# Certificate Verify Failed

**URL:** <https://community.letsencrypt.org/t/certificate-verify-failed/64848>\
**Category:** Help\
**Created:** [June 20, 2018, 2:11pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848 "2018-06-20T14:11:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![tabl](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@tabl](https://community.letsencrypt.org/u/tabl)\
**Post date:** [June 20, 2018, 2:11pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/1 "2018-06-20T14:11:23Z")

</div>

Hi everyone!

I installed certbot and obtained certificate a couple of months ago, but it suddenly stopped getting updated certificates.

What should I do in this case?

I’m getting this output after running  
`sudo certbot --nginx -d my.domain.com`

```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator nginx, Installer nginx
An unexpected error occurred:
Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/urllib3/contrib/pyopenssl.py", line 438, in wrap_socket
    cnx.do_handshake()
  File "/usr/lib/python3/dist-packages/OpenSSL/SSL.py", line 1716, in do_handshake
    self._raise_ssl_error(self._ssl, result)
  File "/usr/lib/python3/dist-packages/OpenSSL/SSL.py", line 1456, in _raise_ssl_error
    _raise_current_error()
  File "/usr/lib/python3/dist-packages/OpenSSL/_util.py", line 54, in exception_from_error_queue
    raise exception_type(errors)
OpenSSL.SSL.Error: [('SSL routines', 'ssl3_get_server_certificate', 'certificate verify failed')]

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 600, in urlopen
    chunked=chunked)
  File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 345, in _make_request
    self._validate_conn(conn)
  File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 846, in _validate_conn
    conn.connect()
  File "/usr/lib/python3/dist-packages/urllib3/connection.py", line 326, in connect
    ssl_context=context)
  File "/usr/lib/python3/dist-packages/urllib3/util/ssl_.py", line 325, in ssl_wrap_socket
    return context.wrap_socket(sock, server_hostname=server_hostname)
  File "/usr/lib/python3/dist-packages/urllib3/contrib/pyopenssl.py", line 445, in wrap_socket
    raise ssl.SSLError('bad handshake: %r' % e)
ssl.SSLError: ("bad handshake: Error([('SSL routines', 'ssl3_get_server_certificate', 'certificate verify failed')],)",)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/requests/adapters.py", line 440, in send
    timeout=timeout
  File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 630, in urlopen
    raise SSLError(e)
urllib3.exceptions.SSLError: ("bad handshake: Error([('SSL routines', 'ssl3_get_server_certificate', 'certificate verify failed')],)",)

During handling of the above exception, another exception occurred:

requests.exceptions.SSLError: ("bad handshake: Error([('SSL routines', 'ssl3_get_server_certificate', 'certificate verify failed')],)",)
Please see the logfiles in /var/log/letsencrypt for more details.
```

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 20, 2018, 3:37pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/2 "2018-06-20T15:37:31Z")

</div>

Hi @tabl

> [@tabl](#):
>
> Please see the logfiles in /var/log/letsencrypt for more details.

what's your domain? Is your Certbot updated?

What is there:

> Please see the logfiles in /var/log/letsencrypt for more details.

---

<div class="post-metadata">

**Author:** ![tabl](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@tabl](https://community.letsencrypt.org/u/tabl)\
**Post date:** [June 20, 2018, 4:08pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/3 "2018-06-20T16:08:22Z")

</div>

The domain is [wifi.enslave.ru](http://wifi.enslave.ru)  
Certbot version is 0.22.2-1 on Ubuntu 16.04

