# Invalid response 404, 403 with win-acme and IIS

**URL:** <https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895>\
**Category:** Help\
**Created:** [August 29, 2024, 11:59pm UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895 "2024-08-29T23:59:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![FM2023](https://avatars.discourse-cdn.com/v4/letter/f/ea5d25/32.png) [@FM2023](https://community.letsencrypt.org/u/FM2023)\
**Post date:** [August 29, 2024, 11:59pm UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895/1 "2024-08-29T23:59:46Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [https://matomopoc.serviceconnect.defence.gov.au/](https://matomopoc.serviceconnect.defence.gov.au/)

I ran this command: C:\Win-ACME\>wacs.exe

Please choose from the menu: r

It produced this output:

Plugin IIS generated source matomopoc.serviceconnect.defence.gov.au with 1 identifiers  
Plugin Single created 1 order  
[HTTP] Request completed with status BadRequest  
Error getting renewal information from server  
Renewing [IIS] Default Web Site, (any host)  
Cached order has status invalid, discarding  
[matomopoc.serviceconnect.defence.gov.au] Authorizing...  
[matomopoc.serviceconnect.defence.gov.au] Authorizing using http-01 validation (SelfHosting)  
[matomopoc.serviceconnect.defence.gov.au] Authorization result: invalid  
[matomopoc.serviceconnect.defence.gov.au] {"type":"urn:ietf:params:acme:error:unauthorized","detail":"2620:1ec:bdf::38: Invalid response from [https://matomopoc.serviceconnect.defence.gov.au/.well-known/acme-challenge/F87ZNXM\_4KQq34068kdSRSvPXN\_lEEOL5c-wczgfu24:](https://matomopoc.serviceconnect.defence.gov.au/.well-known/acme-challenge/F87ZNXM_4KQq34068kdSRSvPXN_lEEOL5c-wczgfu24:) 404","status":403,"instance":null}  
[matomopoc.serviceconnect.defence.gov.au] Deactivating pending authorization  
Renewal for [IIS] Default Web Site, (any host) failed, will retry on next run  
Validation failed  
No certificate generated

My web server is (include version): IIS

The operating system my web server runs on is (include version): Windows Server 2022 DC

My hosting provider, if applicable, is: n/a

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): n/a

No proxy in place. Made sure local firewall is disabled. Website is using Win-Acme on the backend via Application Gateway in Azure. Tried setting ValidateServerCertificate to false in settings.json file.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 30, 2024, 12:05am UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895/2 "2024-08-30T00:05:42Z")

</div>

```nohighlight
Addresses: 2620:1ec:bdf::41
           13.107.246.41
Aliases: matomopoc.serviceconnect.defence.gov.au

```

I find that both IPs are serving the same content; So, that's a good thing.

But, the ACME challenge request failure is in HTTPS:

> [@FM2023](#):
>
> detail":"2620:1ec:bdf::38: Invalid response from [https://matomopoc.serviceconnect.defence.gov.au/.well-known/acme-challenge/F87ZNXM\_4KQq34068kdSRSvPXN\_lEEOL5c-wczgfu24:](https://matomopoc.serviceconnect.defence.gov.au/.well-known/acme-challenge/F87ZNXM_4KQq34068kdSRSvPXN_lEEOL5c-wczgfu24:) 404"

That tells me that HTTP is redirecting the ACME challenge requests.  
Seems like a missed opportunity...  
I've never used WACS, so, I can't say if that is expected.  
I have had only success while using [`CertifyTheWeb`](https://certifytheweb.com/) with all my Windows systems.

---

<div class="post-metadata">

**Author:** ![FM2023](https://avatars.discourse-cdn.com/v4/letter/f/ea5d25/32.png) [@FM2023](https://community.letsencrypt.org/u/FM2023)\
**Post date:** [August 30, 2024, 1:15am UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895/3 "2024-08-30T01:15:16Z")

</div>

Thanks. CertifytheWeb renewed the certificate but we need the PFX file from it.  
In MMC, when I try to export the certificate the PFX option is greyed out.

---

<div class="post-metadata">

**Author:** ![webprofusion](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/webprofusion/32/85310_2.png) [@webprofusion](https://community.letsencrypt.org/u/webprofusion)\
**Post date:** [August 30, 2024, 1:34am UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895/4 "2024-08-30T01:34:46Z")

</div>

Hi @FM2023 I'm the developer of Certify The Web. To export the PFX add an _Export Certificate_ deployment task under Tasks, then save and run the task (you don't need to re-request the cert to run the task). Subsequent renewals will automatically run the task.

The task can be configured to export to the local machine file system or a remote windows share, or via SSH (sftp).

Depending on what you need to export the PFX for you might also want to use something like the Deploy to Azure Keyvault (for instance if you wanted to use the same cert on an azure service).

---

<div class="post-metadata">

**Author:** ![FM2023](https://avatars.discourse-cdn.com/v4/letter/f/ea5d25/32.png) [@FM2023](https://community.letsencrypt.org/u/FM2023)\
**Post date:** [August 30, 2024, 1:47am UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895/5 "2024-08-30T01:47:22Z")

</div>

Splendid! Issue is fixed.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 29, 2024, 1:47am UTC](https://community.letsencrypt.org/t/invalid-response-404-403-with-win-acme-and-iis/224895/6 "2024-09-29T01:47:38Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
