# Deactivating pending authorization win-acmev2.2.7.1612

**URL:** <https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775>\
**Category:** Help\
**Created:** [February 23, 2024, 4:17am UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775 "2024-02-23T04:17:17Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 4:17am UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/1 "2024-02-23T04:17:17Z")

</div>

Good morning,  
I would like to install a certificate on my exchange server, but I have this problem.  
Is it possible to help me please.  
THANKS!

 ![Capture d’écran 2024-02-22 231405](https://global.discourse-cdn.com/letsencrypt/original/3X/7/2/72cd4fe47769799cf101894f1ffa2b07ee1fa4b2.png)

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 23, 2024, 4:31am UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/2 "2024-02-23T04:31:45Z")

</div>

The "timeout" error means the Let's Encrypt server could not reach your domain to prove you control that name. This is likely a firewall or misconfigured comms.

It says SelfHosting so if that means a residential setting make sure to check your router and any NAT or port forwarding in it.

More information from the form you were shown would be helpful to us. It is hard to give specific advice without getting specific info. Thanks

===================================

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 23, 2024, 4:40am UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/4 "2024-02-23T04:40:38Z")

</div>

Hi @kader2006, and welcome to the LE community forum 🙂

Email servers are generally only allowed access for SMTP related ports.  
[that said, Windows email servers may use more ports]

After answering the questions posted by @MikeMcQ, ensure that the Internet can reach your email server via HTTP.

---

<div class="post-metadata">

**Author:** ![webprofusion](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/webprofusion/32/85310_2.png) [@webprofusion](https://community.letsencrypt.org/u/webprofusion)\
**Post date:** [February 23, 2024, 5:48am UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/5 "2024-02-23T05:48:42Z")

</div>

> [@rg305](#):
>
> [that said, Windows email servers may use more ports]

Exchange very often runs outlook web access and other http based services on the same machine.

@kader2006 if you cannot enable TCP port 80 access you can also look at DNS validation instead, that way you don't need port 80 open.

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 1:20pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/6 "2024-02-23T13:20:12Z")

</div>

> [@MikeMcQ](#):
>
> My domain is:
> 
> I ran this command:
> 
> It produced this output:
> 
> My web server is (include version):
> 
> The operating system my web server runs on is (include version):
> 
> My hosting provider, if applicable, is:
> 
> I can login to a root shell on my machine (yes or no, or I don't know):
> 
> I'm using a control panel to manage my site (no, or provide the name and version of the control panel):
> 
> The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

My domain is: [nouakader.com](http://nouakader.com) (GoDaddy)

I ran this command: wacs.exe –target manual –host [mail.xxx.com](http://mail.xxx.com),[autodiscover.xxx.com](http://autodiscover.xxx.com) –certificatestore My –acl-fullcontrol “network service,administrators” –installation iis,script –installationsiteid 1 –script “./Scripts/ImportExchange.ps1” –scriptparameters “‘{CertThumbprint}’ ‘IIS,SMTP,IMAP’ 1 ‘{CacheFile}’ ‘{CachePassword}’ ‘{CertFriendlyName}'”

It produced this output: Deactivating pending authorization

My web server is (include version): IIS

The operating system my web server runs on is (include version): Server 2022

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): I don't know (don't tested)

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): ~~no using~~ win-acmev2.2.7.1612

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 1:29pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/7 "2024-02-23T13:29:57Z")

</div>

My port 80 is open, and I disabled Windows Firewall.  
I have the same error

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 1:32pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/8 "2024-02-23T13:32:07Z")

</div>

DNS validation instead, do I look at this on my local DNS server or on my DNS domain host

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 1:35pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/9 "2024-02-23T13:35:24Z")

</div>

Hi,  
Thank you for your welcome.  
 ![Sans titre](https://global.discourse-cdn.com/letsencrypt/original/3X/8/5/859d5a86f88c2295691692ccafb1b6a9bf4f332a.png)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 23, 2024, 4:02pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/10 "2024-02-23T16:02:59Z")

</div>

> [@kader2006](#):
>
> The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): no using

You said you are using `wacs`:

> [@kader2006](#):
>
> I ran this command: wacs.exe ...

