Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: mail.prospectid.com
I ran this command: certbot renew
It produced this output:
BlockquoteSaving debug log to /var/log/letsencrypt/letsencrypt.log
Processing /etc/letsencrypt/renewal/mail.prospectid.com.conf
Renewing an existing certificate for mail.prospectid.com
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
Domain: mail.prospectid.com
Type: unauthorized
Detail: Invalid response from http://mail.prospectid.com/.well-known/acme-challenge/smHen8-f-yytxFedUShAOg1FxlH1QXofSfeHipG6tB4 [173.255.231.79]: "\r\n404 Not Found\r\n<body bgcolor="white">\r\n
404 Not Found
\r\n"
Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.
Failed to renew certificate mail.prospectid.com with error: Some challenges have failed.
All renewals failed. The following certificates could not be renewed:
/etc/letsencrypt/live/mail.prospectid.com/fullchain.pem (failure)
1 renew failure(s), 0 parse failure(s)
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
Blockquote
My web server is (include version): nginx
The operating system my web server runs on is (include version):
CentOS Linux release 8.5.2111
My hosting provider, if applicable, is: Linode
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): certbot 1.20.0
I am running a mail server with iRedMail installed. Everything worked fine until certificate expired. Cannot get certificate renewed. If I do certbot -v I get the following:
certbot -v
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator nginx, Installer nginx
Which names would you like to activate HTTPS for?
Select the appropriate numbers separated by commas and/or spaces, or leave input
Also see this: https://www.whynopadlock.com/results/8f33dcfd-c344-4b3b-9e1d-452f06f8bd07