# HTTPSConnectionPool(host=‘acme-v02.api.letsencrypt.org’, port=443): Read timed out

**URL:** <https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221>\
**Category:** Help\
**Created:** [March 4, 2020, 7:04am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221 "2020-03-04T07:04:59Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 4, 2020, 7:04am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/1 "2020-03-04T07:04:59Z")

</div>

During the renewal process I get the error message:

Renewing an existing certificate  
Attempting to renew cert ([irish-wolfhound-of-lough-ree.de](http://irish-wolfhound-of-lough-ree.de)) from /etc/letsencrypt/renewal/irish-wolfhound-of-lough-ree.de.conf produced an unexpected error: HTTPSConnectionPool(host=‘[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)’, port=443): Read timed out. (read timeout=45). Skipping.  
All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/irish-wolfhound-of-lough-ree.de/fullchain.pem (failure)

What to do?

Volker

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 4, 2020, 7:30am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/2 "2020-03-04T07:30:41Z")

</div>

Hello. I’ve moved your post to a new topic (with an excessively long title).

Can you post the complete output from Certbot?

Can you also look for the error in `/var/log/letsencrypt/letsencrypt.log` (or wherever the log is), post the traceback, and the last few lines before it?

There could be something wrong with your connectivity to [https://acme-v02.api.letsencrypt.org/](https://acme-v02.api.letsencrypt.org/), but also the service is probably under high load today, so random errors like that are probably going to happen sometimes. 😬

Does it work if you try again?

Does that certificate have an especially large number of (sub)domains?

Does “`curl -v https://acme-v02.api.letsencrypt.org/directory`” work? What does it output?

Can you also fill out the rest of the questionnaire below?

* * *

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you’re using Certbot):

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 4, 2020, 7:41am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/3 "2020-03-04T07:41:20Z")

</div>

There is also a currently ongoing “Security Issue”:  
[https://letsencrypt.status.io/](https://letsencrypt.status.io/)  
 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/e/1/e15405a39cc803a7c9c9ead6e59bbd77f4207132.png)

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/4/e/4ebe662b5c0e4962dd646bc6f77e882cb89924cd.png)

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 4, 2020, 9:04am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/4 "2020-03-04T09:04:50Z")

</div>

Hello,

here are my answers to your questions:

* * *

My domain is: [admin.irish-wolfhound-of-lough-ree.de](http://admin.irish-wolfhound-of-lough-ree.de), [irish-wolfhound-of-lough-ree.de](http://irish-wolfhound-of-lough-ree.de), [www.irish-wolfhound-of-lough-ree.de](http://www.irish-wolfhound-of-lough-ree.de)

I ran this command: certbot renew --force-renewal

It produced this output:  
Saving debug log to /var/log/letsencrypt/letsencrypt.log

* * *

Processing /etc/letsencrypt/renewal/irish-wolfhound-of-lough-ree.de.conf

* * *

Plugins selected: Authenticator apache, Installer apache  
Renewing an existing certificate  
Attempting to renew cert ([irish-wolfhound-of-lough-ree.de](http://irish-wolfhound-of-lough-ree.de)) from /etc/letsencrypt/renewal/irish-wolfhound-of-lough-ree.de.conf produced an unexpected error: HTTPSConnectionPool(host='[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)', port=443): Read timed out. (read timeout=45). Skipping.  
All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/irish-wolfhound-of-lough-ree.de/fullchain.pem (failure)

* * *

All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/irish-wolfhound-of-lough-ree.de/fullchain.pem (failure)

* * *

1 renew failure(s), 0 parse failure(s)

My web server is (include version): Server version: Apache/2.4.18 (Ubuntu) , Server built: 2019-10-08T13:31:25

The operating system my web server runs on is (include version): Linux meerkat 4.15.0-88-generic #88~16.04.1-Ubuntu SMP Wed Feb 12 04:19:15 UTC 2020 x86\_64 x86\_64 x86\_64 GNU/Linux

