# How to set up renewal so it would not need access to port 80?

**URL:** <https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031>\
**Category:** Help\
**Created:** [June 30, 2023, 4:15pm UTC](https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031 "2023-06-30T16:15:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MaciekRyd](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/maciekryd/32/71655_2.png) [@MaciekRyd](https://community.letsencrypt.org/u/MaciekRyd)\
**Post date:** [June 30, 2023, 4:15pm UTC](https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031/1 "2023-06-30T16:15:10Z")

</div>

Lately I had a problem with renewal due to blocked access to port 80.  
After I unlocked it in firewall - renewal ran properly.  
However I'd rather keep this port locked, and have only 443 open for https.  
Any ideas or maybe I am missing something, please?

Best,  
MaciekRyd

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [June 30, 2023, 4:15pm UTC](https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031/2 "2023-06-30T16:15:56Z")

</div>

> **[Best Practice - Keep Port 80 Open - Let's Encrypt](https://letsencrypt.org/docs/allow-port-80/)**
>
> We occasionally get reports from people who have trouble using the HTTP-01 challenge type because they’ve firewalled off port 80 to their web server. Our recommendation is that all servers meant for general web use should offer both HTTP on...

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [June 30, 2023, 4:18pm UTC](https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031/3 "2023-06-30T16:18:48Z")

</div>

Hello @MaciekRyd, welcome to the Let's Encrypt community. 🙂

You would have to not use the [HTTP-01 challenge](https://letsencrypt.org/docs/challenge-types/#http-01-challenge) of the [Challenge Types - Let's Encrypt](https://letsencrypt.org/docs/challenge-types/), most likely that would be the [DNS-01 challenge](https://letsencrypt.org/docs/challenge-types/#dns-01-challenge).

Edit: and as @MikeMcQ points out below the [TLS-ALPN-01](https://letsencrypt.org/docs/challenge-types/#tls-alpn-01)

> [@DNS providers who easily integrate with Let's Encrypt DNS validation](https://community.letsencrypt.org/t/dns-providers-who-easily-integrate-with-lets-encrypt-dns-validation/86438):
>
> I…

**Please fill out the fields below so we can help you better.** Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

Thank you for assisting us in helping **YOU**!

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [June 30, 2023, 4:36pm UTC](https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031/4 "2023-06-30T16:36:08Z")

</div>

> [@MaciekRyd](#):
>
> Any ideas or maybe I am missing something, please?

It would have been helpful to have more answers to the form you were shown and that Bruce re-posted.

But, the TLS-ALPN challenge uses port 443. However, support for this depends on your system. For example, if you use Apache you could look at its `mod_md`

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 30, 2023, 4:36pm UTC](https://community.letsencrypt.org/t/how-to-set-up-renewal-so-it-would-not-need-access-to-port-80/201031/5 "2023-07-30T16:36:49Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
