# Failed authorization procedure

**URL:** <https://community.letsencrypt.org/t/failed-authorization-procedure/90294>\
**Category:** Server\
**Created:** [April 3, 2019, 7:42pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294 "2019-04-03T19:42:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 3, 2019, 7:42pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/1 "2019-04-03T19:42:11Z")

</div>

hi

i have some issue to get my certificates renewed.

My command is `sudo certbot renew --dry-run -v --webroot -w /var/www/cloud/`

> Attempting to renew cert ([example.com](http://example.com)) from /etc/letsencrypt/renewal/example.com.conf produced an unexpected error: Failed authorization procedure. [example.com](http://example.com) (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://example.com/.well-known/acme-challenge/An0cr\_4l6Kxl2\_f606TPzyxTgJ5eZxNoiYgIP7v\_ri4](http://example.com/.well-known/acme-challenge/An0cr_4l6Kxl2_f606TPzyxTgJ5eZxNoiYgIP7v_ri4) [194.191.224.100]: "\n\n404 Not Found\n\n
> 
> # Not Found
> \n\<p". Skipping.

I verified that port 80 and 443 are open on my firewall and router.

The issue seams to be related to redirection.  
If I open [http://example.com/cloud/.well-known/acme-challenge/test](http://example.com/cloud/.well-known/acme-challenge/test)  
i do get a positive respond

If I open [http://example.com/.well-known/acme-challenge/test](http://example.com/.well-known/acme-challenge/test)  
i do get 404 error

My apache2 config and .htaccess are attached.

[htaccess.txt](https://community.letsencrypt.org/uploads/default/original/3X/9/a/9acd0f45c199e757e1cb19e693663f87e32241de.txt) (3.9 KB)  
[example.com.conf.txt](https://community.letsencrypt.org/uploads/default/original/3X/3/b/3b6056ef89b971c1c005a88551287c7abec219b8.txt) (2.1 KB)

thx for helping

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [April 3, 2019, 7:46pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/2 "2019-04-03T19:46:51Z")

</div>

What’s the rest of Certbot’s output?

What do Apache’s logs show?

* * *

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 3, 2019, 7:59pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/3 "2019-04-03T19:59:20Z")

</div>

Hi @kreutpet

> [@kreutpet](#):
>
> If I open [http://example.com/cloud/.well-known/acme-challenge/test](http://example.com/cloud/.well-known/acme-challenge/test)  
> i do get a positive respond
> 
> If I open [http://example.com/.well-known/acme-challenge/test](http://example.com/.well-known/acme-challenge/test)  
> i do get 404 error

sounds that `/var/www` is your webroot, not `/var/www/cloud`.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 3, 2019, 8:25pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/4 "2019-04-03T20:25:44Z")

</div>

in cerbot i give webroot as parameter.  
logs also show that challenge is created in the right folder : /var/www/cloud/.well-known/acme-challenge/An0cr\_4l6Kxl2\_f606TPzyxTgJ5eZxNoiYgIP7v\_ri4

the GET is done on  
[http://kreutzer.asuscomm.com/.well-known/acme-challenge/An0cr\_4l6Kxl2\_f606TPzyxTgJ5eZxNoiYgIP7v\_ri4](http://kreutzer.asuscomm.com/.well-known/acme-challenge/An0cr_4l6Kxl2_f606TPzyxTgJ5eZxNoiYgIP7v_ri4)

My domain is:  
[kreutzer.asuscomm.com](http://kreutzer.asuscomm.com)

I ran this command:  
see original mail  
sudo certbot renew --dry-run -v --webroot -w /var/www/cloud/

It produced this output:  
[output.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/d/d/dd122581c8cd44d0227f9c305581ffcb4b6f1b46.txt) (2 Bytes)

My web server is (include version):  
Server version: Apache/2.4.29 (Ubuntu)  
Server built: 2018-10-10T18:59:25

The operating system my web server runs on is (include version):  
Distributor ID: Ubuntu  
Description: Ubuntu 18.04.2 LTS  
Release: 18.04  
Codename: bionic