My hosting provider, if applicable, is: self hosted

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): certbot 0.31.0

* * *

The contents of the log file is:

Interfaces: IAuthenticator, IInstaller, IPlugin  
Entry point: apache = certbot\_apache.entrypoint:ENTRYPOINT  
Initialized: \<certbot\_apache.override\_debian.DebianConfigurator object at 0x7f60c619fda0\>  
2020-03-03 12:02:41,929:DEBUG:certbot.plugins.storage:Plugin storage file /etc/letsencrypt/.pluginstorage.json was empty, no values loaded  
2020-03-03 12:02:41,929:DEBUG:certbot.renewal:no renewal failures  
2020-03-04 06:55:41,898:DEBUG:certbot.main:certbot version: 0.31.0  
2020-03-04 06:55:41,899:DEBUG:certbot.main:Arguments: ['-q']  
2020-03-04 06:55:41,900:DEBUG:certbot.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#apache,PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)  
"/var/log/letsencrypt/letsencrypt.log" 4034 lines, 275692 characters  
chunked=chunked)  
File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 388, in \_make\_request  
self.\_raise\_timeout(err=e, url=url, timeout\_value=read\_timeout)  
File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 308, in \_raise\_timeout  
raise ReadTimeoutError(self, url, "Read timed out. (read timeout=%s)" % timeout\_value)  
urllib3.exceptions.ReadTimeoutError: HTTPSConnectionPool(host='[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)', port=443): Read timed out. (read timeout=45)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):  
File "/usr/lib/python3/dist-packages/certbot/renewal.py", line 452, in handle\_renewal\_request  
main.renew\_cert(lineage\_config, plugins, renewal\_candidate)  
File "/usr/lib/python3/dist-packages/certbot/main.py", line 1193, in renew\_cert  
renewed\_lineage = \_get\_and\_save\_cert(le\_client, config, lineage=lineage)  
File "/usr/lib/python3/dist-packages/certbot/main.py", line 116, in \_get\_and\_save\_cert  
renewal.renew\_cert(config, domains, le\_client, lineage)  
File "/usr/lib/python3/dist-packages/certbot/renewal.py", line 310, in renew\_cert  
new\_cert, new\_chain, new\_key, \_ = le\_client.obtain\_certificate(domains, new\_key)  
File "/usr/lib/python3/dist-packages/certbot/client.py", line 369, in obtain\_certificate  
cert, chain = self.obtain\_certificate\_from\_csr(csr, orderr)  
File "/usr/lib/python3/dist-packages/certbot/client.py", line 301, in obtain\_certificate\_from\_csr  
orderr = self.acme.finalize\_order(orderr, deadline)  
File "/usr/lib/python3/dist-packages/acme/client.py", line 927, in finalize\_order  
return self.client.finalize\_order(orderr, deadline)  
File "/usr/lib/python3/dist-packages/acme/client.py", line 754, in finalize\_order  
self.\_post(orderr.body.finalize, wrapped\_csr)  
File "/usr/lib/python3/dist-packages/acme/client.py", line 96, in \_post  
return self.net.post(\*args, \*\*kwargs)  
File "/usr/lib/python3/dist-packages/acme/client.py", line 1204, in post  
return self.\_post\_once(\*args, \*\*kwargs)  
File "/usr/lib/python3/dist-packages/acme/client.py", line 1217, in \_post\_once  
response = self.\_send\_request('POST', url, data=data, \*\*kwargs)  
File "/usr/lib/python3/dist-packages/acme/client.py", line 1120, in \_send\_request  
response = self.session.request(method, url, \*args, \*\*kwargs)  
File "/usr/lib/python3/dist-packages/requests/sessions.py", line 502, in request  
resp = self.send(prep, \*\*send\_kwargs)  
File "/usr/lib/python3/dist-packages/requests/sessions.py", line 612, in send  
r = adapter.send(request, \*\*kwargs)  
File "/usr/lib/python3/dist-packages/requests/adapters.py", line 516, in send  
raise ReadTimeout(e, request=request)  
requests.exceptions.ReadTimeout: HTTPSConnectionPool(host='[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)', port=443): Read timed out. (read timeout=45)

