Failed to renew certificate

I ran this command:
sudo certbot renew

It produced this output:
Failed to renew certificate with error: 'utf-8' codec can't decode byte 0x8c in position 30: invalid start byte

Ubuntu 22.04.3 LTS
Codename:|jammy|

Could you please post the entire output, preferably the entire log?

Also, please don't remove any question from the questionnaire. Here is the rest again:

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

It produced this output:

My web server is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

1 Like

sudo certbot renew

Renewing an existing certificate for *.m10.onedbdev.com

Encountered exception during recovery: KeyError: KeyAuthorizationAnnotatedChallenge(challb=ChallengeBody(chall=DNS01(token=b'\x17v\xbb\xd2+\xf2\xfcB9*Q\x02:\x14/\xaal[\xc2\x18\xe0\xfb\xe0\x1f%\xa6\x19\xfd\x01,\x87\xbf'), uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/343812026667/nNr_CQ', status=Status(pending), validated=None, error=None), domain='m10.onedbdev.com', account_key=(key=<ComparableRSAKey(<cryptography.hazmat.backends.openssl.rsa._RSAPrivateKey object at 0x7fba9771b310>)>))

Failed to renew certificate m10.onedbdev.com with error: 'utf-8' codec can't decode byte 0x8c in position 30: invalid start byte

/etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem (failure)

nginx version: nginx/1.18.0 (Ubuntu)
I can login to a root shell on my machine
The version of my client is certbot 2.7.4

What shows?:
ls -l /etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem
cat /etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem

3 Likes

ls -l /etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem

lrwxrwxrwx 1 root root 45 Jan 22 08:11 /etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem -> ../../archive/m10.onedbdev.com/fullchain2.pem
cat /etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem
i see begin end cert three times

1 Like

@Brankili FYI - the fullchain.pem only contains public information, nothing secret private or needing securing.

cat /etc/letsencrypt/live/m10.onedbdev.com/fullchain.pem

-----BEGIN CERTIFICATE-----
MIIEKDCCAxCgAwIBAgISBD6y4r6m3LYdgabGm2Ekeml2MA0GCSqGSIb3DQEBCwUA
MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
EwJSMzAeFw0yNDAxMjIwNzExMjBaFw0yNDA0MjEwNzExMTlaMB0xGzAZBgNVBAMM
EioubTEwLm9uZWRiZGV2LmNvbTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABImT
Z9GZUDSsZyDzu0/+TVanP9+WSehiuQYSXjaoKEC37VCRPOGD0b+a/j6AWQ3eBIXG
A5hAItNYz9tyxzLlp7ujggIWMIICEjAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYw
FAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFEqV
rg5Ocx3lCn8OcDXZv+FXQguvMB8GA1UdIwQYMBaAFBQusxe3WFbLrlAJQOYfr52L
FMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDovL3IzLm8ubGVu
Y3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5vcmcvMB0GA1Ud
EQQWMBSCEioubTEwLm9uZWRiZGV2LmNvbTATBgNVHSAEDDAKMAgGBmeBDAECATCC
AQYGCisGAQQB1nkCBAIEgfcEgfQA8gB3ADtTd3U+LbmAToswWwb+QDtn2E/D9Me9
AA0tcm/h+tQXAAABjTA5V60AAAQDAEgwRgIhAO4jNVSWIOqbcNP18wiZdRV/k+nc
HLKpMR/trsDsh5IdAiEAr0mfsFiTpiNqEXHnfeXayoTwrDSzIQymt3AF86pA2kcA
dwCi4r/WHt4vLweg1k5tN6fcZUOwxrUuotq3iviabfUX2AAAAY0wOVhAAAAEAwBI
MEYCIQD7qrWKXa5iJdwkBdDZG+shyhIJjEGi5EG9NFFEDtl+SAIhAJhPpmcKeppZ
bp5OjjuqfJjlKH8pc4vzjUVL5TmpYJ2iMA0GCSqGSIb3DQEBCwUAA4IBAQCilVLF
b8DTx7lsRAqYtWZNt+bALsxAYfH3SEIFGRn+9bRnBus0QBX96RUj7aOwyfWyrq8k
7LBeaomOavfdGmHh/XQvLSUafCL0eys0+mYL2MeHiePpI87ateWWFnNoC14FNjvI
/ZA4G430T2JKTmcWgD1OjKc0AGF2Sfc+Iod1er4lAC/01Kb3ulBX63hn5fnoFI3G
1qkJxZDqkOANhgoat1aJiB9q4+9gt5eSM1aqzZhRSzX4dVkETDT/T4yh1b1i78ft
gcZByzOteUzJOi3+jhoBhGvxeJkS5nBMdYRGT+v5t9wiGlV4/cvBNhyfGzoWK69U
0/km/eUnu42CyhXG
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw
WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg
RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP
R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx
sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm
NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg
Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG
/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC
AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB
Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA
FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw
AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw
Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB
gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W
PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl
ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz
CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm
lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4
avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2
yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O
yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids
hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+
HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv
MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX
nLRbwHOoq7hHwg==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/
MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow
TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh
cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB
AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC
ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL
wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D
LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK
4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5
bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y
sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ
Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4
FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc
SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql
PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND
TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw
SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1
c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx
+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB
ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu
b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E
U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu
MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC
5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW
9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG
WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O
he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC
Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5
-----END CERTIFICATE-----
2 Likes

Using the online tool https://unboundtest.com/
Here is what I see https://unboundtest.com/m/TXT/_acme-challenge.m10.onedbdev.com/RKCNTKXY

_acme-challenge.m10.onedbdev.com. 0 IN TXT "clean"

Query results for TXT _acme-challenge.m10.onedbdev.com

Response:
;; opcode: QUERY, status: NOERROR, id: 28253
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version 0; flags: do; udp: 512

;; QUESTION SECTION:
;_acme-challenge.m10.onedbdev.com.	IN	 TXT

;; ANSWER SECTION:
_acme-challenge.m10.onedbdev.com.	0	IN	TXT	"clean"

----- Unbound logs -----
Apr 29 20:29:51 unbound1.19[1918747:0] debug: creating udp6 socket ::1 1053
Apr 29 20:29:51 unbound1.19[1918747:0] debug: creating tcp6 socket ::1 1053
Apr 29 20:29:51 unbound1.19[1918747:0] debug: creating udp4 socket 127.0.0.1 1053
Apr 29 20:29:51 unbound1.19[1918747:0] debug: creating tcp4 socket 127.0.0.1 1053
1 Like

Do you have some solution for my problem?

I was really just suppling supplemental information to assist others and you in debugging.

Also @Brankili I believe you accidently check the solution box on my post; you should be able un-check it too.
image

1 Like

What DNS Plugin are you using?

And here is a list DNS providers who easily integrate with Let's Encrypt DNS validation

1 Like

The third cert [in that file] is unexpected:

1 Like