My hosting provider, if applicable, is:  
my own server at home

I can login to a root shell on my machine (yes or no, or I don’t know):  
yes  
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):  
cli

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):  
certbot 0.23.0

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 4, 2019, 5:13am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/5 "2019-04-04T05:13:16Z")

</div>

i recognized that I still have old version installed  
after upgrade i see  
certbot 0.31.0  
here the updated output  
[output.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/e/2/e2938aaa4850539965056d21ecca21ef309ccb07.txt) (20.7 KB)

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 4, 2019, 7:45am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/6 "2019-04-04T07:45:49Z")

</div>

> [@kreutpet](#):
>
> here the updated output

I don't see a direct error.

But webroot should always work.

If webroot doesn't work:

- You have different vHosts with different webroots, another vHost is used
- the webroot (Apache: DocumentRoot) is wrong or not defined
- there are additional locations
- there are incompatible redirects
- an application / firewall / proxy server answers

But there are no wrong redirects visible ( [https://check-your-website.server-daten.de/?q=kreutzer.asuscomm.com](https://check-your-website.server-daten.de/?q=kreutzer.asuscomm.com) ):

| Domainname | Http-Status | redirect | Sec. | G |
| --- | --- | --- | --- | --- |
| • [http://kreutzer.asuscomm.com/](http://kreutzer.asuscomm.com/) | | | | |
| 194.191.224.100 | 302 | [http://kreutzer.asuscomm.com/login](http://kreutzer.asuscomm.com/login) | 0.120 | D |
| | | | | |
| • [http://kreutzer.asuscomm.com/login](http://kreutzer.asuscomm.com/login) | 500 | | 0.120 | S |
| Internal Server Error | | | | |
| | | | | |
| • [https://kreutzer.asuscomm.com/](https://kreutzer.asuscomm.com/) | | | | |
| 194.191.224.100 | 302 | [https://kreutzer.asuscomm.com/login](https://kreutzer.asuscomm.com/login) | 0.723 | A |
| | | | | |
| • [https://kreutzer.asuscomm.com/login](https://kreutzer.asuscomm.com/login) | 500 | | 0.367 | S |
| Internal Server Error | | | | |
| | | | | |
| • [http://kreutzer.asuscomm.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](http://kreutzer.asuscomm.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de) | | | | |
| 194.191.224.100 | 404 | | 0.077 | A |
| Not Found | | | | |
| Visible Content: Not Found The requested URL /.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de was not found on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request. | | | | |

Checking /.well-known/acme-challenge/unknown-file there is the expected http status 404 - Not Found.

Create a test file in your DocumentRoot (file name 1234) and check, if you can load that in your browser.

The same with a file in `DocumentRoot/.well-known/acme-challenge`.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 4, 2019, 9:02am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/7 "2019-04-04T09:02:17Z")

</div>

strange is that the challenge file is created in the right location.  
/var/www/cloud/.well-known/acme-challenge/An0cr\_4l6Kxl2\_f606TPzyxTgJ5eZxNoiYgIP7v\_ri4

I can also see a manually created file in  
[http://kreutzer.asuscomm.com/](http://kreutzer.asuscomm.com/) **cloud** /.well-known/acme-challenge

but this get is always redirected to https

is see my nexcloud page only in [https://kreutzer.asuscomm.com/](https://kreutzer.asuscomm.com/) **cloud** /.  
and not in [http://kreutzer.asuscomm.com](http://kreutzer.asuscomm.com).

can i configure the apache2 in a way that my nextcloud is also reachable on [https://kreutzer.asuscomm.com](https://kreutzer.asuscomm.com) ? i always have to add /cloud to the URL  
I have tryed make an alia but this also did not solfe the letsencrypt certificate renew

thx

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 4, 2019, 9:09am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/8 "2019-04-04T09:09:03Z")

</div>

> [@kreutpet](#):
>
> I can also see a manually created file in  
> [http://kreutzer.asuscomm.com/](http://kreutzer.asuscomm.com/) **cloud** /.well-known/acme-challenge

As written: That's the wrong directory.