2020-03-04 09:51:09,885:ERROR:certbot.renewal:All renewal attempts failed. The following certs could not be renewed:  
2020-03-04 09:51:09,885:ERROR:certbot.renewal: /etc/letsencrypt/live/irish-wolfhound-of-lough-ree.de/fullchain.pem (failure)  
2020-03-04 09:51:09,885:DEBUG:certbot.log:Exiting abnormally:  
Traceback (most recent call last):  
File "/usr/bin/certbot", line 11, in   
load\_entry\_point('certbot==0.31.0', 'console\_scripts', 'certbot')()  
File "/usr/lib/python3/dist-packages/certbot/main.py", line 1365, in main  
return config.func(config, plugins)  
File "/usr/lib/python3/dist-packages/certbot/main.py", line 1272, in renew  
renewal.handle\_renewal\_request(config)  
File "/usr/lib/python3/dist-packages/certbot/renewal.py", line 477, in handle\_renewal\_request  
len(renew\_failures), len(parse\_failures)))  
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)

* * *

The output of the curl command is:

- Trying 2606:4700:60:0:f53d:5624:85c7:3a2c...
- Trying 172.65.32.248...
- Connected to [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org) (172.65.32.248) port 443 (#0)
- found 148 certificates in /etc/ssl/certs/ca-certificates.crt
- found 592 certificates in /etc/ssl/certs
- ALPN, offering http/1.1
- SSL connection using TLS1.2 / ECDHE\_RSA\_AES\_256\_GCM\_SHA384
- 

```
   server certificate verification OK

```

- 

```
   server certificate status verification SKIPPED

```

- 

```
   common name: acme-v01.api.letsencrypt.org (matched)

```

- 

```
   server certificate expiration date OK

```

- 

```
   server certificate activation date OK

```

- 

```
   certificate public key: RSA

```

- 

```
   certificate version: #3

```

- 

```
   subject: CN=acme-v01.api.letsencrypt.org

```

- 

```
   start date: Fri, 07 Feb 2020 02:19:13 GMT

```

- 

```
   expire date: Thu, 07 May 2020 02:19:13 GMT

```

- 

```
   issuer: C=US,O=Let's Encrypt,CN=Let's Encrypt Authority X3

```

- 

```
   compression: NULL

```

- ALPN, server accepted to use http/1.1

> GET /directory HTTP/1.1  
> Host: [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)  
> User-Agent: curl/7.47.0  
> Accept: _/_

\< HTTP/1.1 200 OK  
\< Server: nginx  
\< Date: Wed, 04 Mar 2020 09:03:17 GMT  
\< Content-Type: application/json  
\< Content-Length: 658  
\< Connection: keep-alive  
\< Cache-Control: public, max-age=0, no-cache  
\< X-Frame-Options: DENY  
\< Strict-Transport-Security: max-age=604800  
\<  
{  
"FmDmNTw2qP4": "[Adding random entries to the directory](https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417)",  
"keyChange": "[https://acme-v02.api.letsencrypt.org/acme/key-change](https://acme-v02.api.letsencrypt.org/acme/key-change)",  
"meta": {  
"caaIdentities": [  
"[letsencrypt.org](http://letsencrypt.org)"  
],  
"termsOfService": "[https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf](https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf)",  
"website": "[https://letsencrypt.org](https://letsencrypt.org)"  
},  
"newAccount": "[https://acme-v02.api.letsencrypt.org/acme/new-acct](https://acme-v02.api.letsencrypt.org/acme/new-acct)",  
"newNonce": "[https://acme-v02.api.letsencrypt.org/acme/new-nonce](https://acme-v02.api.letsencrypt.org/acme/new-nonce)",  
"newOrder": "[https://acme-v02.api.letsencrypt.org/acme/new-order](https://acme-v02.api.letsencrypt.org/acme/new-order)",  
"revokeCert": "[https://acme-v02.api.letsencrypt.org/acme/revoke-cert](https://acme-v02.api.letsencrypt.org/acme/revoke-cert)"

