Hi, the ip address of our mails erver looks to be blocked, ip address:, this is a recently adquired ip address from our dedicated server provider, in a new zimbra installation, thanks in advance

curl -4L

curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to

Mail server, Zimbra 8.8.15

Ubuntu 20.04.4 LTS

certbot 1.26.0 snap version

Hi @asesistel, and welcome to the LE community forum :slight_smile:

That is strange for Ubuntu 20...

What say:
curl -4I
curl -4I

openssl version


Hi, thank you for the support,

curl -4I
HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=UTF-8
Date: Wed, 04 May 2022 01:04:21 GMT
Expires: Fri, 03 Jun 2022 01:04:21 GMT
Cache-Control: public, max-age=2592000
Server: gws
Content-Length: 219
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN

curl -4I
HTTP/2 301
content-type: text/html; charset=UTF-8
date: Wed, 04 May 2022 01:04:26 GMT
expires: Fri, 03 Jun 2022 01:04:26 GMT
cache-control: public, max-age=2592000
server: gws
content-length: 220
x-xss-protection: 0
x-frame-options: SAMEORIGIN
alt-svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"

OpenSSL> version
OpenSSL 1.1.1f 31 Mar 2020

by the way i have another ubuntu 20.04 server than i am configuring zimbra too, on these server the curl -4L output is as follow:
"keyChange": "",
"meta": {
"caaIdentities": [
"termsOfService": "",
"website": ""
"newAccount": "",
"newNonce": "",
"newOrder": "",
"revokeCert": "",
"xcfkT2oXMI0": "Adding random entries to the directory"

is exactly the same software installed on both, i supsect maybe was something with the ip address of the first one: but now i am figuring out there is one diference on the network configuration, the first one --> traffic pass through an aditional router (without NAT, only routed) and the server have two ip address, i don't know if maybe these is the problem the second one is connected directly. What do you recomend i can configure the first server without the aditional router to check if the problem persist

thanks in advance

As shown by your tests, the problem is NOT curl.

Let's check DNS and routing.
dig A
traceroute -I


We've unblocked your IP address. Sorry about the trouble!


Thank you for your help, now i was able to generate the certificate

Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator standalone, Installer None
Requesting a certificate for
Performing the following challenges:
http-01 challenge for
Waiting for verification...
Cleaning up challenges

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/
Key is saved at: /etc/letsencrypt/live/
This certificate expires on 2022-08-02.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.


