# Challenge file not created during update

**URL:** <https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636>\
**Category:** Help\
**Created:** [February 29, 2020, 8:16pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636 "2020-02-29T20:16:12Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 29, 2020, 10:36pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/21 "2020-02-29T22:36:59Z")

</div>

> [@crashulater](#):
>
> Still have visitors with old IE browsers.

Yeah... but maybe you don't need all that many old ciphers 😉 [Mozilla SSL Configuration Generator](https://ssl-config.mozilla.org/#server=apache&version=2.4.41&config=old&openssl=1.1.1d&hsts=false&guideline=5.4)

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 29, 2020, 10:44pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/22 "2020-02-29T22:44:46Z")

</div>

right now, I’d try a

```bash
certbot --staging --manual --preferred-challenges=http

```

if it works, remove `--staging` and run again.

at the very least it should tell you where the problem is

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [February 29, 2020, 10:46pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/23 "2020-02-29T22:46:24Z")

</div>

…/.well-known/acme-challenge$ touch webroot\_check  
Yeah, that checks out just fine.

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [February 29, 2020, 11:00pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/24 "2020-02-29T23:00:50Z")

</div>

> [@9peppe](#):
>
> right now, I’d try a
> 
> ```nohighlight
> certbot --staging --manual --preferred-challenges=http
> 
> ```

Right on 6peppe! New command:

# certbot-auto certonly --staging --manual --preferred-challenges=http --break-my-cert

Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Plugins selected: Authenticator manual, Installer None  
Please enter in your domain name(s) (comma and/or space separated) (Enter 'c'  
to cancel): [hork.com](http://hork.com) [www.hork.com](http://www.hork.com)  
Cert is due for renewal, auto-renewing...  
Renewing an existing certificate  
Performing the following challenges:  
http-01 challenge for [hork.com](http://hork.com)  
http-01 challenge for [www.hork.com](http://www.hork.com)

* * *

NOTE: The IP of this machine will be publicly logged as having requested this  
certificate. If you're running certbot in manual mode on a machine that is not  
your server, please ensure you're okay with that.

Are you OK with your IP being logged?

* * *

(Y)es/(N)o: Y

* * *

Create a file containing just this data:

H32iOYOzjyJZp0dvDp-ahSIpI6yJpy3A4dvy0SZZQW4.RBWym4r\_JIAUsFWjcGCZPwjWQbTNRGUZ8eZkUc85iHg

And make it available on your web server at this URL:

[http://hork.com/.well-known/acme-challenge/H32iOYOzjyJZp0dvDp-ahSIpI6yJpy3A4dvy0SZZQW4](http://hork.com/.well-known/acme-challenge/H32iOYOzjyJZp0dvDp-ahSIpI6yJpy3A4dvy0SZZQW4)

* * *

Press Enter to Continue

* * *

Create a file containing just this data:

xr6iu2MBATznK84EavK7RueNiyS4RwNyZi0sDCoz3Sk.RBWym4r\_JIAUsFWjcGCZPwjWQbTNRGUZ8eZkUc85iHg

And make it available on your web server at this URL:

[http://www.hork.com/.well-known/acme-challenge/xr6iu2MBATznK84EavK7RueNiyS4RwNyZi0sDCoz3Sk](http://www.hork.com/.well-known/acme-challenge/xr6iu2MBATznK84EavK7RueNiyS4RwNyZi0sDCoz3Sk)

(This must be set up in addition to the previous challenges; do not remove,  
replace, or undo the previous challenge tasks yet.)

* * *

Press Enter to Continue  
Waiting for verification...  
Cleaning up challenges

IMPORTANT NOTES:

- Congratulations! Your certificate and chain have been saved at:  
/etc/letsencrypt/live/hork.com/fullchain.pem  
Your key file has been saved at:  
/etc/letsencrypt/live/hork.com/privkey.pem  
Your cert will expire on 2020-05-29. To obtain a new or tweaked  
version of this certificate in the future, simply run certbot-auto  
again. To non-interactively renew _all_ of your certificates, run  
"certbot-auto renew"  
and what's more, I now have new certs 🙂  
-rw------- 1 root root 1704 Feb 29 17:57 privkey2.pem  
-rw-r--r-- 1 root root 3549 Feb 29 17:57 fullchain2.pem  
-rw-r--r-- 1 root root 1679 Feb 29 17:57 chain2.pem  
-rw-r--r-- 1 root root 1870 Feb 29 17:57 cert2.pem

Just in time for dinner. Thanks guys!