- Connection #0 to host [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org) left intact

* * *

Best regards,  
Volker

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 4, 2020, 9:18am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/5 "2020-03-04T09:18:51Z")

</div>

I'm not sure if Certbot is unable to connect to [https://acme-v02.api.letsencrypt.org/](https://acme-v02.api.letsencrypt.org/), or if it successfully connects and then it breaks later.

> [@VSiebelink](#):
>
> - Trying 2606:4700:60:0:f53d:5624:85c7:3a2c…
> - Trying 172.65.32.248…
> - Connected to [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org) (172.65.32.248) port 443 (#0)

It looks like curl tries to use IPv6, it fails, and then it uses IPv4, which works.

Does your server have IPv6 connectivity? Does it work?

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 4, 2020, 9:42am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/6 "2020-03-04T09:42:21Z")

</div>

Yes, the server supports IPv6. Just to be sure I have deactivated it and now 'curl' reports:

- Trying 172.65.32.248...
- Connected to [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org) (172.65.32.248) port 443 (#0)
- found 148 certificates in /etc/ssl/certs/ca-certificates.crt
- found 592 certificates in /etc/ssl/certs
- ALPN, offering http/1.1
- SSL connection using TLS1.2 / ECDHE\_RSA\_AES\_256\_GCM\_SHA384
- 

```
   server certificate verification OK

```

- 

```
   server certificate status verification SKIPPED

```

- 

```
   common name: acme-v01.api.letsencrypt.org (matched)

```

- 

```
   server certificate expiration date OK

```

- 

```
   server certificate activation date OK

```

- 

```
   certificate public key: RSA

```

- 

```
   certificate version: #3

```

- 

```
   subject: CN=acme-v01.api.letsencrypt.org

```

- 

```
   start date: Sun, 12 Jan 2020 18:06:08 GMT

```

- 

```
   expire date: Sat, 11 Apr 2020 18:06:08 GMT

```

- 

```
   issuer: C=US,O=Let's Encrypt,CN=Let's Encrypt Authority X3

```

- 

```
   compression: NULL

```

- ALPN, server accepted to use http/1.1

> GET /directory HTTP/1.1  
> Host: [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)  
> User-Agent: curl/7.47.0  
> Accept: _/_

\< HTTP/1.1 200 OK  
\< Server: nginx  
\< Date: Wed, 04 Mar 2020 09:33:11 GMT  
\< Content-Type: application/json  
\< Content-Length: 658  
\< Connection: keep-alive  
\< Cache-Control: public, max-age=0, no-cache  
\< X-Frame-Options: DENY  
\< Strict-Transport-Security: max-age=604800  
\<  
{  
"keyChange": "[https://acme-v02.api.letsencrypt.org/acme/key-change](https://acme-v02.api.letsencrypt.org/acme/key-change)",  
"meta": {  
"caaIdentities": [  
"[letsencrypt.org](http://letsencrypt.org)"  
],  
"termsOfService": "[https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf](https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf)",  
"website": "[https://letsencrypt.org](https://letsencrypt.org)"  
},  
"nG9MF72FHEU": "[Adding random entries to the directory](https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417)",  
"newAccount": "[https://acme-v02.api.letsencrypt.org/acme/new-acct](https://acme-v02.api.letsencrypt.org/acme/new-acct)",  
"newNonce": "[https://acme-v02.api.letsencrypt.org/acme/new-nonce](https://acme-v02.api.letsencrypt.org/acme/new-nonce)",  
"newOrder": "[https://acme-v02.api.letsencrypt.org/acme/new-order](https://acme-v02.api.letsencrypt.org/acme/new-order)",  
"revokeCert": "[https://acme-v02.api.letsencrypt.org/acme/revoke-cert](https://acme-v02.api.letsencrypt.org/acme/revoke-cert)"

