# Generate ssl certificate

**URL:** <https://community.letsencrypt.org/t/generate-ssl-certificate/173878>\
**Category:** Help\
**Created:** [March 15, 2022, 9:58pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878 "2022-03-15T21:58:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 15, 2022, 9:58pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/1 "2022-03-15T21:58:16Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: usdzradio.live

# nslookup www.usdzradio.live

Server: 169.254.169.254  
Address: 169.254.169.254#53

Non-authoritative answer:  
www.usdzradio.live canonical name = usdzradio.live.  
Name: usdzradio.live  
Address: 34.148.79.147

I ran this command:  
/opt/bitnami/letsencrypt/lego --tls [--email="XXXX.athXXX@gmail.com](mailto:--email=%22XXXX.athXXX@gmail.com)" --domains="usdzradio.live" --domains="www.usdzradio.live" --path="/opt/bitnami/letsencrypt" run

It produced this output:  
2022/03/15 21:38:35 [INFO] [usdzradio.live, www.usdzradio.live] acme: Obtaining bundled SAN certificate  
2022/03/15 21:38:35 [INFO] [usdzradio.live] AuthURL: [https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927300](https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927300)  
2022/03/15 21:38:35 [INFO] [www.usdzradio.live] AuthURL: [https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927310](https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927310)  
2022/03/15 21:38:35 [INFO] [usdzradio.live] acme: use tls-alpn-01 solver  
2022/03/15 21:38:35 [INFO] [www.usdzradio.live] acme: use tls-alpn-01 solver  
2022/03/15 21:38:35 [INFO] [usdzradio.live] acme: Trying to solve TLS-ALPN-01  
2022/03/15 21:38:48 [INFO] [www.usdzradio.live] acme: Trying to solve TLS-ALPN-01  
2022/03/15 21:38:55 [INFO] Deactivating auth: [https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927300](https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927300)  
2022/03/15 21:38:55 [INFO] Deactivating auth: [https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927310](https://acme-v02.api.letsencrypt.org/acme/authz-v3/88006927310)  
2022/03/15 21:38:55 Could not obtain certificates:  
error: one or more domains had a problem:  
[usdzradio.live] acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: SERVFAIL looking up A for usdzradio.live - the domain's nameservers may be malfunctioning; DNS problem: SERVFAIL looking up AAAA for usdzradio.live - the domain's nameservers may be malfunctioning  
[www.usdzradio.live] acme: error: 400 :: urn:ietf:params:acme:error:dns :: DNS problem: SERVFAIL looking up A for www.usdzradio.live - the domain's nameservers may be malfunctioning; DNS problem: SERVFAIL looking up AAAA for www.usdzradio.live - the domain's nameservers may be malfunctioning

My web server is (include version):  
i'm using WordPress with NGINX and SSL Certified by Bitnami and Automattic

nginx version: nginx/1.21.6  
with Wordpress

The operating system my web server runs on is (include version):  
lsb\_release -a  
No LSB modules are available.  
Distributor ID: Debian  
Description: Debian GNU/Linux 10 (buster)  
Release: 10  
Codename: buster

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):  
yes  
I'm using a control panel to manage my site (no, or provide the name and version of the control panel):  
No (wordpress  
The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 15, 2022, 10:09pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/2 "2022-03-15T22:09:41Z")

</div>

> [@Athmane](#):
>
> usdzradio.live.

Your DNSSEC is broken. [usdzradio.live | DNSViz](https://dnsviz.net/d/usdzradio.live/dnssec/)

Did you add the proper DS record at your registrar?

Google should've given it to you when you enabled DNSSEC on their side. (something is very broken considering that Google is both your registrar and your DNS provider. Try waiting a bit.)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [March 15, 2022, 10:09pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/3 "2022-03-15T22:09:48Z")

</div>

You'll have to login to Google Domains and disable DNSSEC on your domain, because it's currently misconfigured. This prevents your domain from functioning at all.

You can set it up again, later if you want.

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 16, 2022, 3:29pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/4 "2022-03-16T15:29:50Z")

</div>

Thanks it worked by disabling DNSSEC

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 16, 2022, 3:30pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/5 "2022-03-16T15:30:25Z")

</div>

Thanks it worked

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 2:33pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/6 "2022-03-19T14:33:24Z")

</div>

thanks the certificate problem is solved, but now i have to figure out how i make reverse proxy out of my nginx

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 19, 2022, 5:18pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/7 "2022-03-19T17:18:44Z")

</div>

> [@Athmane](#):
>
> i have to figure out how i make reverse proxy out of my nginx

`nginx` is pretty much useless as a forward proxy....  
So, you shouldn't too much trouble finding information on "how to" use it for what it was meant for.

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 5:22pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/8 "2022-03-19T17:22:33Z")

</div>

thanks for the answer  
but i need to let this [http://usdzradio.live:8000/mount](http://usdzradio.live:8000/mount) pass under https other wise yi can't listen to my radio

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 19, 2022, 5:28pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/10 "2022-03-19T17:28:44Z")

</div>

`nginx` supports "streams"  
But if you want the client to connect via TLS[HTTPS] and the service isn't doing TLS, then `nginx` will have to proxy (not stream) the HTTPS requests to the HTTP service.

