# (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain

**URL:** <https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711>\
**Category:** Help\
**Created:** [July 14, 2018, 6:14am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711 "2018-07-14T06:14:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![TN-1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@TN-1](https://community.letsencrypt.org/u/TN-1)\
**Post date:** [July 14, 2018, 6:14am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/1 "2018-07-14T06:14:44Z")

</div>

My domain is: hamishwest.xyz

I ran this command: sudo certbot renew --dry-run

It produced this output:

> Saving debug log to /var/log/letsencrypt/letsencrypt.log
> 
> * * *
> 
> ## Processing /etc/letsencrypt/renewal/hamishwest.xyz.conf
> 
> Cert is due for renewal, auto-renewing...  
> Renewing an existing certificate  
> Performing the following challenges:  
> http-01 challenge for hamishwest.xyz  
> http-01 challenge for mail.hamishwest.xyz  
> http-01 challenge for www.hamishwest.xyz  
> Waiting for verification...  
> Cleaning up challenges  
> Unable to clean up challenge directory /var/www/html/.well-known/acme-challenge  
> Attempting to renew cert from /etc/letsencrypt/renewal/hamishwest.xyz.conf produced an unexpected error: Failed authorization procedure. hamishwest.xyz (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk\_U4R1BR\_Bu1ZLaBOfkyKMbE:](http://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk_U4R1BR_Bu1ZLaBOfkyKMbE:) Connection refused, www.hamishwest.xyz (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://www.hamishwest.xyz/.well-known/acme-challenge/WQ7B6WGU223uJ0PtnW-15JW-zBU-rplLxd4damjPOQs:](http://www.hamishwest.xyz/.well-known/acme-challenge/WQ7B6WGU223uJ0PtnW-15JW-zBU-rplLxd4damjPOQs:) Connection refused, mail.hamishwest.xyz (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://mail.hamishwest.xyz/.well-known/acme-challenge/mVr\_amE3JU8lwfo9z9CroXTSIIVXIcPm2DkgdqUWgKM:](http://mail.hamishwest.xyz/.well-known/acme-challenge/mVr_amE3JU8lwfo9z9CroXTSIIVXIcPm2DkgdqUWgKM:) Connection refused. Skipping.  
> \*\* DRY RUN: simulating 'certbot renew' close to cert expiry  
> \*\* (The test certificates below have not been saved.)
> 
> All renewal attempts failed. The following certs could not be renewed:  
> /etc/letsencrypt/live/hamishwest.xyz/fullchain.pem (failure)  
> \*\* DRY RUN: simulating 'certbot renew' close to cert expiry  
> \*\* (The test certificates above have not been saved.)  
> 1 renew failure(s), 0 parse failure(s)
> 
> IMPORTANT NOTES:
> 
> - The following errors were reported by the server:

My web server is (include version): Apache/2.4.25 (Raspbian)

The operating system my web server runs on is (include version): Raspbian GNU/Linux 9 (stretch)

My hosting provider, if applicable, is: N/A

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

.well-know/acme-challenge are all set to 755 with root ownership, and I verified that I am able to access files stored in those directories.  
Thanks in advance!

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 14, 2018, 6:41am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/2 "2018-07-14T06:41:14Z")

</div>

What authenticator are you using? Can you show the contents of `/etc/letsencrypt/renewal/hamishwest.xyz.conf` ?

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [July 14, 2018, 6:59am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/3 "2018-07-14T06:59:51Z")

</div>

Hi @TN-1

> [@TN-1](#):
>
> hamishwest.xyz (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk\_U4R1BR\_Bu1ZLaBOfkyKMbE:](http://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk_U4R1BR_Bu1ZLaBOfkyKMbE:) Connection refused

when calling your file

[http://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk\_U4R1BR\_Bu1ZLaBOfkyKMbE](http://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk_U4R1BR_Bu1ZLaBOfkyKMbE)

I get a 403 - Forbidden. Normally, I should get the file or a 404. So Letsencrypt may be unable to get the file.

So I can't confirm

> [@TN-1](#):
>
> .well-know/acme-challenge are all set to 755 with root ownership, and I verified that I am able to access files stored in those directories.

this. Did you test this per command line using special rights?