- Connection #0 to host [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org) left intact

Nevertheless the renewal still reports an error:

Saving debug log to /var/log/letsencrypt/letsencrypt.log

* * *

Processing /etc/letsencrypt/renewal/irish-wolfhound-of-lough-ree.de.conf

* * *

Plugins selected: Authenticator apache, Installer apache  
Renewing an existing certificate  
Attempting to renew cert ([irish-wolfhound-of-lough-ree.de](http://irish-wolfhound-of-lough-ree.de)) from /etc/letsencrypt/renewal/irish-wolfhound-of-lough-ree.de.conf produced an unexpected error: HTTPSConnectionPool(host='[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)', port=443): Read timed out. (read timeout=45). Skipping.  
All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/irish-wolfhound-of-lough-ree.de/fullchain.pem (failure)

* * *

All renewal attempts failed. The following certs could not be renewed:  
/etc/letsencrypt/live/irish-wolfhound-of-lough-ree.de/fullchain.pem (failure)

* * *

1 renew failure(s), 0 parse failure(s)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 5, 2020, 1:29am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/7 "2020-03-05T01:29:07Z")

</div>

> [@VSiebelink](#):
>
> HTTPSConnectionPool(host=‘[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)’, port=443): Read timed out

Have you checked to ensure DNS is working properly?

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 5, 2020, 6:43am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/8 "2020-03-05T06:43:56Z")

</div>

Yes, nslookup gives me

Server: 127.0.1.1  
Address: 127.0.1.1#53

Non-authoritative answer:  
[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org) canonical name = [prod.api.letsencrypt.org](http://prod.api.letsencrypt.org).  
[prod.api.letsencrypt.org](http://prod.api.letsencrypt.org) canonical name = [ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com](http://ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com).  
Name: [ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com](http://ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com)  
Address: 172.65.32.248

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 5, 2020, 8:59am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/9 "2020-03-05T08:59:57Z")

</div>

127.0.1.1 is a local address…  
Perhaps (at times) the local system is having issues with name resolution or running low on resources or …  
Can you (temporarily) switch to another DNS server?  
Can you show a screenshot of `top` ?

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 5, 2020, 9:35am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/10 "2020-03-05T09:35:46Z")

</div>

Ok, I have changed the nameserver to 8.8.8.8, but the behaviour is unchanged; the command still ends up with “Read timed out”. Here’s the request screenshot of the top command:

 ![grafik](https://global.discourse-cdn.com/letsencrypt/original/3X/0/7/07ae919b0ec40a543f6a6d7e5cd824c2dee2a888.png)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 5, 2020, 9:43am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/11 "2020-03-05T09:43:39Z")

</div>

Definitely NOT an internal resource problem.

- 77.7% unused mem (never used)
- 95.3% free mem
- 99.9% CPU idle
- 0.00% swapfile use [you could probably just turn that off: `swapoff -a`]

So that still leaves testing via another DNS server...

> [@rg305](#):
>
> Can you (temporarily) switch to another DNS server?

Like:  
8.8.8.8, 8.8.4.4  
1.1.1.1, 1.0.0.1  
208.67.222.220, 208.67.222.222  
4.2.2.2, 4.2.2.4

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 5, 2020, 10:08am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/12 "2020-03-05T10:08:21Z")

</div>

> [@rg305](#):
>
> 127.0.1.1 is a local address…

That's also expected on systems running systemd-resolved 😉

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 5, 2020, 10:19am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/13 "2020-03-05T10:19:02Z")

</div>

As mentioned before I switched over to 8.8.8.8 as DNS server.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 5, 2020, 10:20am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/14 "2020-03-05T10:20:51Z")

</div>

Hi @VSiebelink

what says

```auto
traceroute acme-v02.api.letsencrypt.org

```

Perhaps reduce your MTU to 1300 or 1100. Sometimes that helps.