Log:  
2018-06-20 14:13:27,687:DEBUG:certbot.main:certbot version: 0.22.2  
2018-06-20 14:13:27,687:DEBUG:certbot.main:Arguments: [’–nginx’, ‘–dry-run’]  
2018-06-20 14:13:27,688:DEBUG:certbot.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#nginx,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)  
2018-06-20 14:13:27,696:DEBUG:certbot.log:Root logging level set at 20  
2018-06-20 14:13:27,697:INFO:certbot.log:Saving debug log to /var/log/letsencrypt/letsencrypt.log  
2018-06-20 14:13:27,705:DEBUG:certbot.plugins.selection:Requested authenticator nginx and installer nginx  
2018-06-20 14:13:27,706:DEBUG:certbot.cli:Var dry\_run=True (set by user).  
2018-06-20 14:13:27,706:DEBUG:certbot.cli:Var server={‘dry\_run’, ‘staging’} (set by user).  
2018-06-20 14:13:27,706:DEBUG:certbot.cli:Var account={‘server’} (set by user).  
2018-06-20 14:13:27,706:DEBUG:certbot.cli:Var authenticator=nginx (set by user).  
2018-06-20 14:13:27,706:DEBUG:certbot.cli:Var installer=nginx (set by user).  
2018-06-20 14:13:27,732:DEBUG:certbot.storage:Should renew, less than 30 days before certificate expiry 2018-07-04 07:18:45 UTC.  
2018-06-20 14:13:27,732:INFO:certbot.renewal:Cert is due for renewal, auto-renewing…  
2018-06-20 14:13:27,733:DEBUG:certbot.plugins.selection:Requested authenticator nginx and installer nginx  
2018-06-20 14:13:27,888:DEBUG:certbot.plugins.selection:Single candidate plugin: \* nginx  
Description: Nginx Web Server plugin - Alpha  
Interfaces: IAuthenticator, IInstaller, IPlugin  
Entry point: nginx = certbot\_nginx.configurator:NginxConfigurator  
Initialized: \<certbot\_nginx.configurator.NginxConfigurator object at 0x7fdbff997ba8\>  
Prep: True  
2018-06-20 14:13:27,890:DEBUG:certbot.plugins.selection:Single candidate plugin: \* nginx  
Description: Nginx Web Server plugin - Alpha  
Interfaces: IAuthenticator, IInstaller, IPlugin  
Entry point: nginx = certbot\_nginx.configurator:NginxConfigurator  
Initialized: \<certbot\_nginx.configurator.NginxConfigurator object at 0x7fdbff997ba8\>  
Prep: True  
2018-06-20 14:13:27,890:DEBUG:certbot.plugins.selection:Selected authenticator \<certbot\_nginx.configurator.NginxConfigurator object at 0x7fdbff997ba8\> and installer \<certbot\_nginx.configurator.NginxConfigurator object at 0x7fdbff997ba8\>  
2018-06-20 14:13:27,890:INFO:certbot.plugins.selection:Plugins selected: Authenticator nginx, Installer nginx  
2018-06-20 14:13:27,905:DEBUG:certbot.main:Picked account: \<Account(RegistrationResource(uri=‘[https://acme-staging-v02.api.letsencrypt.org/acme/acct/5868658](https://acme-staging-v02.api.letsencrypt.org/acme/acct/5868658)’, new\_authzr\_uri=None, terms\_of\_service=‘[https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf](https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf)’, body=Registration(key=JWKRSA(key=\<ComparableRSAKey(\<cryptography.hazmat.backends.openssl.rsa.\_RSAPublicKey object at 0x7fdbff909828\>)\>), agreement=None, status=‘valid’, contact=(), terms\_of\_service\_agreed=None)), a1feb7a10613229dc44c412145d537bb, Meta(creation\_host=‘[ovz2.enslave.z2eez.vps.myjino.ru](http://ovz2.enslave.z2eez.vps.myjino.ru)’, creation\_dt=datetime.datetime(2018, 4, 5, 8, 20, 3, tzinfo=)))\>  
2018-06-20 14:13:27,906:DEBUG:acme.client:Sending GET request to [https://acme-staging-v02.api.letsencrypt.org/directory](https://acme-staging-v02.api.letsencrypt.org/directory).  
2018-06-20 14:13:27,910:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): [acme-staging-v02.api.letsencrypt.org](http://acme-staging-v02.api.letsencrypt.org)  
2018-06-20 14:13:28,070:WARNING:certbot.renewal:Attempting to renew cert ([wifi.enslave.ru](http://wifi.enslave.ru)) from /etc/letsencrypt/renewal/wifi.enslave.ru.conf produced an unexpected error: (“bad handshake: Error([(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)],)”,). Skipping.  
2018-06-20 14:13:28,073:DEBUG:certbot.renewal:Traceback was:  
Traceback (most recent call last):  
File “/usr/lib/python3/dist-packages/urllib3/contrib/pyopenssl.py”, line 438, in wrap\_socket  
cnx.do\_handshake()  
File “/usr/lib/python3/dist-packages/OpenSSL/SSL.py”, line 1716, in do\_handshake  
self.\_raise\_ssl\_error(self.\_ssl, result)  
File “/usr/lib/python3/dist-packages/OpenSSL/SSL.py”, line 1456, in \_raise\_ssl\_error  
\_raise\_current\_error()  
File “/usr/lib/python3/dist-packages/OpenSSL/\_util.py”, line 54, in exception\_from\_error\_queue  
raise exception\_type(errors)  
OpenSSL.SSL.Error: [(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)]

