# I got the connection error, but i can't figure out why

**URL:** <https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987>\
**Category:** Help\
**Created:** [October 26, 2021, 2:40am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987 "2021-10-26T02:40:49Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 26, 2021, 2:40am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/1 "2021-10-26T02:40:49Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [fancytank.com](http://fancytank.com)

I ran this command:

1. sudo certbot --authenticator webroot --installer apache --webroot-path /home/pi/public\_html/portfolio -d [fancytank.com](http://fancytank.com)
2. [https://check-your-website.server-daten.de/?q=fancytank.com](https://check-your-website.server-daten.de/?q=fancytank.com)

It produced this output:

1. Failed authorization procedure. [fancytank.com](http://fancytank.com) (http-01): urn:ietf:params:acme:error:connection :: The server could not connect to the client to verify the domain
2. V - ConnectFailure - Unable to connect to the remote server

My web server is (include version): Apache/2.4.38

The operating system my web server runs on is (include version): Raspbian GNU/Linux 10 (buster)

My hosting provider, if applicable, is: hosting.kr

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 0.31.0

I was trying to renew my SSL certificate but keep failing.  
I can connect my site through just "http", but everytime I try to use certbot, it keep telling me the errors above. I don't understand why.  
I checked my ufw status, the ports 80, 443, and the other ports for port forwarding are also opened.  
What am I missing here?  
Could anyone help me to find my mistakes here? Please..I am spending over a week to figure out 😭

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 26, 2021, 3:35am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/2 "2021-10-26T03:35:39Z")

</div>

> [@2jiwon](#):
>
> Could anyone help me to find my mistakes here?

I would suggest two things:

1. Maybe order matters [slim chance], try:  
`sudo certbot --installer apache --authenticator webroot --webroot-path /home/pi/public_html/portfolio -d fancytank.com`
2. Maybe `Apache` is at it again... [high probability]  
`Apache` is notorious for running at all cost.  
Please confirm all is in order with:  
`sudo apachectl -t -D DUMP_VHOSTS`  
[if you are unsure, just post the output here]

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 26, 2021, 4:53am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/3 "2021-10-26T04:53:53Z")

</div>

Thank you for the reply.

I tried the second one and the output is below.

```nohighlight
AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the 'ServerName' directive globally to suppress this message 
VirtualHost configuration:   
*:80 127.0.1.1 (/etc/apache2/sites-enabled/000-default.conf:1)   
*:8080 is a NameVirtualHost
         default server fancytank.com (/etc/apache2/sites-enabled/001-fancytank.com.conf:3) 
         port 8080 namevhost fancytank.com (/etc/apache2/sites-enabled/001-fancytank.com.conf:3)
         port 8080 namevhost thrive.fancytank.com (/etc/apache2/sites-enabled/002-thrive.fancytank.com.conf:3)
         port 8080 namevhost blog.fancytank.com (/etc/apache2/sites-enabled/003-blog.fancytank.com.conf:3)

```

Does it say like I should set the 'ServerName' in the configuration file?  
I am confused because I set it already.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 26, 2021, 6:56am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/4 "2021-10-26T06:56:37Z")

</div>

Does `http://fancytank.com` reach this server on **port `8080`** or **port `80`**?

And also, show file:  
`/etc/apache2/sites-enabled/001-fancytank.com.conf`

Don't worry about that error message "Could not reliably determine the server's fully qualified domain name, using 127.0.1.1."

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 26, 2021, 7:15am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/5 "2021-10-26T07:15:55Z")

</div>

http use 8080 port becuase i port forwarded 80 to 8080 (also 443 to 8081)

and the conf file is below.

```nohighlight
Listen 8080

<VirtualHost *:8080>
  DocumentRoot /home/pi/public_html/portfolio
  ServerName fancytank.com
  ErrorLog /var/log/apache2/fancytank.com-error_log
  CustomLog /var/log/apache2/fancytank.com-access_log combined
  ServerAdmin ljwjulian@gmail.com

  <Directory /home/pi/public_html/portfolio>
    DirectoryIndex index.html index.php
    Options FollowSymLinks
    AllowOverride All
    Require all granted
  </Directory>

</VirtualHost>

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 26, 2021, 7:30am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/7 "2021-10-26T07:30:41Z")

</div>

Try:

```nohighlight
sudo certbot certonly \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com --dry-run

```

If that works, then try:

```nohighlight
sudo certbot \
-i apache --http-01-port 8080 --https-port 8081 \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com --dry-run

```

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 26, 2021, 7:33am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/8 "2021-10-26T07:33:39Z")

</div>

I tried this

```nohighlight
sudo certbot certonly \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com --dry-run

```

and

```nohighlight
Failed authorization procedure. fancytan.com (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from https://sedo.com/search/details/?partnerid=324561&language=us&domain=fancytan.com&origin=sales_lander_1&utm_medium=Parking&utm_campaign=offerpage [2606:4700::6810:55b]: "<html lang=\"en-US\">\n<head><style>.async-hide { opacity: 0 !important} </style><script>(function(a,s,y,n,c,h,i,d,e){s.className+="

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 26, 2021, 7:34am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/9 "2021-10-26T07:34:36Z")

</div>

> [@2jiwon](#):
>
> `Invalid response from https://sedo.com/search/details`

How does that happen?

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 26, 2021, 7:36am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/10 "2021-10-26T07:36:34Z")

</div>

Ooops, sorry!!  
It was a typo mistake!!

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 26, 2021, 7:37am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/11 "2021-10-26T07:37:35Z")

</div>

Please just copy and paste what I posted (if possible).

