I'm using OpenSuse LEAP 15.4 with an Apache webserver. Certbot is working but I am getting some curious errors. Even though it says it failed, the certificate seems to be renewed as the browser displays the website correctly.
The errors are a bit confusing as it shows failed then later succeeded. Should these errors be fixed or should I ignore them?
safeandtacticalfirearmstraining:/run/media/geno/Data/Library/Reference/Technical/Computing/Software - Linux/OpenSuse/Let's Encrypt renewal # certbot -v renew
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/stft.ddns.net.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate is due for renewal, auto-renewing...
ssl_module is statically linked but --apache-bin is missing; not disabling session tickets.
Plugins selected: Authenticator apache, Installer apache
Renewing an existing certificate for stft.ddns.net
Performing the following challenges:
http-01 challenge for stft.ddns.net
Waiting for verification...
Cleaning up challenges
Reloading apache server after certificate renewal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/www.safeandtacticalfirearmstraining.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate is due for renewal, auto-renewing...
ssl_module is statically linked but --apache-bin is missing; not disabling session tickets.
Plugins selected: Authenticator apache, Installer apache
Renewing an existing certificate for www.safeandtacticalfirearmstraining.com and safeandtacticalfirearmstraining.com
Performing the following challenges:
http-01 challenge for safeandtacticalfirearmstraining.com
http-01 challenge for www.safeandtacticalfirearmstraining.com
Waiting for verification...
Challenge failed for domain safeandtacticalfirearmstraining.com
Challenge failed for domain www.safeandtacticalfirearmstraining.com
http-01 challenge for safeandtacticalfirearmstraining.com
http-01 challenge for www.safeandtacticalfirearmstraining.com
Certbot failed to authenticate some domains (authenticator: apache). The Certificate Authority reported these problems:
Domain: safeandtacticalfirearmstraining.com
Type: unauthorized
Detail: 3.33.251.168: Invalid response from http://safeandtacticalfirearmstraining.com/.well-known/acme-challenge/l7PsJf7tWmFeVtItoco4PL7H6Rqr2S63IjgHdPN1Hf8: 403
Domain: www.safeandtacticalfirearmstraining.com
Type: unauthorized
Detail: 3.33.251.168: Invalid response from http://www.safeandtacticalfirearmstraining.com/.well-known/acme-challenge/h34FM8vICtxP_COVhVX1wMZ7a20L0nxWy4px2k7EG3c: 403
Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet.
Cleaning up challenges
Failed to renew certificate www.safeandtacticalfirearmstraining.com with error: Some challenges have failed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The following renewals succeeded:
/etc/letsencrypt/live/stft.ddns.net/fullchain.pem (success)
The following renewals failed:
/etc/letsencrypt/live/www.safeandtacticalfirearmstraining.com/fullchain.pem (failure)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1 renew failure(s), 0 parse failure(s)
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.