Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is:
I can not provide it.
I ran this command:
It is cron or manual renewal
sudo certbot renew --dry-run
It produced this output:
Processing /etc/letsencrypt/renewal/test.tv.conf
Cert is due for renewal, auto-renewing…
Plugins selected: Authenticator nginx, Installer nginx
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for api.test.tv
http-01 challenge for test.tv
http-01 challenge for www.test.tv
Waiting for verification…
Cleaning up challenges
…
Domain: test.tv
Type: unauthorized
Detail: Invalid response from
https://test.tv/.well-known/acme-challenge/N9mwBk_5P23c2S3kxck3eUv7C1aSNxH3jk-qN1hdNJw
[2606:4700:30::6812:3dee]: “\n\n\n<meta
charset=“utf-8”>\n<meta http-equiv=“X-UA-Compatible”
content=“IE=edge”>\n<meta name=“viewport””
To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
- The following errors were reported by the server:
My web server is (include version):
nginx version: nginx/1.10.3
The operating system my web server runs on is (include version):
debian 9 stretch
My hosting provider, if applicable, is:
abelohost
I can login to a root shell on my machine (yes or no, or I don’t know):
yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):
simple shell, ssh console
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you’re using Certbot):
certbot 0.28.0
As a result, the site is down already about a week, I noticed it only now.
It seems cron is run only after certs expired, which leads to this.
As everything is set up for SSL and only SLL, cert bot requires some http I think.
But nginx, CDN, caches, firewalls are forbidding it.
Direct link test https://api.test.tv/.well-known/acme-challenge/h348_2Nrr8qQfNvuyVfc42triCwdM2BnLq9R_gCnijg
[2019-10-29 04:25:53] app.ERROR: EXCEPTION /var/www/test_api_prod/vendor/symfony/http-kernel/EventListener/RouterListe
ner.php. Message: No route found for "GET /.well-known/acme-challenge/h348_2Nrr8qQfNvuyVfc42triCwdM2BnLq9R_gCnijg". Cod
e: 0 [] []