 80.

2 Likes

Thanks! I have no idea why http was lost?!? Mystery! Thanks a lot!

2 Likes