# Challenge Failed

**URL:** <https://community.letsencrypt.org/t/challenge-failed/89881>\
**Category:** Help\
**Created:** [March 29, 2019, 6:42am UTC](https://community.letsencrypt.org/t/challenge-failed/89881 "2019-03-29T06:42:36Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![piyush1973](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@piyush1973](https://community.letsencrypt.org/u/piyush1973)\
**Post date:** [March 29, 2019, 6:42am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/1 "2019-03-29T06:42:36Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [www.curae.net](http://www.curae.net)

I ran this command:  
./certbot-auto

It produced this output:

- The following errors were reported by the server:

My web server is (include version): apache

The operating system my web server runs on is (include version): linux

My hosting provider, if applicable, is: GoDaddy

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot): certbot 0.32.0

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 29, 2019, 7:54am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/2 "2019-03-29T07:54:06Z")

</div>

Hi @piyush1973

> [@piyush1973](#):
>
> My domain is: [www.curae.net](http://www.curae.net)

your ip numbers ( [https://check-your-website.server-daten.de/?q=curae.net](https://check-your-website.server-daten.de/?q=curae.net) ):

| Host | T | IP-Address | is auth. | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| [curae.net](http://curae.net) | A | 184.168.131.241 | yes | 2 | 0 |
| | AAAA | | yes | | |
| [www.curae.net](http://www.curae.net) | C | [curae.net](http://curae.net) | yes | 1 | 0 |
| | A | 184.168.131.241 | yes | | |

First look, the answers are ok - port 80 is open.

| Domainname | Http-Status | redirect | Sec. | G |
| --- | --- | --- | --- | --- |
| • [http://curae.net/](http://curae.net/) | | | | |
| 184.168.131.241 | 200 | | 3.360 | H |
| | | | | |
| • [http://www.curae.net/](http://www.curae.net/) | | | | |
| 184.168.131.241 | 200 | | 0.350 | H |
| | | | | |
| • [https://curae.net/](https://curae.net/) | | | | |
| 184.168.131.241 | 200 | | 1.900 | N |
| Certificate error: RemoteCertificateNameMismatch | | | | |
| | | | | |
| • [https://www.curae.net/](https://www.curae.net/) | | | | |
| 184.168.131.241 | 200 | | 1.593 | N |
| Certificate error: RemoteCertificateNameMismatch | | | | |
| | | | | |
| • [curae.net](http://curae.net/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | | | | |
| 184.168.131.241 | 200 | | 0.374 | |
| Visible Content: \<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "[http://www.w3.org/TR/html4/strict.dtd](http://www.w3.org/TR/html4/strict.dtd)"\> Curae | | | | |
| | | | | |
| • [curae.net](http://www.curae.net/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | | | | |
| 184.168.131.241 | 200 | | 0.357 | |
| Visible Content: \<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "[http://www.w3.org/TR/html4/strict.dtd](http://www.w3.org/TR/html4/strict.dtd)"\> Curae | | | | |

But there is a http status 200, checking the not existing file /.well-known/acme-challenge.

And there

```nohighlight
http://www.curae.net/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

```

is a frame included.

> \<frame src="http://18.188.130.21:8080/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de" frameborder="0" /\>

If you want a certificate with http-01 validation, your dns entry must use the 18.188.130.21 and you must have an open port 80, not port 8080.

Or use dns-01 validation, then you don't need a running webserver.

---

<div class="post-metadata">

**Author:** ![piyush1973](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@piyush1973](https://community.letsencrypt.org/u/piyush1973)\
**Post date:** [March 29, 2019, 8:26am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/3 "2019-03-29T08:26:36Z")

</div>

Hi,  
I am still getting the same error.  
Piyush Agarwal

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 29, 2019, 8:32am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/4 "2019-03-29T08:32:41Z")

</div>

I also get a “Connection reset by peer” error if I try to access it using curl.

It looks like the website blocks some clients based on the User-Agent header. A browser works – producing the iframe page – but other clients get the connection reset.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 29, 2019, 8:38am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/5 "2019-03-29T08:38:15Z")

</div>

> [@piyush1973](#):
>
> I am still getting the same error.

Rechecked your domain ( [https://check-your-website.server-daten.de/?q=curae.net](https://check-your-website.server-daten.de/?q=curae.net) ):

| Host | T | IP-Address | is auth. | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| [curae.net](http://curae.net) | A | 184.168.131.241 | yes | 2 | 0 |
| | AAAA | | yes | | |
| [www.curae.net](http://www.curae.net) | C | [curae.net](http://curae.net) | yes | 1 | 0 |
| | A | 184.168.131.241 | yes | | |

You didn't change your ip address.

There must be your 18.\* address visible.

http + www now has a server error (bad gateway), the rest is the same.

---

<div class="post-metadata">

**Author:** ![piyush1973](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@piyush1973](https://community.letsencrypt.org/u/piyush1973)\
**Post date:** [March 29, 2019, 8:42am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/6 "2019-03-29T08:42:05Z")

</div>

Actually I am redirecting it from 184.168.131.241 to 18.\*  
I am doing the same for two other websites and it is working

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 29, 2019, 8:47am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/7 "2019-03-29T08:47:44Z")

</div>

> [@piyush1973](#):
>
> Actually I am redirecting it from 184.168.131.241 to 18.\*

On which ip address runs your certbot?

184.\* or 18.\*

---

<div class="post-metadata">

**Author:** ![piyush1973](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@piyush1973](https://community.letsencrypt.org/u/piyush1973)\
**Post date:** [March 29, 2019, 8:49am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/8 "2019-03-29T08:49:05Z")

</div>

certbot is running on 18.\*

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 29, 2019, 8:49am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/9 "2019-03-29T08:49:52Z")

</div>

And that can’t work, Letsencrypt sees:

your domain -\> 184.\* -\> Letsencrypt checks the 184.\*

---

<div class="post-metadata">

**Author:** ![piyush1973](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@piyush1973](https://community.letsencrypt.org/u/piyush1973)\
**Post date:** [March 29, 2019, 8:50am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/10 "2019-03-29T08:50:57Z")

</div>

I have updated the A entry . Now there are two ip addresses

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 29, 2019, 9:06am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/11 "2019-03-29T09:06:34Z")

</div>

> [@piyush1973](#):
>
> Now there are two ip addresses

If your certbot runs on the 18.`*`, certbot can't update the 184.`*` ip addresses.

So remove these entries complete, only

A -\> 18.\*

---

<div class="post-metadata">

**Author:** ![piyush1973](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@piyush1973](https://community.letsencrypt.org/u/piyush1973)\
**Post date:** [March 29, 2019, 9:11am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/12 "2019-03-29T09:11:32Z")

</div>

Thank you. It s working now

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 28, 2019, 9:11am UTC](https://community.letsencrypt.org/t/challenge-failed/89881/13 "2019-04-28T09:11:34Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
