# Error when get certificate Invalid response from /.well-known/acme-challenge

**URL:** <https://community.letsencrypt.org/t/error-when-get-certificate-invalid-response-from-well-known-acme-challenge/124526>\
**Category:** Help\
**Created:** [June 1, 2020, 10:41pm UTC](https://community.letsencrypt.org/t/error-when-get-certificate-invalid-response-from-well-known-acme-challenge/124526 "2020-06-01T22:41:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dengerrrr](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dengerrrr](https://community.letsencrypt.org/u/dengerrrr)\
**Post date:** [June 1, 2020, 10:41pm UTC](https://community.letsencrypt.org/t/error-when-get-certificate-invalid-response-from-well-known-acme-challenge/124526/1 "2020-06-01T22:41:42Z")

</div>

My domain is: [dengerrrr.com](http://dengerrrr.com)

I ran this command: sudo certbot certonly --apache

It produced this output:  
IMPORTANT NOTES:

- The following errors were reported by the server:

I have already point an A record

 ![Screen Shot 2020-06-01 at 17.36.06](https://global.discourse-cdn.com/letsencrypt/original/3X/2/9/299c64728d1bc33f74d6d0d847ce84d407950b38.png)

How can I resolve this?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [June 2, 2020, 12:31am UTC](https://community.letsencrypt.org/t/error-when-get-certificate-invalid-response-from-well-known-acme-challenge/124526/2 "2020-06-02T00:31:01Z")

</div>

Are you sure that’s the correct server? Are you running Certbot on the same computer as the Apache server?

Can you post the output of “`sudo apachectl -t -D DUMP_VHOSTS`” and the contents of the Apache virtual host?

Can you also answer the other questions?

* * *

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 2, 2020, 7:52am UTC](https://community.letsencrypt.org/t/error-when-get-certificate-invalid-response-from-well-known-acme-challenge/124526/3 "2020-06-02T07:52:19Z")

</div>

Hi @dengerrrr

> [@dengerrrr](#):
>
> My domain is: [dengerrrr.com](http://dengerrrr.com)

checking your domain via [https://check-your-website.server-daten.de/?q=dengerrrr.com](https://check-your-website.server-daten.de/?q=dengerrrr.com) - that may not work.

Your ip addresses:

| Host | Type | IP-Address | is auth. | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| [dengerrrr.com](http://dengerrrr.com) | A | 35.153.18.54 Ashburn/Virginia/United States (US) - Amazon Technologies Inc. Hostname: [ec2-35-153-18-54.compute-1.amazonaws.com](http://ec2-35-153-18-54.compute-1.amazonaws.com) | yes | 2 | 0 |
| | A | 50.63.202.41 Scottsdale/Arizona/United States (US) - [GoDaddy.com](http://GoDaddy.com), LLC Hostname: [ip-50-63-202-41.ip.secureserver.net](http://ip-50-63-202-41.ip.secureserver.net) | yes | 2 | 0 |
| | A | 184.168.221.48 Scottsdale/Arizona/United States (US) - [GoDaddy.com](http://GoDaddy.com), LLC Hostname: [ip-184-168-221-48.ip.secureserver.net](http://ip-184-168-221-48.ip.secureserver.net) | yes | 2 | 0 |
| | AAAA | | yes | | |
| [www.dengerrrr.com](http://www.dengerrrr.com) | C | [dengerrrr.com](http://dengerrrr.com) | yes | 1 | 0 |

Your www points per CNAME to your non-www.

Your non-www has 3 ip addresses, two from GoDaddy (secureserver), one from Amazon.

So if you run your certbot on your Amazon, Letsencrypt picks the wrong ip to check your domain name.

`• ns37.domaincontrol.com` is one of your name servers, so from GoDaddy.

Update your DNS so only the Amazon ip is used.

PS: IP addresses are public, that's required a browser can find your website. So hiding ip addresses blocks help.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 2, 2020, 7:52am UTC](https://community.letsencrypt.org/t/error-when-get-certificate-invalid-response-from-well-known-acme-challenge/124526/4 "2020-07-02T07:52:20Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
