Failed to renew certificate

Hi There,

we failed to renew the certificate within Plesk receiving the following message:

Fehler: Could not issue a Let’s Encrypt SSL/TLS certificate for laser-owl.de. Authorization for the domain failed.

Additional error details:
Invalid response from https://acme-v01.api.letsencrypt.org/acme/authz/Ob7fQkzYSmIFVJ-HmYlt46MN_2S4t2qQs8cWYeSRqL4.
Details:
Type: urn:acme:error:connection
Status: 400
Detail: Fetching http://laser-owl.de/.well-known/acme-challenge/fg8kQvEtdPP9QbJ91nPsMbjJeZZ4s8sHKsmPVL9WBy4: Timeout

What can we do?

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

I ran this command: In Plesk “renew certificate”

It produced this output:

Fehler: Could not issue a Let’s Encrypt SSL/TLS certificate for laser-owl.de1. Authorization for the domain failed.

Additional error details:
Invalid response from https://acme-v01.api.letsencrypt.org/acme/authz/Ob7fQkzYSmIFVJ-HmYlt46MN_2S4t2qQs8cWYeSRqL41.
Details:
Type: urn:acme:error:connection
Status: 400
Detail: Fetching http://laser-owl.de/.well-known/acme-challenge/fg8kQvEtdPP9QbJ91nPsMbjJeZZ4s8sHKsmPVL9WBy4: Timeout

My web server is (include version):

Server Parameters
User - Server - IP elbnetz01 - elbnetz.com(2a01:688:4:74::2) Your IP address is: 2003:e3:ebc5:5d00:4fb:8ee5:a0e6:e89e
Server identifier Linux elbnetz02 3.16.0-4-amd64 #1 SMP Debian 3.16.43-2+deb8u5 (2017-09-19) x86_64
Server OS Linux Kernel version: 3.16.0-4-amd64 Web Server Apache
Server Language de-de

The operating system my web server runs on is (include version):
Linux Kernel version: 3.16.0-4-amd64

My hosting provider, if applicable, is:
NMMN

I can login to a root shell on my machine (yes or no, or I don’t know):
The Hosting provider could do

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):
Plesk newest version

You are best to take this to plesk support as they maintain their own plugin and many of the issues we have seen with Plesk has been to do with changes they have made to their plugin

Hi @TF28,

Although I agree with @ahaw021 that Plesk users can usually get better help from the Plesk developers or from the Plesk forum than from this forum, I did do a check to see whether your problem is IPv6-related, which is a common occurrence. It appears to me that your site is listing both IPv4 and IPv6 records in DNS (via A and AAAA DNS records), but the site is only reachable in IPv4. This will cause errors of the kind that you encountered, and is not a Plesk-specific problem.

So, I suggest that you get the hosting provider to fix IPv6 connectivity to your site, or else to remove the AAAA record that advertises an IPv6 address.

1 Like

Thanks,

You mean that the settings are wrong with the service provider, over which the domain was registered?

Cherres, Thorsten

The information provided by the DNS provider doesn’t match what the hosting provider is doing, because the DNS records say that the site is available at the IPv6 address 2001:688:4:74::2 — but it isn’t. It’s not possible for us to say which of these is wrong (that is, whether or not the site should really be available over IPv6), but the reason that you can’t get your certificate is that they don’t agree.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.