# Cannot renew certificate

**URL:** <https://community.letsencrypt.org/t/cannot-renew-certificate/139377>\
**Category:** Help\
**Created:** [November 30, 2020, 5:59am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377 "2020-11-30T05:59:00Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![pizza123](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pizza123](https://community.letsencrypt.org/u/pizza123)\
**Post date:** [November 30, 2020, 5:59am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/1 "2020-11-30T05:59:00Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [haphuongle.com](http://haphuongle.com)

I ran this command: sudo letsencrypt certonly -a manual --rsa-key-size 4096 --email "my email" -d haphuongle.comy

It produced this output:  
Waiting for verification...  
Cleaning up challenges  
Failed authorization procedure. [haphuongle.com](http://haphuongle.com) (http-01): urn:ietf:params:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://haphuongle.com/.well-known/acme-challenge/MP-4GcSlYdYqjtrlRqg1\_WNHG9g\_1yxHj8lGpROgtT8:](http://haphuongle.com/.well-known/acme-challenge/MP-4GcSlYdYqjtrlRqg1_WNHG9g_1yxHj8lGpROgtT8:) Timeout during connect (likely firewall problem)

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): nginx/1.14.2

The operating system my web server runs on is (include version):  
PRETTY\_NAME="Raspbian GNU/Linux 10 (buster)"  
NAME="Raspbian GNU/Linux"

My hosting provider, if applicable, is: Linux version 5.4.51-v7l+

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 0.31.0

I'm super new to web development and stuff so please be patient if I ask too much. Thank you

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [November 30, 2020, 6:45am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/2 "2020-11-30T06:45:40Z")

</div>

The problem is that it's not possible to connect to your domain on port 80.

Some of the causes for this problem are:

1. Your ISP (Verizon) blocking port 80 for your internet connection, in which case you should ask them about it.
2. You not having forwarded port 80 on your modem/router to your Raspberry Pi.
3. You not having opened port 80 on your Raspberry Pi's firewall.

---

<div class="post-metadata">

**Author:** ![pizza123](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pizza123](https://community.letsencrypt.org/u/pizza123)\
**Post date:** [November 30, 2020, 11:14pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/3 "2020-11-30T23:14:20Z")

</div>

I forwarded port 80 to my raspberry pi and allow it on firewall using **sudo ufw allow 80** but have this error:  
Failed authorization procedure. [haphuongle.com](http://haphuongle.com) (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://haphuongle.com/.well-known/acme-challenge/KNaey8BZ\_NgB7CBWs2Ju95WBOkoOBFFsnVvax-29e4A](http://haphuongle.com/.well-known/acme-challenge/KNaey8BZ_NgB7CBWs2Ju95WBOkoOBFFsnVvax-29e4A) [100.36.181.217]: "\r\n404 Not Found\r\n\<body bgcolor="white"\>\r\n

# 404 Not Found
\r\n
* * *
"

IMPORTANT NOTES:

- The following errors were reported by the server:

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [November 30, 2020, 11:44pm UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/4 "2020-11-30T23:44:26Z")

</div>

> [@pizza123](#):
>
> I forwarded port 80 to my raspberry pi and allow it on firewall using **sudo ufw allow 80** but have this error

Progress 👏!

What authenticator are you using? Still `-a manual`?

Have you tried `--nginx` instead?

---

<div class="post-metadata">

**Author:** ![pizza123](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pizza123](https://community.letsencrypt.org/u/pizza123)\
**Post date:** [December 1, 2020, 12:46am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/6 "2020-12-01T00:46:30Z")

</div>

When I use —nginx instead of -a manual, it shows:  
Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Could not choose appropriate plugin: The requested nginx plugin does not appear to be installed.

But I think nginx has been installed already

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [December 1, 2020, 12:51am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/7 "2020-12-01T00:51:11Z")

</div>

For your Raspbian installation, I believe you can install the nginx plugin using:

```
sudo apt install python-certbot-nginx

```

and then the previous command should work.

---

<div class="post-metadata">

**Author:** ![pizza123](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pizza123](https://community.letsencrypt.org/u/pizza123)\
**Post date:** [December 1, 2020, 1:27am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/8 "2020-12-01T01:27:53Z")

</div>

It says congratulations but when I go to my website, the certificate is not updated yet. Am I supposed to wait a few hours or days for the update?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [December 1, 2020, 1:37am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/9 "2020-12-01T01:37:56Z")

</div>

Try run the command without `certonly`.

`certonly` means "obtain the certificate but don't install it, I'll do that myself".

By omitting it, Certbot will also install your certificate and reload your webserver for you. It will also do so automatically in future.

---

<div class="post-metadata">

**Author:** ![pizza123](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pizza123](https://community.letsencrypt.org/u/pizza123)\
**Post date:** [December 1, 2020, 2:33am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/10 "2020-12-01T02:33:28Z")

</div>

It works. Thank you so so much! I have a question tho. If I use certonly in the command, what should I do next to reload the cert to my website?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [December 1, 2020, 2:36am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/11 "2020-12-01T02:36:15Z")

</div>

By using `certonly`, the main thing that is missing is the reload of your nginx server, which needs to be performed after every renewal:

```
sudo service nginx reload
```

---

<div class="post-metadata">

**Author:** ![pizza123](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pizza123](https://community.letsencrypt.org/u/pizza123)\
**Post date:** [December 1, 2020, 2:45am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/12 "2020-12-01T02:45:36Z")

</div>

Thank you so much for your help! Really appreciate!!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 31, 2020, 2:50am UTC](https://community.letsencrypt.org/t/cannot-renew-certificate/139377/13 "2020-12-31T02:50:05Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
