# Certbot does now know how to configure my Apache webserver

**URL:** <https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921>\
**Category:** Help\
**Created:** [July 17, 2021, 4:40pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921 "2021-07-17T16:40:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 17, 2021, 4:40pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/1 "2021-07-17T16:40:08Z")

</div>

My domain is: eclipseofbutterflies.ml

I ran this command:: sudo certbot

It produced this output: Certbot doesn't know how to automatically configure the web server on this system. However, it can still get a certificate for you. Please run "certbot certonly" to do so. You'll need to manually configure your web server to use the resulting certificate.

My web server is (include version): Apache/ 2.4.41

The operating system my web server runs on is (include version): Linux Mint 20.2 Uma

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

The version of my client is: certbot 1.17.0

Copy of let's encrypt log just in case it is needed [Ubuntu Pastebin](https://pastebin.ubuntu.com/p/J8ZTWbBWYy/)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 17, 2021, 5:13pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/2 "2021-07-17T17:13:20Z")

</div>

The letsencrypt.log file still shows your syntax error.. I guess it wasn't fixed after all?

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 17, 2021, 5:20pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/3 "2021-07-17T17:20:08Z")

</div>

It was fixed it's just that there was nothing new logged now that I look at it. atleast I think so

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 17, 2021, 5:25pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/4 "2021-07-17T17:25:05Z")

</div>

I believe the syntax error is still there. It wouldn't make any sense for certbot to log _nothing at all_ when it encounters a rather regular error.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 17, 2021, 6:12pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/5 "2021-07-17T18:12:13Z")

</div>

I use the following regular expression in my text editor when I search help-seekers' configuration files for improper characters:

```nohighlight
[^\w \n(){}\[\]'"#\\@!$&%.^~?=;/,+\|<>*:-]

```

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 17, 2021, 6:16pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/6 "2021-07-17T18:16:53Z")

</div>

@griffin If you want to take a shot at @ScarletDevil25 s Apache configuration at [The error was: PluginError('There has been an error in parsing the file /etc/apache2/sites-enabled/ssl-eclipseofbutterflies.ml.conf on line 132: Syntax error')](https://community.letsencrypt.org/t/the-error-was-pluginerror-there-has-been-an-error-in-parsing-the-file-etc-apache2-sites-enabled-ssl-eclipseofbutterflies-ml-conf-on-line-132-syntax-error/155914) please be my guest.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 17, 2021, 6:18pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/7 "2021-07-17T18:18:07Z")

</div>

I saw it, but I'm running now. 🙁 I'll check into it once I can.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 17, 2021, 8:24pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/8 "2021-07-17T20:24:31Z")

</div>

1. Remove the cruft.

```nohighlight
sudo rm /etc/apache2/sites-available/ssl-eclipseofbutterflies.ml.conf

```

1. Install your clean configuration file.

Download this:  
[ssl-eclipseofbutterflies.ml.conf.txt](https://community.letsencrypt.org/uploads/short-url/6qNIr1dtzi3rgr6fqfolvDTJdgm.txt) (1.1 KB)

Put it here:  
`/etc/apache2/sites-available`

Run this:

```nohighlight
sudo mv /etc/apache2/sites-available/ssl-eclipseofbutterflies.ml.conf.txt /etc/apache2/sites-available/ssl-eclipseofbutterflies.ml.conf

```

1. Reload Apache.

```nohighlight
sudo apachectl -k graceful

```

1. Run certbot.

```nohighlight
sudo certbot --apache -d "eclipseofbutterflies.ml,www.eclipseofbutterflies.ml"

```

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 17, 2021, 10:53pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/9 "2021-07-17T22:53:54Z")

</div>

hmm would it be possible for me to use a wildcard with running certbot, I'll try the new config when I get home

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 17, 2021, 11:16pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/10 "2021-07-17T23:16:17Z")

</div>

Yes. Keep in mind though that certification of a wildcard domain name can only be automated by fulfilling a [dns-01 challenge](https://letsencrypt.org/docs/challenge-types/#dns-01-challenge) via a [dns-plugin](https://certbot.eff.org/docs/using.html#dns-plugins) whereas certification of a non-wildcard domain name can also be automated by fulfilling an [http-01 challenge](https://letsencrypt.org/docs/challenge-types/#http-01-challenge) via the [apache](https://certbot.eff.org/docs/using.html#apache), [nginx](https://certbot.eff.org/docs/using.html#nginx), [webroot](https://certbot.eff.org/docs/using.html#webroot), or [standalone](https://certbot.eff.org/docs/using.html#standalone) authenticators.

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 17, 2021, 11:18pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/11 "2021-07-17T23:18:54Z")

</div>

What would the command be if my DNS provider is Cloudflare.?