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 29, 2020, 11:05pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/25 "2020-02-29T23:05:03Z")

</div>

> [@crashulater](#):
>
> Just in time for dinner

Congratulations, now you have a non-functional **staging** certificate. You literally used the option `--break-my-cert` which should have given you a hint.

Although I don't understand why the staging server would succeed and the live server wouldn't, you could try to run the same command, but now without the `--staging` and `--break-my-cert` options.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [February 29, 2020, 11:15pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/26 "2020-02-29T23:15:31Z")

</div>

Please remember this:

> [@9peppe](#):
>
> if it works, remove `--staging` and run again.

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [March 1, 2020, 12:04am UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/27 "2020-03-01T00:04:53Z")

</div>

Well rats! That does /not/ work, despite my 3 attempts at it. ☹  
New command:

# certbot-auto certonly --manual --preferred-challenges=http

Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Plugins selected: Authenticator manual, Installer None  
Please enter in your domain name(s) (comma and/or space separated) (Enter ‘c’  
to cancel): [hork.com](http://hork.com) [www.hork.com](http://www.hork.com)  
Cert not yet due for renewal

You have an existing certificate that has exactly the same domains or certificate name you requested and isn’t close to expiry.  
(ref: /etc/letsencrypt/renewal/hork.com.conf)

What would you like to do?

* * *

1: Keep the existing certificate for now  
2: Renew & replace the cert (limit ~5 per 7 days)

* * *

Select the appropriate number [1-2] then [enter] (press ‘c’ to cancel): 2  
Renewing an existing certificate  
Performing the following challenges:  
http-01 challenge for [hork.com](http://hork.com)  
http-01 challenge for [www.hork.com](http://www.hork.com)

* * *

NOTE: The IP of this machine will be publicly logged as having requested this  
certificate. If you’re running certbot in manual mode on a machine that is not  
your server, please ensure you’re okay with that.

Are you OK with your IP being logged?

* * *

(Y)es/(N)o: Y

* * *

Create a file containing just this data:

lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ.2uIOTW8ZMoWC4qwu3smFmSSg-bY69H6WN8hRHGTveNw

And make it available on your web server at this URL:

[http://hork.com/.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ](http://hork.com/.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ)

* * *

Press Enter to Continue

* * *

Create a file containing just this data:

PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ.2uIOTW8ZMoWC4qwu3smFmSSg-bY69H6WN8hRHGTveNw

And make it available on your web server at this URL:

[http://www.hork.com/.well-known/acme-challenge/PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ](http://www.hork.com/.well-known/acme-challenge/PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ)

(This must be set up in addition to the previous challenges; do not remove,  
replace, or undo the previous challenge tasks yet.)

* * *

Press Enter to Continue  
Waiting for verification…  
Challenge failed for domain [hork.com](http://hork.com)  
Challenge failed for domain [www.hork.com](http://www.hork.com)  
http-01 challenge for [hork.com](http://hork.com)  
http-01 challenge for [www.hork.com](http://www.hork.com)  
Cleaning up challenges  
Some challenges have failed.

