Error: Let's Encrypt finalize bad status 403

My domain is: bambisleep.chat

I ran this command: hestiaCP Let' Encrypt checkmark

It produced this output: Let's Encrypt finalize bad status 403 (bambisleep.chat)

The operating system my web server runs on is (include version): debian 12 latest

My hosting provider, if applicable, is: LocalMachine

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): hestiCP

1 Like

Welcome to the Let's Encrypt Community! :slightly_smiling_face:

That's a strange response (403 Forbidden) to get after having successfully completed the domain control challenge(s).

4 Likes

stranger even my other domains on the same server fetch the cert without issues.

2 Likes

What's the domain name that's failing?

Never mind. I see it.

bambisleep.chat

3 Likes

Don't see any initial problems, but that's not surprising.

2 Likes

yeah. weird. very suspiciusly weird.

my registar wasnt able to find anything either.

1 Like

Let me check something... :rabbit2:

3 Likes
2 Likes

I'm not seeing those failures myself, so not a generic failure in staging. :thinking:

3 Likes

did my site get infected with something weird? i checked logs. it was working till yesterday. honest. i literally clicked trough everything my control panel has.
getting a 429 now. ^^

1 Like

I understand now. :man_facepalming:t3:

The primary Let's Encrypt validation server is getting a 404 when trying to read your validation file for an HTTP-01 challenge.

4 Likes

YAY! a possible fix is in sight!

1 Like

finalize says malformed
what is my server malforming?

1 Like

I'm checking... :slightly_smiling_face:

3 Likes

http://bambisleep.chat/.well-known/acme-challenge/OCX1li08exBXUKf1Q4RLQKDi9afJ16qs6_rAXfOEY3c

this address doesn't exist on my site. im running a node application

1 Like

It's created by your ACME client then typically removed after validation.

3 Likes

for namecheaps cert to work it always needs to be there. & i haven't touched it. i haven't touched anything in my control panel in weeks, maybe longer.

1 Like

Let's Encrypt's validation files are one-shot.

4 Likes

you learn something every day.
whats the fix my Leader?

You can't hit that endpoint directly from a browser (without some serious background and tooling). :wink:

It's meant to be used by your ACME client.

4 Likes