Hi,
I have problems renewing my domain and I can't figure it out why. I believe that it could be related to the HTTP -> HTTPS redirection because it seems that it works for IPv6 but not for IPv4.
When I run the below command (OpenBSD have their own implementation - acme-client
) I can see the following in the nginx logs:
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:33 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 200 87 "http://cloud.bsdbg.net/.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:33 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:34 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 200 87 "http://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:35 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:36 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 200 87 "http://juri.bsdbg.net/.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:58:43 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:58:45 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:45 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:46 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 200 87 "http://cloud.bsdbg.net/.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:46 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:47 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 200 87 "http://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:47 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:48 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 200 87 "http://juri.bsdbg.net/.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:58:52 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:58:52 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:58:53 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:58:54 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:58:55 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:58:56 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:58:57 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:57 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:58 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 200 87 "http://cloud.bsdbg.net/.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:58 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:58:59 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 200 87 "http://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:58:59 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::83 - - [22/Jan/2024:19:59:00 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 200 87 "http://juri.bsdbg.net/.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:05 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:06 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:07 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:59:08 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:59:09 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:59:10 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:59:10 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:59:10 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 200 87 "http://cloud.bsdbg.net/.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
2600:3000:2710:300::88 - - [22/Jan/2024:19:59:11 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 200 87 "http://juri.bsdbg.net/.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:17 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:59:17 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:18 +0200] "GET /.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:19 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:59:19 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:29 +0200] "GET /.well-known/acme-challenge/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
18.216.244.154 - - [22/Jan/2024:19:59:30 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
35.91.114.106 - - [22/Jan/2024:19:59:30 +0200] "GET /.well-known/acme-challenge/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)"
As you can see the IPv6 works, but IPv4 won't. I only get the HTTP/1.1" 301
and nothing more.
Any help will be much appreciated!
My domain is: hodor.bsdbg.net
I ran this command: acme-client -vv hodor.bsdbg.net
It produced this output - here part of the output
acme-client: dochngreq: https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819874
acme-client: transfer buffer: [{ "identifier": { "type": "dns", "value": "cloud.bsdbg.net" }, "status": "pending", "expires": "2024-01-29T17:58:28Z", "challenges": [ { "type": "http-01", "status": "pending", "url": "https:/
/acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/ltyblw", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" }, { "type": "dns-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.or
g/acme/chall-v3/10759819874/PMZV7g", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" }, { "type": "tls-alpn-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/tTs
Djg", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" } ] }] (820 bytes)
acme-client: challenge, token: wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY, uri: https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/ltyblw, status: 0
acme-client: /var/www/acme/wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY: created
acme-client: dochngreq: https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819884
acme-client: transfer buffer: [{ "identifier": { "type": "dns", "value": "hodor.bsdbg.net" }, "status": "invalid", "expires": "2024-01-29T17:58:28Z", "challenges": [ { "type": "http-01", "status": "invalid", "error": { "typ
e": "urn:ietf:params:acme:error:connection", "detail": "During secondary validation: 78.130.168.61: Fetching https://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0: Timeout during con
nect (likely firewall problem)", "status": 400 }, "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819884/MxcCAw", "token": "jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0", "validationRecord": [ { "url"
: "http://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0", "hostname": "hodor.bsdbg.net", "port": "80", "addressesResolved": [ "78.130.168.61", "2001:67c:21bc:68::1", "2001:67c:21bc:4
2::1" ], "addressUsed": "2001:67c:21bc:68::1" }, { "url": "https://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0", "hostname": "hodor.bsdbg.net", "port": "443", "addressesResolved":
[ "78.130.168.61", "2001:67c:21bc:68::1", "2001:67c:21bc:42::1" ], "addressUsed": "2001:67c:21bc:68::1" } ], "validated": "2024-01-22T17:58:33Z" } ] }] (1564 bytes)
acme-client: challenge, token: jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0, uri: https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819884/MxcCAw, status: -1
acme-client: dochngreq: https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819894
acme-client: transfer buffer: [{ "identifier": { "type": "dns", "value": "juri.bsdbg.net" }, "status": "pending", "expires": "2024-01-29T17:58:28Z", "challenges": [ { "type": "http-01", "status": "pending", "url": "https://
acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/o_riIg", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" }, { "type": "dns-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org
/acme/chall-v3/10759819894/DJFRQQ", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" }, { "type": "tls-alpn-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/-C4D
qA", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" } ] }] (819 bytes)
acme-client: challenge, token: bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM, uri: https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/o_riIg, status: 0
acme-client: /var/www/acme/bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM: created
acme-client: https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/ltyblw: challenge
acme-client: transfer buffer: [{ "type": "http-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/ltyblw", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" }] (194
bytes)
acme-client: https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/o_riIg: challenge
acme-client: transfer buffer: [{ "type": "http-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/o_riIg", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" }] (194
bytes)
acme-client: transfer buffer: [{ "status": "invalid", "expires": "2024-01-29T17:58:28Z", "identifiers": [ { "type": "dns", "value": "cloud.bsdbg.net" }, { "type": "dns", "value": "hodor.bsdbg.net" }, { "type": "dns", "value
": "juri.bsdbg.net" } ], "authorizations": [ "https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819874", "https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819884", "https://acme-staging-v02.api.
