# Help with error when requesting new SSL certificate (nginx proxy manager)

**URL:** <https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181>\
**Category:** Help\
**Created:** [November 3, 2022, 12:12am UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181 "2022-11-03T00:12:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jjnether](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjnether/32/65299_2.png) [@jjnether](https://community.letsencrypt.org/u/jjnether)\
**Post date:** [November 3, 2022, 12:12am UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/1 "2022-11-03T00:12:18Z")

</div>

I'm not too experienced in this, so would greatly appreciate help!

My domain is: [jjnether.duckdns.com](http://jjnether.duckdns.com)

I'm using nginx proxy manager, and I'm trying to create a new proxy host. I get this error when trying to create a new SSL certificate (see log below and image: [Imgur: The magic of the Internet](https://imgur.com/oWFvfw5)).

It says internal error. The log for npm is below

I'm using duckdns for the domain, and my goal is to provide outside access to my overseerr server.

I'm running with docker on a synology NAS (DSM 7.1.1-42962 Update 2)

I used this guide to install npm: [How to Install Nginx Proxy Manager on Your Synology NAS – Marius Hosting](https://mariushosting.com/how-to-install-nginx-proxy-manager-on-your-synology-nas/)

Log:

```nohighlight
[11/3/2022] [12:36:14 AM] [Nginx] › ℹ info Reloading Nginx
Saving debug log to /var/log/letsencrypt/letsencrypt.log
[11/3/2022] [12:36:23 AM] [Express] › ⚠ warning Command failed: certbot certonly --config "/etc/letsencrypt.ini" --cert-name "npm-4" --agree-tos --authenticator webroot --email "jjnether@gmail.com" --preferred-challenges "dns,http" --domains "jjnether.duckdns.org" 
[11/3/2022] [12:36:19 AM] [SSL] › ℹ info Command: certbot certonly --config "/etc/letsencrypt.ini" --cert-name "npm-4" --agree-tos --authenticator webroot --email "jjnether@gmail.com" --preferred-challenges "dns,http" --domains "jjnether.duckdns.org" 
[11/3/2022] [12:36:19 AM] [SSL] › ℹ info Requesting Let'sEncrypt certificates for Cert #4: jjnether.duckdns.org
Some challenges have failed.
[11/3/2022] [12:36:22 AM] [Nginx] › ℹ info Reloading Nginx

```

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [November 3, 2022, 1:18am UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/2 "2022-11-03T01:18:53Z")

</div>

We'd probably need to see the contents of the `/var/log/letsencrypt/letsencrypt.log` file. The output from npm doesn't really reveal much.

---

<div class="post-metadata">

**Author:** ![jjnether](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjnether/32/65299_2.png) [@jjnether](https://community.letsencrypt.org/u/jjnether)\
**Post date:** [November 3, 2022, 2:10pm UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/3 "2022-11-03T14:10:13Z")

</div>

Thanks for the response. I don't actually have a `/var/log/letsencrypt` directory... not sure where I should find the log you're looking for.

In case I have something setup wrong, my docker compose for npm is below:

```nohighlight
...
    app:
        image: 'jc21/nginx-proxy-manager:latest'
        container_name: npm
        restart: always
        ports:
          - '8341:80'
          - '81:81'
          - '8766:443'
        volumes:
          - /volume1/docker/npm/config.json:/app/config/production.json
          - /volume1/docker/npm/data:/data
          - /volume1/docker/npm/letsencrypt:/etc/letsencrypt

```

Here you can see me trying to find that directory with ssh: [Imgur: The magic of the Internet](https://imgur.com/9cFBrAg)

Perhaps it's a permissions issue?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 3, 2022, 5:06pm UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/4 "2022-11-03T17:06:16Z")

</div>

Try finding it with:  
`find / -name letsencrypt.log`

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [November 3, 2022, 5:08pm UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/5 "2022-11-03T17:08:01Z")

</div>

Hopefully is a small and fast filesystem. 😄

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 3, 2022, 5:08pm UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/6 "2022-11-03T17:08:44Z")

</div>

> [@jjnether](#):
>
> ```nohighlight
> ports:
> - '8341:80'
> - '81:81'
> - '8766:443'
> 
> ```

That seems to use non-standard ports [externally].  
In order to use `HTTP-01` authentication, the external port 80 must reach your ACME client.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [November 3, 2022, 5:10pm UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/7 "2022-11-03T17:10:54Z")

</div>

> [@rg305](#):
>
> In order to use `HTTP-01` authentication, the external port 80 must reach your ACME client.

[Best Practice - Keep Port 80 Open](https://letsencrypt.org/docs/allow-port-80/)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 3, 2022, 5:11pm UTC](https://community.letsencrypt.org/t/help-with-error-when-requesting-new-ssl-certificate-nginx-proxy-manager/187181/8 "2022-12-03T17:11:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