Letsencrypt checks /.well-known/, not /cloud/.well-known.

Remove /cloud/.

And remove that redirect to the login page.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 4, 2019, 9:13am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/9 "2019-04-04T09:13:31Z")

</div>

You can’t choose an own directory.

You have to use the standard address

```auto
http://yourdomain/.well-known/acme-challenge/challenge-file

```

So Certbot must know where to create the file.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 4, 2019, 11:38am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/10 "2019-04-04T11:38:30Z")

</div>

yes cerbot creates the file in the right directory.  
but when it validates it is no looking into the right location .  
Thats why i was thinking that it must be on my side that the validation is redirected, but i cannot see any configuration that redirects it

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 4, 2019, 12:51pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/11 "2019-04-04T12:51:06Z")

</div>

> [@kreutpet](#):
>
> yes cerbot creates the file in the right directory.

That's wrong. You use the wrong directory, so Certbot creates the file in the wrong place.

> [@kreutpet](#):
>
> but when it validates it is no looking into the right location .

The location is defined (RFC 8555 - [RFC 8555 - Automatic Certificate Management Environment (ACME)](https://tools.ietf.org/html/rfc8555) ).

You can't choose your own location.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 5, 2019, 5:57pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/12 "2019-04-05T17:57:39Z")

</div>

ok, now reconfigure so that the web page does not need /cloud in the url.  
I checked again the

> **[Make your website better](https://check-your-website.server-daten.de/?q=kreutzer.asuscomm.com)**
>
> Check your redirects http - https, your preferred version (www vs. non-www), certificates, connections and your html-content. A ranking system shows, if your domain is A+ (no errors + preload), has errors (https - http) or loops.

According above the [http://kreutzer.asuscomm.com/](http://kreutzer.asuscomm.com/) is redirected to [http://kreutzer.asuscomm.com/login](http://kreutzer.asuscomm.com/login)

i also created a file /var/www/cloud/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de  
and according above web page get a  
[http://kreutzer.asuscomm.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](http://kreutzer.asuscomm.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de)  
“Visible Content: Not Found The requested URL /.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de was not found on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.”

so i a still lost .  
what configuration in the .conf of apache or .htaccess prevent me to get access for the http challange file?  
[htaccess.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/c/4/c497dbab0b41da6a0faa247fc1fc72509ea78b7a.txt) (2.8 KB)  
[kreutzer.asuscomm.com.conf.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/2/7/276d475687b885ce8acf2ab5075c0268d61f8f7e.txt) (7.8 KB)

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 5, 2019, 7:24pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/13 "2019-04-05T19:24:14Z")

</div>

> [@kreutpet](#):
>
> what configuration in the .conf of apache or .htaccess prevent me to get access for the http challange file?  
> [htaccess.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/c/4/c497dbab0b41da6a0faa247fc1fc72509ea78b7a.txt) (2.8 KB)  
> [kreutzer.asuscomm.com.conf.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/2/7/276d475687b885ce8acf2ab5075c0268d61f8f7e.txt) (7.8 KB)

Checking your config:

```nohighlight
DocumentRoot /var/www/cloud 

```

is your DocumentRoot, so create the two subdirectories

```nohighlight
/var/www/cloud/.well-known/acme-challenge

```

there a file 1234 with content, then test, if that file is visible.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 5, 2019, 7:28pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/14 "2019-04-05T19:28:59Z")

</div>

i already created  
/var/www/cloud/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de and used you link to verify.

i cannot see the file and get above error  
[http://kreutzer.asuscomm.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de](http://kreutzer.asuscomm.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de)

> Not Found  
> The requested URL /.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de was not found on this server.
> 
> Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.  
> thx for your patient

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 5, 2019, 7:33pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/15 "2019-04-05T19:33:08Z")

</div>

> [@kreutpet](#):
>
> i cannot see the file and get above

Then you must have other definitions, so your vHost isn't used.