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 17, 2021, 11:21pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/12 "2021-07-17T23:21:49Z")

</div>

There is a [certbot dns-plugin for Cloudflare](https://certbot-dns-cloudflare.readthedocs.io/). Before you go that route though, are you intending to use Cloudflare's content delivery network (CDN) where Cloudflare acts as a reverse proxy for your webserver?

If so, I highly recommend reading how TLS/SSL works with Cloudflare:

> **[End-to-end HTTPS with Cloudflare - Part 1: conceptual overview](https://support.cloudflare.com/hc/en-us/articles/360024787372-End-to-end-HTTPS-with-Cloudflare-Part-1-conceptual-overview)**
>
> Learn to configure end-to-end HTTPS encryption for website traffic protected by Cloudflare.
> Overview
> Step 1 - Choose a Cloudflare SSL certificate
> Step 2 - Configure an SSL certificate at your origi...

You would probably be better off using a [Cloudflare Origin CA certificate](https://developers.cloudflare.com/ssl/origin-configuration/origin-ca) rather than a Let's Encrypt certificate.

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 18, 2021, 4:11pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/13 "2021-07-18T16:11:55Z")

</div>

I do use Cloudflare as a reverse proxy but I would still like to use Let's Encrypt as my cert provider for my origin server

```nohighlight
sudo certbot --apache -d "*eclipseofbutterflies.ml" --dns-cloudflare-credentials

```

Would this be the correct command?

or this?

```nohighlight
sudo certbot --dns-cloudflare-credentials -d "*eclipseofbutterflies.ml"

```

I had to fix all my SSL configs apparently

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 18, 2021, 5:45pm UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/14 "2021-07-18T17:45:29Z")

</div>

> [@ScarletDevil25](#):
>
> `*eclipseofbutterflies.ml`

Are you meaning `*.eclipseofbutterflies.ml` ?

First, run these to install certbot-dns-cloudflare:

```nohighlight
sudo snap install core

sudo snap refresh core

sudo snap set certbot trust-plugin-with-root=ok

sudo snap install certbot-dns-cloudflare

```

Then, read the [certbot-dns-cloudflare instructions](https://certbot-dns-cloudflare.readthedocs.io/).

You will probably use a certbot command that will acquire your certificate via certbot-dns-cloudflare and install your certificate into Apache, like this:

```nohighlight
sudo certbot -a dns-cloudflare --dns-cloudflare-credentials ~/.secrets/certbot/cloudflare.ini --dns-cloudflare-propagation-seconds 60 -d "eclipseofbutterflies.ml,*.eclipseofbutterflies.ml" -i apache

```

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 19, 2021, 12:18am UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/15 "2021-07-19T00:18:58Z")

</div>

Interesting. my googling led me to install the plugin using python, I didn't realize there was a snap version

Running the commands give me this error, researching online it said to place the text`ini file on

`/etc/letsencrypt/`

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/7/b/7b9b0bd443b563cb5feed54c003aca1d9f89fd3c.png)

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 19, 2021, 12:24am UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/16 "2021-07-19T00:24:28Z")

</div>

Out of curiosity, what is the output of:

`sudo certbot certonly --dns-cloudflare --dns-cloudflare-credentials ~/.secrets/certbot/cloudflare.ini --dns-cloudflare-propagation-seconds 60 -d "eclipseofbutterflies.ml,*.eclipseofbutterflies.ml" --dry-run`

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 19, 2021, 12:26am UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/17 "2021-07-19T00:26:46Z")

</div>

Here you go

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/8/d/8d9eca3618ec1f063f78e43415955eee90e5ecb2.png)

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 19, 2021, 12:27am UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/18 "2021-07-19T00:27:56Z")

</div>

Do you have the snap version of certbot installed?

---

<div class="post-metadata">

**Author:** ![ScarletDevil25](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/scarletdevil25/32/51223_2.png) [@ScarletDevil25](https://community.letsencrypt.org/u/ScarletDevil25)\
**Post date:** [July 19, 2021, 12:29am UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/19 "2021-07-19T00:29:57Z")

</div>

According to snap yes but let me just remove the python version I installed and try again

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 19, 2021, 12:32am UTC](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921/20 "2021-07-19T00:32:08Z")

</div>

Make sure to run these in this order:

```nohighlight
sudo snap install core

sudo snap refresh core

sudo snap set certbot trust-plugin-with-root=ok

sudo snap install certbot-dns-cloudflare

```

You need to remove ALL non-snap certbot packages first.

[Next page](https://community.letsencrypt.org/t/certbot-does-now-know-how-to-configure-my-apache-webserver/155921.md?page=2)