---

<div class="post-metadata">

**Author:** ![TN-1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@TN-1](https://community.letsencrypt.org/u/TN-1)\
**Post date:** [July 14, 2018, 7:25am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/4 "2018-07-14T07:25:03Z")

</div>

Hi @_az, Webroot.  
hamishwest.xyz.conf:

> # renew\_before\_expiry = 30 days  
> version = 0.10.2  
> archive\_dir = /etc/letsencrypt/archive/hamishwest.xyz  
> cert = /etc/letsencrypt/live/hamishwest.xyz/cert.pem  
> privkey = /etc/letsencrypt/live/hamishwest.xyz/privkey.pem  
> chain = /etc/letsencrypt/live/hamishwest.xyz/chain.pem  
> fullchain = /etc/letsencrypt/live/hamishwest.xyz/fullchain.pem
> 
> # Options used in the renewal process  
> [renewalparams]  
> authenticator = webroot  
> installer = apache  
> account = 27cd9256103492fd226d7651fb8da477  
> renew\_hook = sh /root/bin/certbot-renew  
> [[webroot\_map]]  
> www.hamishwest.xyz = /var/www/html  
> mail.hamishwest.xyz = /var/www/html  
> hamishwest.xyz = /var/www/html

Hi @JuergenAuer, That was my bad. I had a https rewrite in my .htaccess which I disabled for my test, then reenabled without thinking. With it disabled, the link you mentioned comes with the 404 you expect.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [July 14, 2018, 10:07am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/5 "2018-07-14T10:07:16Z")

</div>

> [@TN-1](#):
>
> I had a https rewrite in my .htaccess which I disabled for my test, then reenabled without thinking. With it disabled, the link you mentioned comes with the 404 you expect.

Yes, now I get the 404. But a rewrite http -\> https should work, it should not produce a 403. Is it possible that there are other rewrite - rules or redirects?

[https://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk\_U4R1BR\_Bu1ZLaBOfkyKMbE](https://hamishwest.xyz/.well-known/acme-challenge/rGDq0UCb8M2INKu-cQrk_U4R1BR_Bu1ZLaBOfkyKMbE) works (with 404), the certificate is valid from 2018-04-25 to 208-07-24.

> [@TN-1](#):
>
> Connection refused

normally indicates, that the webserver can't create a correct connection. Wrong redirects, too many etc.

---

<div class="post-metadata">

**Author:** ![TN-1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@TN-1](https://community.letsencrypt.org/u/TN-1)\
**Post date:** [July 14, 2018, 11:01am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/6 "2018-07-14T11:01:28Z")

</div>

The https redirect was the only rule in my .htaccess, my server has no redirects, symbolics or anything like that.  
This is my apache conf, if it helps:

> \<VirtualHost \*:80\>  
> ServerAdmin webmaster@localhost  
> DocumentRoot /var/www/html
> 
> ErrorLog ${APACHE\_LOG\_DIR}/error.log  
> CustomLog ${APACHE\_LOG\_DIR}/access.log combined
> 
> ```
> AliasMatch ^/.well-known/acme-challenge/(.*)$ /var/www/html/.well-known/acme-challenge/$1
> Alias /.well-known/acme-challenge/ /var/www/html/.well-known/acme-challenge/
> <Directory "/var/www/html/.well-known/acme-challenge/">
> Options None
> AllowOverride None
> ForceType text/plain
> RedirectMatch 404 "^(?!/\.well-known/acme-challenge/[\w-]{43}$)"
> </Directory>
> 
> ```

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [July 14, 2018, 11:19am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/7 "2018-07-14T11:19:23Z")

</div>

I don't understand your configuration.

If this

> [@TN-1](#):
>
> DocumentRoot /var/www/html

is your document root, a GET (browser, Letsencrypt) of

[http://hamishwest.xyz/.well-known/acme-challenge/123456789](http://hamishwest.xyz/.well-known/acme-challenge/123456789)

should send the content of

/var/www/html/.well-known/acme-challenge/123456789

if this file exists. This is the definition of "DocumentRoot". So you don't need the AliasMatch/Alias - rows.

Your Redirect

> [@TN-1](#):
>
> RedirectMatch 404 "^(?!/.well-known/acme-challenge/[\w-]{43}$)"

answers with 404, if Letsencrypt wants to get your file. The token = filename has 43 characters.

---

<div class="post-metadata">

**Author:** ![TN-1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@TN-1](https://community.letsencrypt.org/u/TN-1)\
**Post date:** [July 15, 2018, 6:12am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/8 "2018-07-15T06:12:26Z")

</div>

Honestly, im a programmer, not a sysadmin so this stuff isnt my strong suit at all. For what it is worth though, I didnt add any of that stuff myself, I believe certbot added those lines. Only the ServerAdmin, DocRoot and Log lines are configs that I added.

---

<div class="post-metadata">

**Author:** ![TN-1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@TN-1](https://community.letsencrypt.org/u/TN-1)\
**Post date:** [July 15, 2018, 9:41am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/9 "2018-07-15T09:41:37Z")

</div>

Also, it seems that the auto-renew has worked, I just got a new cert.  
So whatever the issue is, it only affects a manual certbot run.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 14, 2018, 9:41am UTC](https://community.letsencrypt.org/t/http-01-urnerror-connection-the-server-could-not-connect-to-the-client-to-verify-the-domain/66711/10 "2018-08-14T09:41:41Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