Are there symlinks in /sites-enabled?

What says

```nohighlight
apachectl configtest
apachectl -S

```

And you have a long .htaccess. Perhaps remove / comment some parts to check that.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 5, 2019, 7:56pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/16 "2019-04-05T19:56:58Z")

</div>

> [@JuergenAuer](#):
>
> apachectl configtest apachectl -S

sudo apachectl -S  
AH00548: NameVirtualHost has no effect and will be removed in the next release /etc/apache2/conf-enabled/virtual.conf:4  
VirtualHost configuration:  
\*:80 [kreutzer.asuscomm.com](http://kreutzer.asuscomm.com) (/etc/apache2/sites-enabled/kreutzer.asuscomm.com.conf:1)  
\*:443 [kreutzer.asuscomm.com](http://kreutzer.asuscomm.com) (/etc/apache2/sites-enabled/kreutzer.asuscomm.com.conf:25)  
ServerRoot: "/etc/apache2"  
Main DocumentRoot: "/var/www/html"  
Main ErrorLog: "/var/log/apache2/error.log"  
Mutex ssl-stapling: using\_defaults  
Mutex proxy: using\_defaults  
Mutex ssl-cache: using\_defaults  
Mutex default: dir="/var/lock/apache2" mechanism=fcntl  
Mutex watchdog-callback: using\_defaults  
Mutex rewrite-map: using\_defaults  
Mutex ssl-stapling-refresh: using\_defaults  
PidFile: "/var/run/apache2/apache2.pid"  
Define: DUMP\_VHOSTS  
Define: DUMP\_RUN\_CFG  
Define: MODPERL2  
User: name="www-data" id=33  
Group: name="www-data" id=33

very strange that Main DocumentRoot: "/var/www/html"  
i do have a sites-available/000-default.conf which contain this configuration but it is not enabled

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 5, 2019, 7:59pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/17 "2019-04-05T19:59:49Z")

</div>

> [@kreutpet](#):
>
> very strange that Main DocumentRoot: “/var/www/html”

To test: Create the two subdirectories there. And a test file.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 5, 2019, 8:30pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/18 "2019-04-05T20:30:38Z")

</div>

ls -l /var/www/html/.well-known/acme-challenge/  
insgesamt 8  
-rwxr-xr-x 1 www-data www-data 6 Apr 5 22:21 check-your-website-dot-server-daten-dot-de  
-rwxr-xr-x 1 www-data www-data 6 Apr 5 22:21 test

but renew command is not sucessful.  
still i think is cannot be as cerbot shows:  
Attempting to save validation to /var/www/cloud/.well-known/acme-challenge/jbt0wb9dRSkYy7KdVlRtgEt420RA9tbVKBNY2EpzFRg

here the output [output.txt](https://global.discourse-cdn.com/letsencrypt/original/3X/a/5/a584c15be2d4d7efeab571cd790df1352265f962.txt) (20.7 KB)

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [April 5, 2019, 8:39pm UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/19 "2019-04-05T20:39:45Z")

</div>

Remove your complete .htaccess.

Looks like there are some definitions (blocking, wrong redirect or something else).

webroot should always work if there is a running webserver.

---

<div class="post-metadata">

**Author:** ![kreutpet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kreutpet/32/30984_2.png) [@kreutpet](https://community.letsencrypt.org/u/kreutpet)\
**Post date:** [April 6, 2019, 10:24am UTC](https://community.letsencrypt.org/t/failed-authorization-procedure/90294/20 "2019-04-06T10:24:06Z")

</div>

the only way to get certificate is to stop apache and to use standalone  
sudo letsencrypt certonly --standalone --domain [kreutzer.asuscomm.com](http://kreutzer.asuscomm.com)

i will try renew next time with pre and post hooks to start / stop apache.  
hope that helps

[Next page](https://community.letsencrypt.org/t/failed-authorization-procedure/90294.md?page=2)
