Hi,
Hello, unfortunately, I find too many posts on the topic, but I can't find anything specific that helps me. I am unable to create a certificate using Certbot.
Despite having the firewall disabled, I still get a time-out. Interestingly, I can access the FETCH URL in the browser and see the correct token. I'm not sure if it matters, but the server is not reachable via IPv4. I have an AAAA record under my domain pointing to my server in my home network.
Does anyone have an idea of what else I could check?
Here you can find my certbot log. I'm wondering, it ends with a traceback I can't read.
My domain is:
> nextcloud.wref.de
I ran this command: s
> udo certbot certonly --apache -d "nextcloud.wref.de" --debug-challenges --dry-run -v
It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator apache, Installer apache
Simulating a certificate request for nextcloud.wref.de
Performing the following challenges:
http-01 challenge for nextcloud.wref.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Challenges loaded. Press continue to submit to CA.
The following URLs should be accessible from the internet and return the value
mentioned:
URL:
http://nextcloud.wref.de/.well-known/acme-challenge/FTzeYTH6wLKI_ehLeqXa_HHPPQWk0mbH2mbQUG7w3_4
Expected value:
FTzeYTH6wLKI_ehLeqXa_HHPPQWk0mbH2mbQUG7w3_4.iMCLnutg62tG3mlwZLUYIX7-qzaRKuL0emaVxuomnB8
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Press Enter to Continue
Waiting for verification...
Challenge failed for domain nextcloud.wref.de
http-01 challenge for nextcloud.wref.de
Certbot failed to authenticate some domains (authenticator: apache). The Certificate Authority reported these problems:
Domain: nextcloud.wref.de
Type: connection
Detail: 2a00:6020:4196:ca00:3bee:c98b:d966:9e3d: Fetching http://nextcloud.wref.de/.well-known/acme-challenge/FTzeYTH6wLKI_ehLeqXa_HHPPQWk0mbH2mbQUG7w3_4: Timeout during connect (likely firewall problem)
Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet.
Cleaning up challenges
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
My web server is (include version):
Server version: Apache/2.4.62 (Debian)
The operating system my web server runs on is (include version):
Linux nextcloud 6.1.0-28-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.119-1 (2024-11-22) x86_64 GNU/Linux
My hosting provider, if applicable, is:
self-hosted
I can login to a root shell on my machine (yes or no, or I don't know):
yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel):
no
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot):
certbot 2.1.0