Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: hiconv.com
I ran this command: certbot renew
It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Processing /etc/letsencrypt/renewal/docs.hiconv.com.conf
Cert not yet due for renewal
Processing /etc/letsencrypt/renewal/admin.hiconv.com.conf
Cert not yet due for renewal
Processing /etc/letsencrypt/renewal/hiconv.com.conf
Cert is due for renewal, auto-renewing…
Renewing an existing certificate
Performing the following challenges:
tls-sni-01 challenge for hiconv.com
nginx: [warn] conflicting server name “hiconv.com” on 0.0.0.0:80, ignored
nginx: [warn] conflicting server name “hiconv.com” on 0.0.0.0:443, ignored
Waiting for verification…
Cleaning up challenges
nginx: [warn] conflicting server name “hiconv.com” on 0.0.0.0:80, ignored
nginx: [warn] conflicting server name “hiconv.com” on 0.0.0.0:443, ignored
Attempting to renew cert (hiconv.com) from /etc/letsencrypt/renewal/hiconv.com.conf produced an unexpected error: Failed authorization procedure. hiconv.com (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for tls-sni-01 challenge. Requested 9860c77fc499d68357f14c6a72770bd6.c82c209c5b0012f63f3c3209ced0a9e6.acme.invalid from 95.85.40.77:443. Received 2 certificate(s), first certificate had names “admin.hiconv.com”. Skipping.
The following certs are not due for renewal yet:
/etc/letsencrypt/live/docs.hiconv.com/fullchain.pem (skipped)
/etc/letsencrypt/live/becausejavascript.com/fullchain.pem (skipped)
/etc/letsencrypt/live/admin.hiconv.com/fullchain.pem (skipped)
/etc/letsencrypt/live/wiki.hiconv.com/fullchain.pem (skipped)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/hiconv.com/fullchain.pem (failure)
1 renew failure(s), 0 parse failure(s)
IMPORTANT NOTES:
-
The following errors were reported by the server:
Domain: hiconv.com
Type: unauthorized
Detail: Incorrect validation certificate for tls-sni-01 challenge.
Requested
9860c77fc499d68357f14c6a72770bd6.c82c209c5b0012f63f3c3209ced0a9e6.acme.invalid
from 95.85.40.77:443. Received 2 certificate(s), first certificate
had names “admin.hiconv.com”To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
My web server is (include version): nginx/1.6.2
The operating system my web server runs on is (include version): Ubuntu 14.04.5 LTS
My hosting provider, if applicable, is: DigitalOcean
I can login to a root shell on my machine (yes or no, or I don’t know): yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no