# Certficate for email domain mail.mydomain.nl

**URL:** <https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512>\
**Category:** Uncategorized\
**Created:** [May 9, 2016, 6:52pm UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512 "2016-05-09T18:52:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![arjenmeijer](https://avatars.discourse-cdn.com/v4/letter/a/779978/32.png) [@arjenmeijer](https://community.letsencrypt.org/u/arjenmeijer)\
**Post date:** [May 9, 2016, 6:52pm UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/1 "2016-05-09T18:52:47Z")

</div>

Oke, I am trying to generate a certificate for my [mail.mydomain.nl](http://mail.mydomain.nl) email (dovecot and postfix) server.

I took some time to find that the command ./letsencrypt certonly … does not work. Use always ./letsencrypt-auto certonly … .

I have access to my webserver as root and used the command:

/opt/letsencrypt# sudo ./letsencrypt-auto certonly --webroot -w /var/www/html/mydomain.nl -d [mail.mydomain.nl](http://mail.mydomain.nl)

The response is:

Checking for new version…  
Requesting root privileges to run letsencrypt…  
/root/.local/share/letsencrypt/bin/letsencrypt certonly --webroot -w /var/www/html/mydomain.nl -d [mail.mydomain.nl](http://mail.mydomain.nl)  
Failed authorization procedure. [mail.mydomain.nl](http://mail.mydomain.nl) (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://mail.mydomain.nl/.well-known/acme-challenge/0il40p8ufdlJ08H-6CX5-BJKcXdo7I-V-iUAQma2Fjo](http://mail.mydomain.nl/.well-known/acme-challenge/0il40p8ufdlJ08H-6CX5-BJKcXdo7I-V-iUAQma2Fjo) [[46.xxx.xxx.xxx](http://46.xxx.xxx.xxx)]: 404

IMPORTANT NOTES:

- The following errors were reported by the server:

Which is correct, because the domain [mail.mydomain.nl](http://mail.mydomain.nl) is no webserver, but a mail server. A mail server has a MX record and No DNS A record.

So, now I am lost. The point of getting a certificate only, is to use the certificate elsewhere, isn’t it. Is it posible to get a mail cdrtificate at all? I am a little bit confused.

How can I get a certificate for [mail.mydomain.nl](http://mail.mydomain.nl)?

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [May 9, 2016, 7:00pm UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/2 "2016-05-09T19:00:32Z")

</div>

To obtain a certificate you either need to use a webserver (in which case [mail.mydomain.nl](http://mail.mydomain.nl) needs to respond on port 80 - using your current webserver, or stopping it and using the built in webserver in the letsencrypt client ) or using the DNS challenge ( whereby the challenge token is presented by DNS rather than http. The current official client doesn’t support the DNS challenge yet, but the alternative clients do.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [May 9, 2016, 8:53pm UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/3 "2016-05-09T20:53:52Z")

</div>

> [@arjenmeijer](#):
>
> Which is correct, because the domain mail.mydomain.nl is no webserver, but a mail server. A mail server has a MX record and No DNS A record.

Not quite. You should have `mydomain.nl IN MX 10 mail.mydomain.nl`, i.e., the MX record for your "main" domain points to the A record of `mail.mydomain.nl`. And `mail.mydomain.nl` probably resolves to the same IP as `www.mydomain.nl`.

The question is: how's your webserver configured? What kind of `VirtualHosts` does it have? What happenes when you point to `mail.mydomain.nl` in your browser? Do you get the same website as `www.mydomain.nl`? Or some kind of error?

---

<div class="post-metadata">

**Author:** ![DarkSteve](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/darksteve/32/1050_2.png) [@DarkSteve](https://community.letsencrypt.org/u/DarkSteve)\
**Post date:** [May 9, 2016, 11:29pm UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/4 "2016-05-09T23:29:26Z")

</div>

I created a certificate for my (postfix/dovecot) mail server using certonly and webroot authentication. However the same domains I use for mail also direct to my webserver.