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 5:34pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/11 "2022-03-19T17:34:34Z")

</div>

i tried many combination  
proxy\_pass [http://localhost:8000](http://localhost:8000);  
proxy\_pass [http://usdzradio.live:8000](http://usdzradio.live:8000);

none did work.  
im doing something wrong most probably worst case i will revert to http and stop this ssl certificate

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 19, 2022, 5:38pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/12 "2022-03-19T17:38:27Z")

</div>

inside your (https, and http) server block that serves the blog:

```nohighlight

location /mount {
   proxy_pass http://127.0.0.1:8000/mount;
}

```

(and you probably need more options, which are in [the manual](https://docs.nginx.com/nginx/admin-guide/web-server/reverse-proxy/) and [the documentation](http://nginx.org/en/docs/http/ngx_http_proxy_module.html))

(and after you've seen that it works, make the icecast server only listen on localhost)

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 7:52pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/13 "2022-03-19T19:52:16Z")

</div>

thanks  
it's not working

my icecast is listening on port 8000 and 8443  
i can listen to the music if i go directly using the URL [http://hooggar.com:8443/mount](http://hooggar.com:8443/mount)  
however i can't listen to the music from [https://hooggar.com](https://hooggar.com)

this is my 3rd VM this week i install to get it done lol i will stop

ss -tlpn | grep 443  
LISTEN 0 128 0.0.0.0:443 0.0.0.0:\* users:(("nginx",pid=1344,fd=6),("nginx",pid=1342,fd=6))  
LISTEN 0 5 0.0.0.0:8443 0.0.0.0:\* users:(("icecast2",pid=462,fd=4))

# ss -tlpn | grep 8000

LISTEN 0 5 0.0.0.0:8000 0.0.0.0:\* users:(("icecast2",pid=462,fd=5))

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [March 19, 2022, 8:06pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/14 "2022-03-19T20:06:45Z")

</div>

I don't know how much you know about icecast but many people have struggled with it. One key issue is that the cert file it needs must have both the fullchain and private key in the bundle file. I did not see this mentioned yet in this thread.

Here is another thread with an icecast person from earlier that talks about this and has links to docs.

> [@After renewal, domain.com:8XXX uses old cert](https://community.letsencrypt.org/t/after-renewal-domain-com-8xxx-uses-old-cert/165785/16):
>
> …

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 19, 2022, 8:07pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/15 "2022-03-19T20:07:36Z")

</div>

It looks like icecast and nginx might not play too nice together. There are several example configs online, you might try those.

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 8:18pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/16 "2022-03-19T20:18:12Z")

</div>

yes i did it as it is on the procedure

cat /opt/bitnami/letsencrypt/certificates/hooggar.com.crt /opt/bitnami/letsencrypt/certificates/hooggar.com.key \> /usr/share/icecast2/bundle.pem

my icecast xml file have this values :

```
<listen-socket>
    <port>8000</port>
    <!-- <bind-address>127.0.0.1</bind-address> -->
    <!-- <shoutcast-mount>/stream</shoutcast-mount> -->
</listen-socket>
<!--
<listen-socket>
    <port>8080</port>
</listen-socket>
-->  
<listen-socket>
    <port>8443</port>
    <ssl>1</ssl>
</listen-socket>

```

/usr/share/icecast2/bundle.pem

i can see the hhtps ports listening on

# ss -tlpn | grep 443

LISTEN 0 128 0.0.0.0:443 0.0.0.0:\* users:(("nginx",pid=1746,fd=6),("nginx",pid=1744,fd=6))  
LISTEN 0 5 0.0.0.0:8443 0.0.0.0:\* users:(("icecast2",pid=462,fd=4))

and the http on 🙂

# ss -tlpn | grep 8000

LISTEN 0 5 0.0.0.0:8000 0.0.0.0:\* users:(("icecast2",pid=462,fd=5))

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 8:21pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/17 "2022-03-19T20:21:02Z")

</div>

i dont know if it's thenginx bitnami version or the icecast but defnitely not working.  
the ports are listening but the output with https is not cominng  
thanks for your support

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 19, 2022, 8:24pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/18 "2022-03-19T20:24:05Z")

</div>

Your port 8443 is an http one: [http://hooggar.com:8443/mount](http://hooggar.com:8443/mount)

> [@Athmane](#):
>
> ` <ssl>1</ssl>`

I don't know why it's ignoring this. Did you reload/restart icecast after adding that?

[https://icecast.org/docs/icecast-2.4.1/config-file.html#ports](https://icecast.org/docs/icecast-2.4.1/config-file.html#ports)

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 8:25pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/19 "2022-03-19T20:25:25Z")

</div>

yes i did reboot the server

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 19, 2022, 8:27pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/20 "2022-03-19T20:27:47Z")

</div>

It's pretty strange.

did you see this?

```nohighlight
    <ssl-certificate>/path/to/certificate.pem</ssl-certificate>

```

[https://icecast.org/docs/icecast-2.4.1/config-file.html#path](https://icecast.org/docs/icecast-2.4.1/config-file.html#path)

---

<div class="post-metadata">

**Author:** ![Athmane](https://avatars.discourse-cdn.com/v4/letter/a/eb9ed0/32.png) [@Athmane](https://community.letsencrypt.org/u/Athmane)\
**Post date:** [March 19, 2022, 8:32pm UTC](https://community.letsencrypt.org/t/generate-ssl-certificate/173878/21 "2022-03-19T20:32:01Z")

</div>

(( /usr/share/icecast2/bundle.pem ))

yes the file is there

# ls -l /usr/share/icecast2/

total 24  
drwxr-xr-x 2 root root 4096 Mar 17 14:48 admin  
-rw-r--r-- 1 root root 5560 Mar 19 18:05 bundle.pem  
-rw-r--r-- 1 root root 5560 Mar 17 15:02 icecast.pem.old  
drwxr-xr-x 2 root root 4096 Mar 17 14:51 web

[Next page](https://community.letsencrypt.org/t/generate-ssl-certificate/173878.md?page=2)
