# Creat new certificate failed on a proxy reverse

**URL:** <https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339>\
**Category:** Help\
**Created:** [April 6, 2022, 9:33pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339 "2022-04-06T21:33:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gamma2011](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@Gamma2011](https://community.letsencrypt.org/u/Gamma2011)\
**Post date:** [April 6, 2022, 9:33pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339/1 "2022-04-06T21:33:30Z")

</div>

Hello everyone,  
I encounter an issue during the first certificate generation of the domain name [domo.serverdegamma.fr](http://domo.serverdegamma.fr). I want to use this domain on a reverse proxy server in apache2 on the "server 1". This server proxy is used to redirect client to a raspberry pi 4 "server 2" in the local network where the apache server is installed. The website hosted on the raspierry pi 4 can be reach only in the local network throught an URL like [http://my.domain.private:8080](http://my.domain.private:8080) (with "my.domain.private" associated to an ip address in /etc/hosts in the apache2 server). The proxy virtual host on the apache2 server is the following:

"\<VirtualHost \*:80\>  
ServerName [domo.serveurdegamma.fr](http://domo.serveurdegamma.fr)  
ProxyPass / [http://my.domain.private:8080/](http://my.domain.private:8080/)  
ProxyPassReverse / [http://my.domain.private:8080/](http://my.domain.private:8080/)  
ProxyPreserveHost On  
"

My first investigations:

- I set up listening port on apache2 like this: 0.0.0.0:80 (disabling ipv6)
- The Let's debug returned the following result: [Let's Debug](https://letsdebug.net/domo.serveurdegamma.fr/982706)
- I set up a root path for the proxy server like /var/myserver in case of the certbot needs a directory.
- The domain name [domo.serveurdegamma.fr](http://domo.serveurdegamma.fr) is redirected to the correct ip address by dynhost on OVH CLOUD.
- The proxy server is working and redirect all flow from [domo.serveurdegamma.fr](http://domo.serveurdegamma.fr) on the correct website hosted on the raspberry pi 4.

Do you have any idea of what kind of mistake I could have done?

Thank you by advance!

My domain is: [domo.serveurdegamma.fr](http://domo.serveurdegamma.fr)

I ran this command: sudo certbot

It produced this output:

"Failed authorization procedure. [domo.serveurdegamma.fr](http://domo.serveurdegamma.fr) (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://domo.serveurdegamma.fr/.well-known/acme-challenge/5trW4lqFRL8ne6H3cuXURFomftiMQuDD8ywo8q4cuOk](http://domo.serveurdegamma.fr/.well-known/acme-challenge/5trW4lqFRL8ne6H3cuXURFomftiMQuDD8ywo8q4cuOk) [xxx.xxx.xxx.xxx]: 403

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): apache/2.4.29

The operating system my web server runs on is (include version): ubuntu 18.04

My hosting provider, if applicable, is: private server

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 0.27.0

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 6, 2022, 10:01pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339/2 "2022-04-06T22:01:31Z")

</div>

> [@Gamma2011](#):
>
> Do you have any idea of what kind of mistake I could have done?

I think your apache config on the reverse proxy is somehow interfering (or not interfering enough, and the requests just go to the raspberry pi ignoring the reverse proxy completely)

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [April 6, 2022, 10:03pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339/3 "2022-04-06T22:03:10Z")

</div>

I'm not sure exactly what your problem is, but certbot 0.27.0 is quite old. The latest release is certbot 1.26.0: [Releases · certbot/certbot · GitHub](https://github.com/certbot/certbot/releases).

It's worth spending time to update to a recent version of certbot. You can find instructions that will work on Ubuntu 18 here: [Certbot Instructions | Certbot](https://certbot.eff.org/instructions?ws=apache&os=ubuntubionic) (found by going to [certbot.eff.org](http://certbot.eff.org), and selecting "I'm using" \> "Apache", "on" \> "Ubuntu 18".

---

<div class="post-metadata">

**Author:** ![Gamma2011](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@Gamma2011](https://community.letsencrypt.org/u/Gamma2011)\
**Post date:** [April 7, 2022, 5:03pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339/4 "2022-04-07T17:03:06Z")

</div>

Thank you for your feedback! I finaly solved the problem by adding a webroot on the proxy server to make sure that certbot can send his data to verifying the server authentification.

I also updated certbot the the version 1.26.0.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [April 7, 2022, 7:21pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339/5 "2022-04-07T19:21:40Z")

</div>

Excellent! Glad you solved the problem.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 7, 2022, 7:22pm UTC](https://community.letsencrypt.org/t/creat-new-certificate-failed-on-a-proxy-reverse/175339/6 "2022-05-07T19:22:07Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