letsencrypt.org/acme/authz-v3/10759819894" ], "finalize": "https://acme-staging-v02.api.letsencrypt.org/acme/finalize/133398274/13864003414" }] (643 bytes)
acme-client: order.status -1
acme-client: dochngreq: https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819874
acme-client: transfer buffer: [{ "identifier": { "type": "dns", "value": "cloud.bsdbg.net" }, "status": "pending", "expires": "2024-01-29T17:58:28Z", "challenges": [ { "type": "http-01", "status": "pending", "url": "https:/
/acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/ltyblw", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" }, { "type": "dns-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.or
g/acme/chall-v3/10759819874/PMZV7g", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" }, { "type": "tls-alpn-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819874/tTs
Djg", "token": "wqLKC0CfDQyambovY83T5dIHf1fMbG8F7KNoYaJd4cY" } ] }] (820 bytes)
acme-client: dochngreq: https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819884
acme-client: transfer buffer: [{ "identifier": { "type": "dns", "value": "hodor.bsdbg.net" }, "status": "invalid", "expires": "2024-01-29T17:58:28Z", "challenges": [ { "type": "http-01", "status": "invalid", "error": { "typ
e": "urn:ietf:params:acme:error:connection", "detail": "During secondary validation: 78.130.168.61: Fetching https://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0: Timeout during con
nect (likely firewall problem)", "status": 400 }, "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819884/MxcCAw", "token": "jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0", "validationRecord": [ { "url"
: "http://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0", "hostname": "hodor.bsdbg.net", "port": "80", "addressesResolved": [ "78.130.168.61", "2001:67c:21bc:68::1", "2001:67c:21bc:4
2::1" ], "addressUsed": "2001:67c:21bc:68::1" }, { "url": "https://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0", "hostname": "hodor.bsdbg.net", "port": "443", "addressesResolved":
[ "78.130.168.61", "2001:67c:21bc:68::1", "2001:67c:21bc:42::1" ], "addressUsed": "2001:67c:21bc:68::1" } ], "validated": "2024-01-22T17:58:33Z" } ] }] (1564 bytes)
acme-client: During secondary validation: 78.130.168.61: Fetching https://hodor.bsdbg.net/.well-known/acme-challenge/jrhFZ6mdiMK6E4F3_mhSXCBx1GgkXAjbYpUL1sA-Cg0: Timeout during connect (likely firewall problem)
acme-client: dochngreq: https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/10759819894
acme-client: transfer buffer: [{ "identifier": { "type": "dns", "value": "juri.bsdbg.net" }, "status": "pending", "expires": "2024-01-29T17:58:28Z", "challenges": [ { "type": "http-01", "status": "pending", "url": "https://
acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/o_riIg", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" }, { "type": "dns-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org
/acme/chall-v3/10759819894/DJFRQQ", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" }, { "type": "tls-alpn-01", "status": "pending", "url": "https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/10759819894/-C4D
qA", "token": "bqujGRZYZ8B6nOMknd-p7H2zQn4gAtlNQkq7ELuVtaM" } ] }] (819 bytes)
acme-client: bad exit: netproc(39956): 1
My web server is (include version): nginx/1.24.0
I have the following in the config:
server {
listen 80 default_server;
listen [::]:80 default_server;
server_name _;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name hodor.bsdbg.net;
root /htdocs;
ssl_certificate /etc/ssl/bsdbg.fullchain.pem;
ssl_certificate_key /etc/ssl/private/bsdbg.key;
ssl_session_timeout 5m;
ssl_session_cache shared:SSL:1m;
ssl_protocols TLSv1.2;
ssl_ciphers HIGH:!aNULL:!MD5:!RC4;
ssl_prefer_server_ciphers on;
location /.well-known/acme-challenge {
alias /acme/;
try_files $uri =404;
}
.............
The operating system my web server runs on is (include version): OpenBSD 7.4
I can login to a root shell on my machine (yes or no, or I don't know): yes