# Having problems obtaining an SSL certificate

**URL:** <https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731>\
**Category:** Help\
**Created:** [September 6, 2023, 9:07pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731 "2023-09-06T21:07:47Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 6, 2023, 9:07pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/1 "2023-09-06T21:07:47Z")

</div>

My domain is: [selbyironworks.com](http://selbyironworks.com)

I ran this command: sudo certbot --nginx --redirect -d [selbyironworks.com](http://selbyironworks.com) -d [www.selbyironworks.com](http://www.selbyironworks.com)  
It produced this output:  
Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Requesting a certificate for [selbyironworks.com](http://selbyironworks.com) and [www.selbyironworks.com](http://www.selbyironworks.com)

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:  
Domain: [selbyironworks.com](http://selbyironworks.com)  
Type: unauthorized  
Detail: 2001:19f0:5:4e63:5400:4ff:fe90:6da2: Invalid response from [http://selbyironworks.com/.well-known/acme-challenge/FisXBiyRohebtiV\_JapUt14sHbX3RTKSceqMIoY40ps:](http://selbyironworks.com/.well-known/acme-challenge/FisXBiyRohebtiV_JapUt14sHbX3RTKSceqMIoY40ps:) 404

Domain: [www.selbyironworks.com](http://www.selbyironworks.com)  
Type: unauthorized  
Detail: 2001:19f0:5:4e63:5400:4ff:fe90:6da2: Invalid response from [http://www.selbyironworks.com/.well-known/acme-challenge/zQ96OgvwwB2HUM\_B2zXvkFSn4PVV0ZvRcbzO26hzqs4:](http://www.selbyironworks.com/.well-known/acme-challenge/zQ96OgvwwB2HUM_B2zXvkFSn4PVV0ZvRcbzO26hzqs4:) 404

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Some challenges have failed.  
Ask for help or search for solutions at [https://community.letsencrypt.org](https://community.letsencrypt.org). See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

My web server is (include version): Nginx

The operating system my web server runs on is (include version): Debian 12 x64

My hosting provider, if applicable, is: vultr

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

root@vultr:~# netstat -an | grep LISTEN  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:80 0.0.0.0:\* LISTEN  
tcp6 0 0 :::22 :::\* LISTEN  
tcp6 0 0 :::80 :::\* LISTEN  
unix 2 [ACC] STREAM LISTENING 15966 /run/user/0/systemd/private  
unix 2 [ACC] STREAM LISTENING 15975 /run/user/0/bus  
unix 2 [ACC] STREAM LISTENING 15982 /run/user/0/gnupg/S.dirmngr  
unix 2 [ACC] STREAM LISTENING 15984 /run/user/0/gnupg/S.gpg-agent.browser  
unix 2 [ACC] STREAM LISTENING 15986 /run/user/0/gnupg/S.gpg-agent.extra  
unix 2 [ACC] STREAM LISTENING 15988 /run/user/0/gnupg/S.gpg-agent.ssh  
unix 2 [ACC] STREAM LISTENING 15990 /run/user/0/gnupg/S.gpg-agent  
unix 2 [ACC] STREAM LISTENING 13326 /run/systemd/private  
unix 2 [ACC] STREAM LISTENING 13328 /run/systemd/userdb/io.systemd.DynamicUser  
unix 2 [ACC] STREAM LISTENING 13329 /run/systemd/io.system.ManagedOOM  
unix 2 [ACC] STREAM LISTENING 13340 /run/systemd/fsck.progress  
unix 2 [ACC] STREAM LISTENING 13348 /run/systemd/journal/stdout  
unix 2 [ACC] SEQPACKET LISTENING 13350 /run/udev/control  
unix 2 [ACC] STREAM LISTENING 13790 /run/systemd/journal/io.systemd.journal  
unix 2 [ACC] STREAM LISTENING 15285 /run/dbus/system\_bus\_socket

thank you for your time.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 9:12pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/2 "2023-09-06T21:12:19Z")

</div>

Welcome @selbyironworks

A 404 error with the --nginx plug-in is usually something unusual in the nginx server block configuration. Can you upload the config.txt file from this command

```plaintext
sudo nginx -T >config.txt

```

capital T is essential

Also, I am curious. I see you got a wildcard cert a couple days ago. That would have required using a DNS Challenge. Why are you now switching to --nginx plug-in and HTTP Challenge?

---

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 6, 2023, 9:35pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/3 "2023-09-06T21:35:20Z")

</div>

I'm still learning about this process, so I appreciate your patience. I'm using the --nginx plug-in and HTTP Challenge because I'm trying to set up a simple static website for my business. I was using Bluehost to make my website, but I didn't need everything they were offering, so I canceled it and I want to make a static website. I'm a noob at this and only know basic Linux

nginx: the configuration file /etc/nginx/nginx.conf syntax is ok

nginx: configuration file /etc/nginx/nginx.conf test is successful

Thanks again for your help.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 9:40pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/4 "2023-09-06T21:40:43Z")

</div>

> [@MikeMcQ](#):
>
> ```nohighlight
> sudo nginx -T >config.txt
> 
> ```
> 
> **capital T is essential**

Please try again with capital T. Thanks for explaining about prior situation

---

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 6, 2023, 9:41pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/5 "2023-09-06T21:41:52Z")

</div>

root@vultr:~# sudo nginx -T \>config.txt

nginx: the configuration file /etc/nginx/nginx.conf syntax is ok

nginx: configuration file /etc/nginx/nginx.conf test is successful

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 9:49pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/6 "2023-09-06T21:49:54Z")

</div>

I am looking for the contents of the `config.txt` file. Can you upload that?

