Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: stepmodifications.org
I ran this command: certbot renew --dry-run
It produced this output:
IMPORTANT NOTES:
-
The following errors were reported by the server:
Domain: stepmodifications.org
Type: unauthorized
Detail: Invalid response from
http://stepmodifications.org/.well-known/acme-challenge/JlrUGjnsy-z1vzWVYCgcOQzWBv-hJcgpMw8T41zdoC4
[138.197.49.211]: "\r\n403
Forbidden\r\n\r\n403
\r\n
Forbidden
nginx\r\n"To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address. -
The following errors were reported by the server:
Domain: www.stepmodifications.org
Type: unauthorized
Detail: Invalid response from
http://www.stepmodifications.org/.well-known/acme-challenge/mStaMQ-aG9GmTFf9uxexhb8XT4CSVq4pRsF5ztloMGc
[138.197.49.211]: "\r\n403
Forbidden\r\n\r\n403
\r\n
Forbidden
nginx\r\n"To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
My web server is (include version): nginx 1.19.6
The operating system my web server runs on is (include version): CentOS 7
My hosting provider, if applicable, is: DigitalOcean
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): n/a shell only
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): 1.10.1
I have been running Certbot to renew my Letsencrypt certs for a few years now, so my config is 'good'. The issue seems to have begun on Dec 24, 2020 as determined from the logs. I renew via cron task, which worked for about a year on this server up to that point. I use the same method on another server (past 2 years) and have had no issues there.
Note that my server is IP restricted, so if anyone wants to help, I will need to clear your IP or IP range.
Thanks in advance!