# Error when trying to renew certificate using docker certbot

**URL:** <https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351>\
**Category:** Help\
**Created:** [November 6, 2022, 9:25am UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351 "2022-11-06T09:25:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ma7gdp](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@ma7gdp](https://community.letsencrypt.org/u/ma7gdp)\
**Post date:** [November 6, 2022, 9:25am UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/1 "2022-11-06T09:25:47Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [ma7gdp.duckdns.org](http://ma7gdp.duckdns.org)

I ran this command:

docker run -it --rm --name certbot -v ":/etc/letsencrypt" -v ":/var/lib/letsencrypt" -p "28443:443" -p "28080:80" certbot/certbot certonly -d [ma7gdp.duckdns.org](http://ma7gdp.duckdns.org) --standalone

It produced this output:

Saving debug log to /var/log/letsencrypt/letsencrypt.log  
An unexpected error occurred:  
requests.exceptions.ConnectionError: HTTPSConnectionPool(host='[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)', port=443): Max retries exceeded with url: /directory (Caused by NewConnectionError('\<urllib3.connection.HTTPSConnection object at 0x7fecb1639990\>: Failed to establish a new connection: [Errno -3] Try again'))  
Ask for help or search for solutions at [https://community.letsencrypt.org](https://community.letsencrypt.org). See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

My web server is (include version): official certbot docker container image

The operating system my web server runs on is (include version): Debian host

My hosting provider, if applicable, is: n/a local home server

I can login to a root shell on my machine (yes or no, or I don't know): yes

Thanks in advance for any help.  
Cheers.

---

<div class="post-metadata">

**Author:** ![ma7gdp](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@ma7gdp](https://community.letsencrypt.org/u/ma7gdp)\
**Post date:** [November 6, 2022, 9:28am UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/2 "2022-11-06T09:28:28Z")

</div>

JFYI I ran the debug here: [Let's Debug](https://letsdebug.net/ma7gdp.duckdns.org/1252662) and it was showing as OK, so I am pretty sure it is not a firewall issue.  
I just stood up a temporary nginx server on the same ports via docker to run this debug, but it is no longer running incase anyone tried to run the debug test again.

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [November 6, 2022, 12:29pm UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/3 "2022-11-06T12:29:16Z")

</div>

where port 28xxx proxyed to? unless port ma6gdp..duckdns.org:80 from outside goes to certbot, it won't work=  
you may better to use other client

---

<div class="post-metadata">

**Author:** ![ma7gdp](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@ma7gdp](https://community.letsencrypt.org/u/ma7gdp)\
**Post date:** [November 6, 2022, 12:51pm UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/4 "2022-11-06T12:51:38Z")

</div>

If you hit 80 from external it is forwarded to 28080 and picked up by certbot container and port mapped back to 80. This all worked ok for the last time I renewed, so not sure what is happening.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [November 6, 2022, 1:02pm UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/5 "2022-11-06T13:02:23Z")

</div>

It seems to have trouble to make an _outgoing_ connection to the ACME API.

That said, I don't know anything about Docker, so no idea on how to debug or fix that.. Perhaps it's as simple as the error message suggest: try again.

---

<div class="post-metadata">

**Author:** ![ma7gdp](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@ma7gdp](https://community.letsencrypt.org/u/ma7gdp)\
**Post date:** [November 6, 2022, 2:09pm UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/6 "2022-11-06T14:09:07Z")

</div>

Well if in doubt then reboot I guess. Seems to have done the trick. I made no changes, just rebooted and it started working. Not great when that happens as you never find out the real cause, but happy its working 🙂 Thanks all for replies.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 6, 2022, 2:09pm UTC](https://community.letsencrypt.org/t/error-when-trying-to-renew-certificate-using-docker-certbot/187351/7 "2022-12-06T14:09:50Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