IMPORTANT NOTES:

- The following errors were reported by the server:

and to remove any doubts about those two file:  
.well-known/acme-challenge$ ls -l  
-rw-r----- 1 webmastr apache 88 Feb 29 18:50 lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ  
-rw-r----- 1 webmastr apache 88 Feb 29 18:51 PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ

hork10:.well-known/acme-challenge$ more \*  
::::::::::::::  
lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ  
::::::::::::::  
lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ.2uIOTW8ZMoWC4qwu3smFmSSg-bY69H6WN8hRHGTveNw  
::::::::::::::  
PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ  
::::::::::::::  
PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ.2uIOTW8ZMoWC4qwu3smFmSSg-bY69H6WN8hRHGTveNw

and they /are/ visible/readable from here:  
[http://www.hork.com/.well-known/acme-challenge/](http://www.hork.com/.well-known/acme-challenge/)

access\_log shows all these attempts to read them:  
66.133.109.36 - - [29/Feb/2020:18:52:06 -0500] “GET /.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ HTTP/1.1” 200 88 “-” “Mozilla/5.0 (compatible; Let’s Encrypt validation server; +https://www.letsencrypt.org)”  
66.133.109.36 - - [29/Feb/2020:18:52:06 -0500] “GET /.well-known/acme-challenge/PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ HTTP/1.1” 200 88 “-” “Mozilla/5.0 (compatible; Let’s Encrypt validation server; +https://www.letsencrypt.org)”  
52.28.236.88 - - [29/Feb/2020:18:52:06 -0500] “GET /.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ HTTP/1.1” 200 88 “-” “Mozilla/5.0 (compatible; Let’s Encrypt validation server; +https://www.letsencrypt.org)”  
52.28.236.88 - - [29/Feb/2020:18:52:06 -0500] “GET /.well-known/acme-challenge/PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ HTTP/1.1” 200 88 “-” “Mozilla/5.0 (compatible; Let’s Encrypt validation server; +https://www.letsencrypt.org)”  
65.19.128.70 - - [29/Feb/2020:18:53:53 -0500] “HEAD /.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ HTTP/1.1” 200 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:53:53 -0500] “GET /.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ HTTP/1.1” 200 88 “-” “Discourse Forum Onebox v2.5.0.beta1”  
65.19.128.70 - - [29/Feb/2020:18:53:53 -0500] “HEAD /.well-known/acme-challenge/PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ HTTP/1.1” 200 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:53:53 -0500] “GET /.well-known/acme-challenge/PCeBPh7I7y33wPbm5FY7FAS4ahVeCvrM5MoYLumH2QQ HTTP/1.1” 200 88 “-” “Discourse Forum Onebox v2.5.0.beta1”  
105.242.128.41 - - [29/Feb/2020:18:54:45 -0500] “POST /ctrlt/DeviceUpgrade\_1 HTTP/1.1” 400 226 “-” “-”  
192.168.1.1 - - [29/Feb/2020:18:54:51 -0500] “GET /.well-known/acme-challenge/ HTTP/1.1” 200 492 “-” “Mozilla/5.0 (X11; Fedora; Linux x86\_64; rv:57.0) Gecko/20100101 Firefox/57.0”  
192.168.1.1 - - [29/Feb/2020:18:54:57 -0500] “GET /.well-known/acme-challenge/lr8P-m0zUck1NgE9EXVHNEnRJv-u7w1rHcpV82DZ1lQ HTTP/1.1” 200 88 “[http://www.hork.com/.well-known/acme-challenge/](http://www.hork.com/.well-known/acme-challenge/)” “Mozilla/5.0 (X11; Fedora; Linux x86\_64; rv:57.0) Gecko/20100101 Firefox/57.0”  
65.19.128.70 - - [29/Feb/2020:18:55:25 -0500] “HEAD / HTTP/1.1” 200 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:25 -0500] “GET / HTTP/1.1” 200 1237 “-” “Discourse Forum Onebox v2.5.0.beta1”  
65.19.128.70 - - [29/Feb/2020:18:55:28 -0500] “HEAD /.wel HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:28 -0500] “HEAD /.well HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:29 -0500] “HEAD /.well-k HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:29 -0500] “HEAD /.well-kno HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:30 -0500] “HEAD /.well-know HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:30 -0500] “HEAD /.well-known HTTP/1.1” 301 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:30 -0500] “HEAD /.well-known/ HTTP/1.1” 200 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:30 -0500] “GET /.well-known/ HTTP/1.1” 200 282 “-” “Discourse Forum Onebox v2.5.0.beta1”  
65.19.128.70 - - [29/Feb/2020:18:55:32 -0500] “HEAD /.well-known/ac HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:32 -0500] “HEAD /.well-known/acm HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:33 -0500] “HEAD /.well-known/acme- HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:33 -0500] “HEAD /.well-known/acme-ch HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:34 -0500] “HEAD /.well-known/acme-chal HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:34 -0500] “HEAD /.well-known/acme-chall HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:34 -0500] “HEAD /.well-known/acme-challe HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:35 -0500] “HEAD /.well-known/acme-challen HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:35 -0500] “HEAD /.well-known/acme-challeng HTTP/1.1” 404 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:36 -0500] “HEAD /.well-known/acme-challenge HTTP/1.1” 301 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:36 -0500] “HEAD /.well-known/acme-challenge/ HTTP/1.1” 200 - “-” “Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36”  
65.19.128.70 - - [29/Feb/2020:18:55:36 -0500] “GET /.well-known/acme-challenge/ HTTP/1.1” 200 492 “-” “Discourse Forum Onebox v2.5.0.beta1”

