Don't renew some certificates why?

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: techcomputerworld.com and gamesyap.com

I ran this command:
certbot renew

It produced this output:


Processing /etc/letsencrypt/renewal/mail.gamesyap.com.conf


Attempting to parse the version 0.39.0 renewal configuration file found at /etc/letsencrypt/renewal/mail.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert is due for renewal, auto-renewing…
Plugins selected: Authenticator standalone, Installer None
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for mail.gamesyap.com
http-01 challenge for mail.izquierdaanarkista.info
http-01 challenge for mail.techcomputerworld.com
Cleaning up challenges
Attempting to renew cert (mail.gamesyap.com) from /etc/letsencrypt/renewal/mail.gamesyap.com.conf produced an unexpected error: Problem binding to port 80: Could not bind to IPv4 or IPv6… Skipping.


Processing /etc/letsencrypt/renewal/techcomputerworld.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/techcomputerworld.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/test.gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/test.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/web.techcomputerworld.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/web.techcomputerworld.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/prueba.gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/prueba.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/mail.gamesyap.com/fullchain.pem (failure)


The following certs are not due for renewal yet:
/etc/letsencrypt/live/academia.techcomputerworld.com/fullchain.pem expires on 2020-03-16 (skipped)
/etc/letsencrypt/live/despedidasexclusivas.com/fullchain.pem expires on 2020-03-18 (skipped)
/etc/letsencrypt/live/juegos.gamesyap.com/fullchain.pem expires on 2020-04-14 (skipped)
/etc/letsencrypt/live/techcomputerworld.com/fullchain.pem expires on 2020-02-28 (skipped)
/etc/letsencrypt/live/test.gamesyap.com/fullchain.pem expires on 2020-03-14 (skipped)
/etc/letsencrypt/live/gamesyap.com/fullchain.pem expires on 2020-03-07 (skipped)
/etc/letsencrypt/live/web.techcomputerworld.com/fullchain.pem expires on 2020-03-27 (skipped)
/etc/letsencrypt/live/prueba.gamesyap.com/fullchain.pem expires on 2020-03-14 (skipped)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/mail.gamesyap.com/fullchain.pem (failure)


1 renew failure(s), 0 parse failure(s)
root@ubuntu:/home/onzulin# clear
root@ubuntu:/home/onzulin# certbot renew
Saving debug log to /var/log/letsencrypt/letsencrypt.log


Processing /etc/letsencrypt/renewal/academia.techcomputerworld.com.conf


Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/despedidasexclusivas.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/despedidasexclusivas.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/juegos.gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/juegos.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/mail.gamesyap.com.conf


Attempting to parse the version 0.39.0 renewal configuration file found at /etc/letsencrypt/renewal/mail.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert is due for renewal, auto-renewing…
Plugins selected: Authenticator standalone, Installer None
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for mail.gamesyap.com
http-01 challenge for mail.izquierdaanarkista.info
http-01 challenge for mail.techcomputerworld.com
Cleaning up challenges
Attempting to renew cert (mail.gamesyap.com) from /etc/letsencrypt/renewal/mail.gamesyap.com.conf produced an unexpected error: Problem binding to port 80: Could not bind to IPv4 or IPv6… Skipping.


Processing /etc/letsencrypt/renewal/techcomputerworld.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/techcomputerworld.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/test.gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/test.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/web.techcomputerworld.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/web.techcomputerworld.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal


Processing /etc/letsencrypt/renewal/prueba.gamesyap.com.conf


Attempting to parse the version 0.31.0 renewal configuration file found at /etc/letsencrypt/renewal/prueba.gamesyap.com.conf with version 0.28.0 of Certbot. This might not work.
Cert not yet due for renewal
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/mail.gamesyap.com/fullchain.pem (failure)


The following certs are not due for renewal yet:
/etc/letsencrypt/live/academia.techcomputerworld.com/fullchain.pem expires on 2020-03-16 (skipped)
/etc/letsencrypt/live/despedidasexclusivas.com/fullchain.pem expires on 2020-03-18 (skipped)
/etc/letsencrypt/live/juegos.gamesyap.com/fullchain.pem expires on 2020-04-14 (skipped)
/etc/letsencrypt/live/techcomputerworld.com/fullchain.pem expires on 2020-02-28 (skipped)
/etc/letsencrypt/live/test.gamesyap.com/fullchain.pem expires on 2020-03-14 (skipped)
/etc/letsencrypt/live/gamesyap.com/fullchain.pem expires on 2020-03-07 (skipped)
/etc/letsencrypt/live/web.techcomputerworld.com/fullchain.pem expires on 2020-03-27 (skipped)
/etc/letsencrypt/live/prueba.gamesyap.com/fullchain.pem expires on 2020-03-14 (skipped)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/mail.gamesyap.com/fullchain.pem (failure)


1 renew failure(s), 0 parse failure(s)

My web server is (include version): nginx version: nginx/1.14.0 (Ubuntu)

The operating system my web server runs on is (include version):
root@ubuntu:/home/onzulin# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 18.04.3 LTS
Release: 18.04
Codename: bionic

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): certbot 0.28.0

1 Like

The renewal process replicates the last known good procedure.
Which involved --standalone; But that requires spinning up a temporary web server on port 80 which no longer seems possible.
Have you recently installed a web server?
Did you originally stop your web server to obtain certs?

I also see a lot of:

Do you have multiple copies of certbot installed?
Did you downgrade cerbot from 0.31.0 to 0.28.0?

2 Likes

The renewal of certificates does not work, I am still the same, I stop this web server and the same and I do not know if it works because of a domain that I have neither available because it is not mine anymore.
The renewal does not work and does not allow me to revoke and create the certificate again, what can I do?

First, stand by understand what certificates are issued.
We can see the list with:
certbot certificates

From there you can delete whichever are no longer used or no longer belong to you.

Then you can try to renew the ones that remain.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.