Cannot Renew - Server 2016 Exchange 2016

Server: Windows 2016
Web: On_Prem Exchange/IIS

My domain is: and 6 other subdomains.

I originally had a scheduled task to renew, but it started failing and I didn’t realize until it was too late. The autorenew command was wacs.exe --renew --baseuri “

Task output: Task Scheduler successfully completed task “\win-acme renew (” , instance “{78391ef9-7458-432a-b6a9-01756b0778a4}” , action “D:\LetsEncrypt\wacs.exe” with return code 2147516570.

When attempting to renew manually, I received the errors below.

Unable to refresh cached order: JWS has an invalid anti-replay nonce: “0002nSVfeD9rItOwtRbZWKWAJBVo9Wd_8tRTyhGCGjh7xmQ”
Cached authorization result for valid
Cached authorization result for valid
Cached authorization result for valid
Cached authorization result for valid
Cached authorization result for valid
Authorize identifier
Authorizing using http-01 validation (FileSystem)
Answer should now be browsable at
Preliminary validation failed, the server answered ‘(null)’ instead of ‘k367DSz4nlkg8z_BVPaL9Ued_BVq_cHGzaH2KEVTbiw.7iN1DWaYDPmQjyNvQ1ZwDZDQf8yaRRh8UGOO3AejmeE’. The ACME server might have a different perspective
“type”: “urn:ietf:params:acme:error:connection”,
“detail”: “Fetching Timeout during connect (likely firewall problem)”,
“status”: 400
Authorization result: invalid

I was using wacs.exe V2.1.7.807
Also tried using v2.1.8.835

Same issue, it will not renew, always get an error code with timeout. Firewall is off. Although that page is not browsable at all. I have never had to go to that page before so I cannot say whether it worked or not in the past.

Any help would be awesome! I have people breathing down my neck right now.


Hi @dmctools

a working port 80 is required to create a certificate if you want to use http validation.

Is there a webserver with that domain name and a port 80 binding defined?

If not, create one.

PS: Same with all of your other domains.


Did something change in the way wacs renews? This just started happening this month. It worked fine before and I never had to make available on port 80. it is only available via https.

Please read the basics.


Thank you,

I have created those subdomaind in IIS and they are viewable locally but it still fails. Do I need to temporarily open that up to the outside to validate? I see it creates the files for each sub, then removes them when it fails.

EDIT: I read the error/warning, yes it does.

They are accessable, but still cannot validate.
Type: unauthorized
Detail: Invalid response from
[]: "\r\n<html


I ended up switching from certbot back to wacs.exe and it worked.

Thank you!


Yep, now there is a http answer.

http validation -> working port 80 is required.


This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.