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 1, 2020, 12:24am UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/28 "2020-03-01T00:24:40Z")

</div>

> [@crashulater](#):
>
> Detail: During secondary validation: Fetching

Please read my answer. You are blocking some ip addresses, so the secondary validation doesn't work.

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [March 1, 2020, 12:37am UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/29 "2020-03-01T00:37:33Z")

</div>

Thanks for hanging in there with me Juergen. Yes, I am blocking IP addresses. Over 50 million of them. Most of China, Russia, Ukraine, Iran, and selected ranges elsewhere. These were blocked in the last 20 minutes. Please let me know which need to be given access.  
Feb 29 18:52:06 hork10 kernel: web\_blcklst SRC=52.15.254.228  
Feb 29 18:52:06 hork10 kernel: web\_blcklst SRC=34.222.229.130  
Feb 29 18:53:17 hork10 kernel: web\_blcklst SRC=178.128.75.244  
Feb 29 19:08:17 hork10 kernel: web\_blcklst SRC=106.120.173.139  
Feb 29 19:08:19 hork10 kernel: web\_blcklst SRC=111.202.100.82  
Feb 29 19:08:19 hork10 kernel: web\_blcklst SRC=58.250.125.185  
Feb 29 19:14:21 hork10 kernel: web\_blcklst SRC=111.206.198.223  
Feb 29 19:14:21 hork10 kernel: web\_blcklst SRC=111.206.222.193  
Feb 29 19:14:24 hork10 kernel: web\_blcklst SRC=111.206.198.36  
Feb 29 19:14:31 hork10 kernel: web\_blcklst SRC=111.206.198.44  
Feb 29 19:16:02 hork10 kernel: web\_blcklst SRC=118.101.51.95  
Feb 29 19:28:18 hork10 kernel: web\_blcklst SRC=106.120.173.139

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 1, 2020, 8:14am UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/30 "2020-03-01T08:14:23Z")

</div>

> [@crashulater](#):
>
> Please let me know which need to be given access.

We don't know. Read the blog post which was linked twice above already about multi-perspective validation.

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [March 1, 2020, 3:48pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/31 "2020-03-01T15:48:21Z")

</div>

Thanks Osiris. Much better this way!  
% date  
Sun Mar 1 10:15:42 EST 2020  
% systemctl stop seamus (that’s my dog)  
% systemctl stop iptables  
% certbot-auto certonly --manual --preferred-challenges=http  
(all that jazz) Congratulations!  
% systemctl start iptables  
% systemctl start seamus  
% date  
Sun Mar 1 10:17:41 EST 2020

And that is how I will be renewing my letsencrypt certificate from here on out. 🙂  
Maybe I could have figured this out for myself if the Error message had been something like this:  
Your secondary validation failed. This feature was newly added for version 1.2, because single point validation is susceptible to man-in-the-middle network attackers that may hijack or redirect the traffic along the validation path. Multi-Perspective validation uses a number of cloud based servers to independently validate your server. Because these cloud services (e.g. Amazon, DigitalOcean) are only semi-reputable themselves and seldom if ever produce real web traffic, you may have blocked them at your firewall, in which case the validation will fail. See if you can’t live with your firewall (partially) switched off for the two minutes it takes to renew your certificate. Also make sure you call of your (watch)dog if he is particularly vicious, as he may wake up the cat and you really don’t want that automatic reporting to the offending network provider to kick in.  
With Love,  
The outstanding letsencrypt team.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 1, 2020, 4:11pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/32 "2020-03-01T16:11:07Z")