There is an upload button on the post menu (has an up arrow).

---

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 6, 2023, 9:53pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/7 "2023-09-06T21:53:28Z")

</div>

I opened the config.txt file and there is nothing in it.

---

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 6, 2023, 10:26pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/8 "2023-09-06T22:26:21Z")

</div>

[config.txt](https://community.letsencrypt.org/uploads/short-url/qQbKbK9GmoHGdBLdNQFBW4m5xcZ.txt) (8.4 KB)

---

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 6, 2023, 10:26pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/9 "2023-09-06T22:26:52Z")

</div>

sorry I think I found it

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 10:34pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/10 "2023-09-06T22:34:47Z")

</div>

Yes, that's it 🙂  
This file

```plaintext
# configuration file /etc/nginx/sites-enabled/selbyironworks.com:

```

should look like below instead. You are missing the listen statement for IPv6. So, when Let's Encrypt makes an IPv6 HTTP request it goes to your default server instead which is listening for IPv6.

```plaintext
# configuration file /etc/nginx/sites-enabled/selbyironworks.com:
server {
  listen 80;
  listen [::]:80; # THIS IS THE MISSING LINE
  server_name selbyironworks.com www.selbyironworks.com;

  location / {
    root /var/www/html/selbyironworks.com;
    index index.html;
  }
}

```

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [September 6, 2023, 10:36pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/11 "2023-09-06T22:36:12Z")

</div>

Note this:

(it's usually the other way around)

```plaintext
C:\Users\peppe>curl -IL6 http://selbyironworks.com/
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Wed, 06 Sep 2023 22:34:30 GMT
Content-Type: text/html
Content-Length: 615
Last-Modified: Wed, 06 Sep 2023 17:59:43 GMT
Connection: keep-alive
ETag: "64f8be0f-267"
Accept-Ranges: bytes

C:\Users\peppe>curl -IL4 http://selbyironworks.com/
HTTP/1.1 403 Forbidden
Server: nginx/1.22.1
Date: Wed, 06 Sep 2023 22:34:38 GMT
Content-Type: text/html
Content-Length: 153
Connection: keep-alive

```

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 10:40pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/12 "2023-09-06T22:40:33Z")

</div>

> [@9peppe](#):
>
> Note this:
> 
> (it's usually the other way around)

Did we cross-post?

Yeah, it almost looks like IPv4 in DNS is pointing to a different nginx than what is shown here. I don't see anything in their nginx config to cause that 403.

But, the IPv6 fix I showed should fix the cert problem anyway. Well, at least they need that listen clause for IPv6 so we'll see 🙂

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [September 6, 2023, 10:44pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/13 "2023-09-06T22:44:36Z")

</div>

I don't know. I noticed the validation failing with an IPv6 and I started checking if that was the same machine on IPv4 -- it looks like it's the same machine.

Also, it answers fine without SNI:

```plaintext
C:\Users\peppe>curl -IL [2001:19f0:5:4e63:5400:4ff:fe90:6da2]
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Wed, 06 Sep 2023 22:31:46 GMT
Content-Type: text/html
Content-Length: 615
Last-Modified: Wed, 06 Sep 2023 17:59:43 GMT
Connection: keep-alive
ETag: "64f8be0f-267"
Accept-Ranges: bytes

C:\Users\peppe>curl -IL 144.202.6.17
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Wed, 06 Sep 2023 22:32:57 GMT
Content-Type: text/html
Content-Length: 615
Last-Modified: Wed, 06 Sep 2023 17:59:43 GMT
Connection: keep-alive
ETag: "64f8be0f-267"
Accept-Ranges: bytes

```

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 10:51pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/14 "2023-09-06T22:51:34Z")

</div>

> [@9peppe](#):
>
> Also, it answers fine without SNI:

The missing `listen` explains the cert fail. Your non-sni hit the default server. Not sure why 403 with IPv4 and sni but one at a time

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 6, 2023, 10:54pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/15 "2023-09-06T22:54:53Z")

</div>

Try moving the "`root`" statement outside the "`location`" block.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 10:58pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/16 "2023-09-06T22:58:53Z")

</div>

> [@rg305](#):
>
> Try moving the "`root`" statement

That won't affect certbot using Nginx plugin. Maybe it could explain the 403

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 6, 2023, 11:02pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/17 "2023-09-06T23:02:22Z")

</div>

I was trying to fix the 403.

To that end...  
I'd also insert the following into that "`location`" block:  
`try_files $uri $uri/ =404;`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 6, 2023, 11:05pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/18 "2023-09-06T23:05:13Z")

</div>

As for the `--nginx` plugin failing...  
I'd move the relevant server block into it's own "`.conf`" file and place it in the included directory.  
`include /etc/nginx/conf.d/*.conf;`

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 6, 2023, 11:24pm UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/19 "2023-09-06T23:24:43Z")

</div>

> [@rg305](#):
>
> As for the `--nginx` plugin failing...  
> I'd move the relevant server block into it's own "`.conf`" file and place it in the included directory.

Why don't you like it in the sites-enabled folder? It already was its own config file there

---

<div class="post-metadata">

**Author:** ![selbyironworks](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@selbyironworks](https://community.letsencrypt.org/u/selbyironworks)\
**Post date:** [September 7, 2023, 12:39am UTC](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731/20 "2023-09-07T00:39:28Z")

</div>

Thank you everyone, I have resolved the issue.

[Next page](https://community.letsencrypt.org/t/having-problems-obtaining-an-ssl-certificate/204731.md?page=2)