During handling of the above exception, another exception occurred:

Traceback (most recent call last):  
File “/usr/lib/python3/dist-packages/urllib3/connectionpool.py”, line 600, in urlopen  
chunked=chunked)  
File “/usr/lib/python3/dist-packages/urllib3/connectionpool.py”, line 345, in \_make\_request  
self.\_validate\_conn(conn)  
File “/usr/lib/python3/dist-packages/urllib3/connectionpool.py”, line 846, in _validate\_conn  
conn.connect()  
File “/usr/lib/python3/dist-packages/urllib3/connection.py”, line 326, in connect  
ssl\_context=context)  
File "/usr/lib/python3/dist-packages/urllib3/util/ssl_.py", line 325, in ssl\_wrap\_socket  
return context.wrap\_socket(sock, server\_hostname=server\_hostname)  
File “/usr/lib/python3/dist-packages/urllib3/contrib/pyopenssl.py”, line 445, in wrap\_socket  
raise ssl.SSLError(‘bad handshake: %r’ % e)  
ssl.SSLError: (“bad handshake: Error([(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)],)”,)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):  
File “/usr/lib/python3/dist-packages/requests/adapters.py”, line 440, in send  
timeout=timeout  
File “/usr/lib/python3/dist-packages/urllib3/connectionpool.py”, line 630, in urlopen  
raise SSLError(e)  
urllib3.exceptions.SSLError: (“bad handshake: Error([(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)],)”,)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):  
File “/usr/lib/python3/dist-packages/certbot/renewal.py”, line 422, in handle\_renewal\_request  
main.renew\_cert(lineage\_config, plugins, renewal\_candidate)  
File “/usr/lib/python3/dist-packages/certbot/main.py”, line 1100, in renew\_cert  
le\_client = \_init\_le\_client(config, auth, installer)  
File “/usr/lib/python3/dist-packages/certbot/main.py”, line 642, in \_init\_le\_client  
return client.Client(config, acc, authenticator, installer, acme=acme)  
File “/usr/lib/python3/dist-packages/certbot/client.py”, line 230, in **init**  
acme = acme\_from\_config\_key(config, self.account.key, self.account.regr)  
File “/usr/lib/python3/dist-packages/certbot/client.py”, line 46, in acme\_from\_config\_key  
return acme\_client.BackwardsCompatibleClientV2(net, key, config.server)  
File “/usr/lib/python3/dist-packages/acme/client.py”, line 718, in **init**  
directory = messages.Directory.from\_json(net.get(server).json())  
File “/usr/lib/python3/dist-packages/acme/client.py”, line 1041, in get  
self.\_send\_request(‘GET’, url, \*\*kwargs), content\_type=content\_type)  
File “/usr/lib/python3/dist-packages/acme/client.py”, line 990, in \_send\_request  
response = self.session.request(method, url, \*args, \*\*kwargs)  
File “/usr/lib/python3/dist-packages/requests/sessions.py”, line 502, in request  
resp = self.send(prep, \*\*send\_kwargs)  
File “/usr/lib/python3/dist-packages/requests/sessions.py”, line 612, in send  
r = adapter.send(request, \*\*kwargs)  
File “/usr/lib/python3/dist-packages/requests/adapters.py”, line 514, in send  
raise SSLError(e, request=request)  
requests.exceptions.SSLError: (“bad handshake: Error([(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)],)”,)