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 26, 2021, 7:39am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/12 "2021-10-26T07:39:30Z")

</div>

Sorry. I just ran the second one. This time, I copy and paste it.  
And this is the result.

`usage: certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ... Certbot can obtain and install HTTPS/TLS/SSL certificates. By default, it will attempt to use a webserver both for obtaining and installing the certificate. certbot: error: unrecognized arguments: --https-port 8081`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 26, 2021, 8:09am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/13 "2021-10-26T08:09:37Z")

</div>

> [@2jiwon](#):
>
> certbot 0.31.0

Can you update the version?  
If not, then try:

```nohighlight
sudo certbot \
-i apache --http-01-port 8080 \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com --dry-run

```

And you haven't told me if any of the other commands were successful OR if all failed.

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 27, 2021, 12:59am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/14 "2021-10-27T00:59:27Z")

</div>

I tried to update the version but it says it's already the newest version.

and I also tried the command and the results says

`--dry-run currently only works with the 'certonly' or 'renew' subcommands ('run')`

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 27, 2021, 1:03am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/15 "2021-10-27T01:03:57Z")

</div>

Oh and yes, I ran this command

```nohighlight
sudo certbot certonly \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com --dry-run

```

then it said "the dry run was successful", so I ran this command after

```nohighlight
sudo certbot \
-i apache --http-01-port 8080 --https-port 8081 \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com --dry-run

```

Then, the result was below. (I already posted it)

`usage: certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ... Certbot can obtain and install HTTPS/TLS/SSL certificates. By default, it will attempt to use a webserver both for obtaining and installing the certificate. certbot: error: unrecognized arguments: --https-port 8081`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 27, 2021, 2:33am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/16 "2021-10-27T02:33:23Z")

</div>

> [@2jiwon](#):
>
> "the dry run was successful"

Progress!

I would try:

```nohighlight
sudo certbot \
-i apache --http-01-port 8080 \
--webroot -w /home/pi/public_html/portfolio \
-d fancytank.com

```

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 27, 2021, 2:37am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/17 "2021-10-27T02:37:42Z")

</div>

😭 😭 😭

The result said "congratulations!"  
But when I try to open the site, it doesn't connect and the test site  
[https://www.ssllabs.com/ssltest/analyze.html?d=fancytank.com](https://www.ssllabs.com/ssltest/analyze.html?d=fancytank.com)  
also says this  
`Assessment failed: Unable to connect to the server`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 27, 2021, 2:41am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/18 "2021-10-27T02:41:17Z")

</div>

Please follow my instructions more closely.  
I did not ask for you to try to connect to the site securely - that is not yet possible.  
We've only taken some small steps.  
_You must learn to walk before you can run._

Please show the outputs of:  
`certbot certificates`  
`sudo apachectl -t -D DUMP_VHOSTS`

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 27, 2021, 2:48am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/19 "2021-10-27T02:48:00Z")

</div>

`sudo certbot certificates`

* * *

Found the following certs:  
Certificate Name: [blog.fancytank.com](http://blog.fancytank.com)  
Domains: [blog.fancytank.com](http://blog.fancytank.com)  
Expiry Date: 2021-12-11 15:13:54+00:00 (VALID: 45 days)  
Certificate Path: /etc/letsencrypt/live/blog.fancytank.com/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/blog.fancytank.com/privkey.pem  
Certificate Name: [fancytank.com](http://fancytank.com)  
Domains: [fancytank.com](http://fancytank.com)  
Expiry Date: 2022-01-25 01:34:51+00:00 (VALID: 89 days)  
Certificate Path: /etc/letsencrypt/live/fancytank.com/fullchain.pem  
Private Key Path: /etc/letsencrypt/live/fancytank.com/privkey.pem

* * *

`sudo apachectl -t -D DUMP_VHOSTS`

```nohighlight
AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the 'ServerName' directive globally to suppress this message
VirtualHost configuration:
*:80 127.0.1.1 (/etc/apache2/sites-enabled/000-default.conf:1)
*:443 fancytank.com (/etc/apache2/sites-enabled/001-fancytank.com-le-ssl.conf:2)
*:8080 is a NameVirtualHost
default server fancytank.com (/etc/apache2/sites-enabled/001-fancytank.com.conf:3)
port 8080 namevhost fancytank.com (/etc/apache2/sites-enabled/001-fancytank.com.conf:3)
port 8080 namevhost thrive.fancytank.com (/etc/apache2/sites-enabled/002-thrive.fancytank.com.conf:3)
port 8080 namevhost blog.fancytank.com (/etc/apache2/sites-enabled/003-blog.fancytank.com.conf:3)

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 27, 2021, 3:07am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/20 "2021-10-27T03:07:05Z")

</div>

Now all we need to do is to modify the `Listen` on port `443` to `Listen` on port `8081` in the file:  
`/etc/apache2/sites-enabled/001-fancytank.com-le-ssl.conf`

[and restart `Apache`]

---

<div class="post-metadata">

**Author:** ![2jiwon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/2jiwon/32/25668_2.png) [@2jiwon](https://community.letsencrypt.org/u/2jiwon)\
**Post date:** [October 27, 2021, 4:56am UTC](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987/21 "2021-10-27T04:56:35Z")

</div>

Oh my god. It works 🤗 🤗 🤗  
Thank you, thank you so much. 🤩

[Next page](https://community.letsencrypt.org/t/i-got-the-connection-error-but-i-cant-figure-out-why/163987.md?page=2)
