Certbot renew problem on some domain

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:taldap.de

I ran this command:certbot-auto renew --dry-run --cert-name taldap.de

It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log


Processing /etc/letsencrypt/renewal/taldap.de.conf


Cert is due for renewal, auto-renewing…
Plugins selected: Authenticator webroot, Installer None
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for taldap.de
http-01 challenge for www.taldap.de
Waiting for verification…
Challenge failed for domain taldap.de
Challenge failed for domain www.taldap.de
http-01 challenge for taldap.de
http-01 challenge for www.taldap.de
Cleaning up challenges
Attempting to renew cert (taldap.de) from /etc/letsencrypt/renewal/taldap.de.conf produced an unexpected error: Some challenges have failed… Skipping.
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/taldap.de/fullchain.pem (failure)


** DRY RUN: simulating ‘certbot renew’ close to cert expiry
** (The test certificates below have not been saved.)

All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/taldap.de/fullchain.pem (failure)
** DRY RUN: simulating ‘certbot renew’ close to cert expiry
** (The test certificates above have not been saved.)


1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:

My web server is (include version):Server version: Apache/2.4.10 (Debian)

The operating system my web server runs on is (include version):Debian GNU/Linux 8 (jessie)

My hosting provider, if applicable, is:ovh.net

I can login to a root shell on my machine (yes or no, or I don’t know):yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot):certbot 0.40.1

Hi @pauldon2

there are a lot of redirects to argusoft.de - https://check-your-website.server-daten.de/?q=taldap.de

Sample:

http://taldap.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
54.36.119.183
302
	http://www.argusoft.de/taldap.html.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

So it's impossible that Letsencrypt checks your validation file. Or runs argusoft.de on the same server?

Yes. This is the same sever.

But why is there such a curious redirect? It’s your software? Letsencrypt must find the validation file.

This is just another virtual server.

Please read some basics about challenge types.

You have to remove that curious redirect.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.