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 5, 2020, 11:03am UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/15 "2020-03-05T11:03:36Z")

</div>

traceroute to [ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com](http://ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com) (172.65.32.248), 64 hops max  
1 10.11.12.1 0,505ms 0,530ms 0,527ms  
2 62.156.244.49 63,755ms 11,780ms 11,738ms  
3 62.156.247.178 12,415ms 12,130ms 12,171ms  
4 217.0.195.205 15,478ms 15,112ms 15,236ms  
5 217.0.195.205 15,084ms 14,749ms 14,830ms  
6 62.157.249.186 15,034ms 14,950ms 14,935ms  
7 \* \* \*  
8 129.250.4.187 15,313ms 15,186ms 15,393ms  
9 213.198.81.142 15,559ms 17,347ms 15,622ms  
10 \* \* \*  
11 \* \* \*  
12 \* \* \*  
13 \* \* \*

‘ping’ is working without any problems.

I don’t think that it is a network issue or something like that, because the automatic renewal of the certificates works for more than a year without any problems.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 5, 2020, 2:09pm UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/16 "2020-03-05T14:09:57Z")

</div>

> [@VSiebelink](#):
>
> I don’t think that it is a network issue or something like that, because the automatic renewal of the certificates works for more than a year without any problems.

Looks like this is a part of your problem.

traceroute / tracert should work.

> D:\temp\>tracert -4 [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org).
> 
> Routenverfolgung zu [ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com](http://ca80a1adb12a4fbdac5ffcbc944e9a61.pacloudflare.com) [172.65.32.248]  
> über maximal 30 Hops:
> 
> 1 \<1 ms \<1 ms \<1 ms fritz.box [192.168.0.1]  
> 2 4 ms 5 ms 5 ms 62.155.240.117  
> 3 7 ms 6 ms 6 ms 217.239.55.2  
> 4 6 ms 5 ms 6 ms 217.239.55.2  
> 5 7 ms 6 ms 6 ms [lag-10.edge4.Berlin1.Level3.net](http://lag-10.edge4.Berlin1.Level3.net) [4.68.73.5]  
> 6 7 ms 6 ms 6 ms [ae-1-3502.edge3.Berlin1.Level3.net](http://ae-1-3502.edge3.Berlin1.Level3.net) [4.69.159.1]  
> 7 6 ms 6 ms 8 ms [unknown.Level3.net](http://unknown.Level3.net) [212.162.40.34]  
> 8 6 ms 5 ms 6 ms 172.65.32.248

Last year Letsencrypt switched to another CDN solution.

> [@New CDN for the Production API](https://community.letsencrypt.org/t/new-cdn-for-the-production-api/102629):
>
> T…

A lot of topics with such connection problems, reducing MTU sometimes helped.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 5, 2020, 2:13pm UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/17 "2020-03-05T14:13:08Z")

</div>

Also, Certbot might be trying to use IPv6.

---

<div class="post-metadata">

**Author:** ![VSiebelink](https://avatars.discourse-cdn.com/v4/letter/v/dc4da7/32.png) [@VSiebelink](https://community.letsencrypt.org/u/VSiebelink)\
**Post date:** [March 5, 2020, 3:38pm UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/18 "2020-03-05T15:38:39Z")

</div>

Hi @JuergenAuer

thank you very much for insisting on changing the MTU! Indeed this was the cause of the problem. After reducing it to 1300 the renewal ran without any complains 🙂

Best regards,  
Volker

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [March 5, 2020, 4:57pm UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/19 "2020-03-05T16:57:42Z")

</div>

> [@VSiebelink](#):
>
> Indeed this was the cause of the problem. After reducing it to 1300 the renewal ran without any complains

Ah, happy to read it had worked. Thanks for reporting back 👍

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 4, 2020, 4:57pm UTC](https://community.letsencrypt.org/t/httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-read-timed-out/115221/20 "2020-04-04T16:57:45Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