2018-06-20 14:13:28,074:ERROR:certbot.renewal:All renewal attempts failed. The following certs could not be renewed:  
2018-06-20 14:13:28,074:ERROR:certbot.renewal: /etc/letsencrypt/live/wifi.enslave.ru/fullchain.pem (failure)  
2018-06-20 14:13:28,074:DEBUG:certbot.log:Exiting abnormally:  
Traceback (most recent call last):  
File “/usr/bin/certbot”, line 11, in   
load\_entry\_point(‘certbot==0.22.2’, ‘console\_scripts’, ‘certbot’)()  
File “/usr/lib/python3/dist-packages/certbot/main.py”, line 1266, in main  
return config.func(config, plugins)  
File “/usr/lib/python3/dist-packages/certbot/main.py”, line 1179, in renew  
renewal.handle\_renewal\_request(config)  
File “/usr/lib/python3/dist-packages/certbot/renewal.py”, line 443, in handle\_renewal\_request  
len(renew\_failures), len(parse\_failures)))  
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 20, 2018, 4:30pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/4 "2018-06-20T16:30:29Z")

</div>

> [@tabl](#):
>
> The domain is [wifi.enslave.ru](http://wifi.enslave.ru)

Why is there a 302 - Redirect to [enslave.ru](http://enslave.ru)? I don't know if Certbot interprets that as an error.

On [enslave.ru](http://enslave.ru), there is a Letsencrypt-certificate (start 2018-06-10) with [www.enslave.ru](http://www.enslave.ru) + [enslave.ru](http://enslave.ru). Perhaps Certbot creates this error.

> 2018-06-20 14:13:28,070:WARNING:certbot.renewal:Attempting to renew cert ([wifi.enslave.ru](http://wifi.enslave.ru)) from /etc/letsencrypt/renewal/wifi.enslave.ru.conf produced an unexpected error: (“bad handshake: Error([(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)],)”,). Skipping.

@schoen wrote (some days earlier), that Certbot ignores chain errors and outdated certificates. [Edit] But I don't know if such a redirect from [wifi.enslave.ru](http://wifi.enslave.ru) to [enslave.ru](http://enslave.ru) (without a certificate of [wifi.enslave.ru](http://wifi.enslave.ru)) is also ok.

Remove the 302-redirect and check it again. Perhaps use the test/staging - system first. If this works, then switch to the productive system.

---

<div class="post-metadata">

**Author:** ![tabl](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@tabl](https://community.letsencrypt.org/u/tabl)\
**Post date:** [June 20, 2018, 5:29pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/5 "2018-06-20T17:29:31Z")

</div>

I removed the redirect. Unfortunately, that did not fix the error.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 20, 2018, 5:36pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/6 "2018-06-20T17:36:07Z")

</div>

Now I can see a Letsencrypt-certificate [https://wifi.enslave.ru/](https://wifi.enslave.ru/) NotAfter 2018-07-04.

And [http://wifi.enslave.ru/](http://wifi.enslave.ru/) is available.

But I don't see why this

> requests.exceptions.SSLError: (“bad handshake: Error([(‘SSL routines’, ‘ssl3\_get\_server\_certificate’, ‘certificate verify failed’)],)”,)

happens.

---

<div class="post-metadata">

**Author:** ![tabl](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@tabl](https://community.letsencrypt.org/u/tabl)\
**Post date:** [June 20, 2018, 5:46pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/7 "2018-06-20T17:46:24Z")

</div>

Hmm, I googled out that it could be a `ca-certificates` package problems so I reinstalled it (with the whole certbot) and now it works.

Thanks!

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 20, 2018, 8:44pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/8 "2018-06-20T20:44:25Z")

</div>

> [@JuergenAuer](#):
>
> @schoen wrote (some days earlier), that Certbot ignores chain errors and outdated certificates. [Edit] But I don’t know if such a redirect from [wifi.enslave.ru](http://wifi.enslave.ru) to [enslave.ru](http://enslave.ru) (without a certificate of [wifi.enslave.ru](http://wifi.enslave.ru)) is also ok.

It's the Let's Encrypt CA that ignores them, rather than Certbot, and the redirect is also OK.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 20, 2018, 8:44pm UTC](https://community.letsencrypt.org/t/certificate-verify-failed/64848/9 "2018-07-20T20:44:30Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