Postfix accepts mail from [darksteve.tk](http://darksteve.tk) and [mail.darksteve.tk](http://mail.darksteve.tk). But port 80 and 443 goes to my landing page ([darksteve.tk](http://darksteve.tk)) and Roundcube ([mail.darksteve.tk](http://mail.darksteve.tk)). Because I have an active webserver for those domains, webroot works.

However if you don’t have such a setup, you’ll have to use DNS or standalone mode to create the certs. But standalone requires you shutdown any running webserver to authenticate and the official client doesn’t yet support DNS!

I’d take a look at NeilPang’s [acme.sh](http://acme.sh) client and see if DNS authentication works for you.

Good luck!

---

<div class="post-metadata">

**Author:** ![arjenmeijer](https://avatars.discourse-cdn.com/v4/letter/a/779978/32.png) [@arjenmeijer](https://community.letsencrypt.org/u/arjenmeijer)\
**Post date:** [May 10, 2016, 6:26am UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/5 "2016-05-10T06:26:22Z")

</div>

So we have two options. Option 1: make a virtual server for [mail.mydomain.nl](http://mail.mydomain.nl) and keep it running for the renewal of the certificate. Or make use of the built in webserver. But what happens with renewal of the certificate in this case?

---

<div class="post-metadata">

**Author:** ![arjenmeijer](https://avatars.discourse-cdn.com/v4/letter/a/779978/32.png) [@arjenmeijer](https://community.letsencrypt.org/u/arjenmeijer)\
**Post date:** [May 10, 2016, 6:30am UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/6 "2016-05-10T06:30:51Z")

</div>

I am getting a certificate error. [mail.mydomain.nl](http://mail.mydomain.nl) differs with [www.mydomain.nl](http://www.mydomain.nl). After accepting the certificate the default website shows.

Can I conclude that the certificate of [www.mydomain.nl](http://www.mydomain.nl) prevents a ‘handsake’ with [mail.mydomain.nl](http://mail.mydomain.nl)?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [May 10, 2016, 6:32am UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/7 "2016-05-10T06:32:58Z")

</div>

You could also make the [mail.mydomain.nl](http://mail.mydomain.nl) virtualhost a reverse proxy to localhost on another port. Although Boulder will always try to connect to port 80 or 443 (depending on the challenge type), you can instruct the client in standalone mode to listen on another port. That way you don’t have to serve a complete page/site on [mail.mydomain.nl](http://mail.mydomain.nl) (although you’d need to generate a virtualhost section) and renewal would work.

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [May 10, 2016, 6:35am UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/8 "2016-05-10T06:35:35Z")

</div>

> [@arjenmeijer](#):
>
> Or make use of the built in webserver. But what happens with renewal of the certificate in this case?

You would need to do the same as at creation. Shut down the main server, and use the standalone version for renewal. Hence personally I'd either use the first method ( a virtual sever for mail.mydomain.nl -- purely used for the .well-known/acme-challenge/token ) which can then make everything automated ( as can the DNS challenge method).

---

<div class="post-metadata">

**Author:** ![arjenmeijer](https://avatars.discourse-cdn.com/v4/letter/a/779978/32.png) [@arjenmeijer](https://community.letsencrypt.org/u/arjenmeijer)\
**Post date:** [May 10, 2016, 6:59am UTC](https://community.letsencrypt.org/t/certficate-for-email-domain-mail-mydomain-nl/15512/9 "2016-05-10T06:59:30Z")

</div>

> [@Osiris](#):
>
> You could also make the mail.mydomain.nl virtualhost a reverse proxy to localhost on another port. Although Boulder will always try to connect to port 80 or 443 (depending on the challenge type), you can instruct the client in standalone mode to listen on another port. That way you don't have to serve a complete page/site on mail.mydomain.nl (although you'd need to generate a virtualhost section) and renewal would work.

Can you give an example of the config of a virtual host in Apache2 with a reverse proxy? That makes it possible to comprehend what you are saying.