What is that version?  
Did this ever work?  
Have you tried any other client?  
[note: I've used [https://CertifyTheWeb.com/](https://CertifyTheWeb.com/) on Windows systems without fail]

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 4:06pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/11 "2024-02-23T16:06:08Z")

</div>

What is that version? last version  
Did this ever work? no first installation  
Have you tried any other client? no  
[note: I've used [https://CertifyTheWeb.com/](https://certifytheweb.com/) on Windows systems without fail] ok

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 23, 2024, 4:10pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/12 "2024-02-23T16:10:26Z")

</div>

> [@kader2006](#):
>
> What is that version? last version

Please provide an actual version number - "last" may mean different things to different people and can change from day to day.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [February 23, 2024, 4:26pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/13 "2024-02-23T16:26:22Z")

</div>

For posterity, anyone searching this site could come across your topic and think "_I'm also using the "latest version"... maybe this (solution) is relevant to my case._".  
When, in fact, the problems are on two different version, and your solution may do nothing for their problem.

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 4:31pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/14 "2024-02-23T16:31:00Z")

</div>

win-acmev2.2.7.1612

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 23, 2024, 5:14pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/15 "2024-02-23T17:14:45Z")

</div>

> [@kader2006](#):
>
> My web server is (include version): IIS

If I check the headers of your domain `nouakader.com` (IP address `3.33.130.190`), I'm seeing that a webserver which is calling itself "openresty" is answering. Are you sure your port 80 and 443 are mapped to IIS?

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 7:25pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/16 "2024-02-23T19:25:13Z")

</div>

> [@Osiris](#):
>
> openresty

that I think if the default site provided by GoDaddy.  
yes i have open 443 and 80 in my router

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 23, 2024, 7:50pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/17 "2024-02-23T19:50:12Z")

</div>

> [@kader2006](#):
>
> that I think if the default site provided by GoDaddy.

So if I understand you correctly that means requests for your website are ending up at GoDaddy and _not_ at _your_ server?

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 8:45pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/18 "2024-02-23T20:45:56Z")

</div>

I opened port 443 on my router for my iis server ip. ah on the other hand port 80 does not want to open for the IIS address it tells me port conflict

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 23, 2024, 8:47pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/19 "2024-02-23T20:47:38Z")

</div>

Is the IP address `3.33.130.190` even the address of your server? (There was a reason why I mentioned it in my post earlier.)

And who is actually hosting your server? You've left that question unanswered. Those questions are there to help us help you. Leaving them completely blank is, in my opinion, disrespectful to the volunteers who are trying to help you.

---

<div class="post-metadata">

**Author:** ![kader2006](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@kader2006](https://community.letsencrypt.org/u/kader2006)\
**Post date:** [February 23, 2024, 9:27pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/20 "2024-02-23T21:27:16Z")

</div>

sorry, This IP is for Godaddy not for my server.  
my ip server is 192.168.0.253 in internal and public add is (38.xxx.xxx.xxx) for my ISP.  
ping [mail.nouakader.com](http://mail.nouakader.com) you see my address.  
thank you for your help .

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 23, 2024, 9:38pm UTC](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775/21 "2024-02-23T21:38:07Z")

</div>

If you want your website to actually work from the public internet, the IP address configured in the DNS needs to be the _public_ IP address of the place where your webserver is actually running.

It seems you're running IIS on your home server and _not_ at GoDaddy? So you'd need to change the IP address in the DNS zone from the GoDaddy IP to your (public) home IP.

This is actually basic networking and not really the scope of this Community.

[Next page](https://community.letsencrypt.org/t/deactivating-pending-authorization-win-acmev2-2-7-1612/213775.md?page=2)