</div>

You can use [`--pre-hook` and `--post-hook`](https://certbot.eff.org/docs/using.html#renewing-certificates) to run scripts before and after the renewal attempt. Might be an idea for your firewall.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 1, 2020, 4:15pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/33 "2020-03-01T16:15:32Z")

</div>

You can also probably remove `--manual` and `--preferred-challenges=http`

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [March 1, 2020, 6:02pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/34 "2020-03-01T18:02:18Z")

</div>

I like the --manual option. I know it is a goal of letsencrypt to make the cert renewal an automated process, but I rather spent 2 minutes every 12th Sunday manually renewing the cert than to have an automated process restart httpd on an active user of my web portal. I also understand that there are many options to modify certbot to everyone’s liking. I only need a single version that works for me. You guys have made installing a cert as easy as doing a self-signed certificate, with the added bonus that browsers will actually accept it, without screaming bloody murder. That’s good enough for me. Cheers. Crashulater out.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 1, 2020, 6:40pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/35 "2020-03-01T18:40:46Z")

</div>

Ok.

Restart and reload are very different, though. (you can also choose the time, make it run a 3AM, etc…)

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [March 1, 2020, 7:10pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/36 "2020-03-01T19:10:35Z")

</div>

Thanks, you’ve been great. Not only do I now have a valid cert again, the site also gets an ‘A’ from SSL labs. I didn’t know that just defining the CipherSuite in conf.d/ssl.conf wasn’t good enough. Apparently it must also be defined for each \<VirtualHost: \*:443\>. Now it is. But that’s a different topic for a different board. 😉  
Cheers mate.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 1, 2020, 7:45pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/37 "2020-03-01T19:45:26Z")

</div>

For A+ you need hsts, but be careful: activating hsts literally means most people won’t be able to see your site unencrypted.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 1, 2020, 9:24pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/38 "2020-03-01T21:24:14Z")

</div>

> [@9peppe](#):
>
> (…) most people won’t be able to see your site unencrypted.

That fact alone isn't such a problem: it's the reason why HSTS exists in the first place! Perhaps you meant in the scenario when the encrypted site isn't functioning properly? 😉

---

<div class="post-metadata">

**Author:** ![ZetaRevan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/zetarevan/32/37496_2.png) [@ZetaRevan](https://community.letsencrypt.org/u/ZetaRevan)\
**Post date:** [March 1, 2020, 9:27pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/39 "2020-03-01T21:27:31Z")

</div>

> [@crashulater](#):
>
> I didn’t know that just defining the CipherSuite in conf.d/ssl.conf wasn’t good enough. Apparently it must also be defined for each \<VirtualHost: \*:443\>. Now it is.

You have to watch where you're placing those config lines inside ssl.conf. `SSLCipherSuite` & `SSLProtocol` tend to be placed inside the default VirtualHost block, which limits them to be used only when the 443 traffic doesn't match any other vhost. If you set them outside the block, they will be set globally.

---

<div class="post-metadata">

**Author:** ![crashulater](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/crashulater/32/37545_2.png) [@crashulater](https://community.letsencrypt.org/u/crashulater)\
**Post date:** [March 1, 2020, 9:46pm UTC](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636/40 "2020-03-01T21:46:34Z")

</div>

That certainly explains that ZataRevan. My interpretation of _default_ was always that those declarations would apply unless overridden by declarations made in the specific VirtualHost definition. You know, the inheritance principle. I guess, too much JavaScript can do that to a man. 😉

[Previous page](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636.md?page=1)

[Next page](https://community.letsencrypt.org/t/challenge-file-not-created-during-update/114636.md?page=3)
