# Error starting userland proxy: listen tcp4 0.0.0.0:443: bind: address already in use

**URL:** <https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336>\
**Category:** Help\
**Created:** [February 15, 2024, 9:39am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336 "2024-02-15T09:39:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![korben1989](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/korben1989/32/77596_2.png) [@korben1989](https://community.letsencrypt.org/u/korben1989)\
**Post date:** [February 15, 2024, 9:39am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/1 "2024-02-15T09:39:59Z")

</div>

Hello

My domain is:

- [rentyon.com](http://rentyon.com)

I ran this command:

when I started docker I received a message:

- docker compose -f docker-compose.prod.yml up
- Error response from daemon: driver failed programming external connectivity on endpoint nginx (e0ee73bf9b8a7b6f1dc9da0e111cdb10a2088f9597ff30bd72334d9607fc1ce9): Error starting userland proxy: listen tcp4 0.0.0.0:443: bind: address already in use

Then I checked who is listening on port 443

- sudo lsof -i -P -n | grep 443

Got a reply

- nginx 29804 root 8u IPv6 278268 0t0 TCP \*:443 (LISTEN)
- nginx 29804 root 9u IPv4 278269 0t0 TCP \*:443 (LISTEN)
- nginx 29805 www-data 8u IPv6 278268 0t0 TCP \*:443 (LISTEN)
- nginx 29805 www-data 9u IPv4 278269 0t0 TCP \*:443 (LISTEN)

and the main page of the site gives

- Welcome to nginx!
- If you see this page, the nginx web server is successfully installed and working. Further configuration is required.

The site becomes accessible along the path from the config  
/etc/nginx/sites-enabled/\*;  
with basic settings, if I replace them with my own, the site becomes inaccessible

And I must give from mine  
/etc/nginx/conf.d/\*.conf;

It produced this output:

My web server is (include version):

- nginx version: nginx/1.18.0 (Ubuntu)

The operating system my web server runs on is (include version):

- Ubuntu 22.04 (LTS) x64

My hosting provider, if applicable, is:

- digitalocean

I can login to a root shell on my machine (yes or no, or I don't know):

- yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):  
\*no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

- certbot 1.21.0

How can I solve this problem?

---

<div class="post-metadata">

**Author:** ![webprofusion](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/webprofusion/32/85310_2.png) [@webprofusion](https://community.letsencrypt.org/u/webprofusion)\
**Post date:** [February 15, 2024, 9:50am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/2 "2024-02-15T09:50:23Z")

</div>

I think this means the host you are running docker on already has something on port 443 (e.g. a web server) so docker can't bind to that for your container services.

[Your question is perhaps better suited to stackoverflow, at least to get the answers you need, it's not yet anything to do with Let's Encrypt]

---

<div class="post-metadata">

**Author:** ![Mad182](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mad182/32/77719_2.png) [@Mad182](https://community.letsencrypt.org/u/Mad182)\
**Post date:** [February 15, 2024, 11:01am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/3 "2024-02-15T11:01:27Z")

</div>

You can't run two services on the same port. If it's a freshly installed server and you are NOT using or planing to use nginx for anything (it came preinstalled?), you can just uninstall it. If you ARE using nginx for something else, then you probably can install the other service on a different port and configure nginx as a reverse proxy for it.

---

<div class="post-metadata">

**Author:** ![korben1989](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/korben1989/32/77596_2.png) [@korben1989](https://community.letsencrypt.org/u/korben1989)\
**Post date:** [February 15, 2024, 11:10am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/4 "2024-02-15T11:10:53Z")

</div>

I want to use port 443 for docker,  
how to remove unnecessary nginx?

---

<div class="post-metadata">

**Author:** ![Mad182](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mad182/32/77719_2.png) [@Mad182](https://community.letsencrypt.org/u/Mad182)\
**Post date:** [February 15, 2024, 11:13am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/5 "2024-02-15T11:13:37Z")

</div>

`sudo apt remove nginx`

or you can just stop it for now, if you are not absolutely certain you don't need it.  
`sudo service nginx stop`

---

<div class="post-metadata">

**Author:** ![korben1989](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/korben1989/32/77596_2.png) [@korben1989](https://community.letsencrypt.org/u/korben1989)\
**Post date:** [February 15, 2024, 11:38am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/6 "2024-02-15T11:38:35Z")

</div>

After I stopped nginx  
gives the following message when trying to restart docker with command:

> docker compose -f docker-compose.prod.yml up --build

> nginx | 2024/02/15 11:34:31 [emerg] 1#1: cannot load certificate "/etc/letsencrypt/live/rentyon.com/fullchain.pem": BIO\_new\_file() failed (SSL: error:02001002:system library :fopen:No such file or directory:fopen('/etc/letsencrypt/live/rentyon.com/fullchain.pem','r') error:2006D080:BIO routines:BIO\_new\_file:no such file)

and command

> sudo lsof -i -P -n | grep 443

doesn't show anything

---

<div class="post-metadata">

**Author:** ![webprofusion](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/webprofusion/32/85310_2.png) [@webprofusion](https://community.letsencrypt.org/u/webprofusion)\
**Post date:** [February 16, 2024, 3:09am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/7 "2024-02-16T03:09:16Z")

</div>

> [@korben1989](#):
>
> nginx | 2024/02/15 11:34:31 [emerg] 1#1: cannot load certificate

This means nginx is looking for the certificate file and can't find it. I'm not an nginx expert but I'd suggest removing the https configuration (the listen on port 443 and pointers to the certificate files) then try it all again.

Alternatively if you're not an nginx expert either, try out Caddy ([caddyserver.com](http://caddyserver.com)) instead as it has automatic https.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 17, 2024, 3:09am UTC](https://community.letsencrypt.org/t/error-starting-userland-proxy-listen-tcp4-0-0-0-0-bind-address-already-in-use/213336/8 "2024-03-17T03:09:33Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
