# Invalid Response Error "Client Lacks Sufficient Authorization"

**URL:** https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176
**Category:** Help
**Created:** [July 19, 2018, 5:19pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176 "2018-07-19T17:19:43Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![bushwacker](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bushwacker](https://community.letsencrypt.org/u/bushwacker)
#### Post date: [July 19, 2018, 5:19pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/1 "2018-07-19T17:19:43Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

## Summary:

-\> Getting certs for all three of the below domains works fine individually, but if we try to specify SANS entries it does ok with the local, but throws error for the other two domains. If we try from the servers hosting autha or authb it fails for the other two domains.

## My domain is:

-\> [gateway.tfs.amerstage.dxcidam.com](http://gateway.tfs.amerstage.dxcidam.com)  
-\> [autha.tfs.amerstage.dxcidam.com](http://autha.tfs.amerstage.dxcidam.com)  
-\> [authb.tfs.amerstage.dxcidam.com](http://authb.tfs.amerstage.dxcidam.com)

## I ran this command:

-\> certbot certonly --csr request.csr --webroot -w /apache/webapps/ --agree-tos --non-interactive --staging -d [autha.tfs.amerstage.dxcidam.com](http://autha.tfs.amerstage.dxcidam.com) -d [authb.tfs.amerstage.dxcidam.com](http://authb.tfs.amerstage.dxcidam.com)

## It produced this output:

Performing the following challenges:  
http-01 challenge for [gateway.tfs.amerstage.dxcidam.com](http://gateway.tfs.amerstage.dxcidam.com)  
http-01 challenge for [autha.tfs.amerstage.dxcidam.com](http://autha.tfs.amerstage.dxcidam.com)  
http-01 challenge for [authb.tfs.amerstage.dxcidam.com](http://authb.tfs.amerstage.dxcidam.com)  
Using the webroot path /abs/apache-tomcat-8.5.13/webapps for all unmatched domains.  
Waiting for verification…  
Cleaning up challenges  
Failed authorization procedure. [autha.tfs.amerstage.dxcidam.com](http://autha.tfs.amerstage.dxcidam.com) (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://autha.tfs.amerstage.dxcidam.com/.well-known/acme-challenge/TZrJbKwo7GxCHKG0zp0kbYw-xWE4lWemjbGGGk5Y6uk:](http://autha.tfs.amerstage.dxcidam.com/.well-known/acme-challenge/TZrJbKwo7GxCHKG0zp0kbYw-xWE4lWemjbGGGk5Y6uk:) “\<!doctype html\>HTTP Status 404 \u2013 Not Foundh1 {font-family:Tahoma,A”, [authb.tfs.amerstage.dxcidam.com](http://authb.tfs.amerstage.dxcidam.com) (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://authb.tfs.amerstage.dxcidam.com/.well-known/acme-challenge/jq8FiZKJ4ir80hhHFov4WQLA3Ba3\_DharDfMUDlzDAQ:](http://authb.tfs.amerstage.dxcidam.com/.well-known/acme-challenge/jq8FiZKJ4ir80hhHFov4WQLA3Ba3_DharDfMUDlzDAQ:) “\<!doctype html\>HTTP Status 404 \u2013 Not Foundh1 {font-family:Tahoma,A”

## My hosting provider, if applicable, is:

-\> AWS

## I can login to a root shell on my machine (yes or no, or I don’t know):

-\> YES

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [July 19, 2018, 5:27pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/2 "2018-07-19T17:27:07Z")

</div>

Hi @bushwacker

> [@bushwacker](#):
>
> http-01 challenge for [gateway.tfs.amerstage.dxcidam.com](http://gateway.tfs.amerstage.dxcidam.com)  
> http-01 challenge for [autha.tfs.amerstage.dxcidam.com](http://autha.tfs.amerstage.dxcidam.com)  
> http-01 challenge for [authb.tfs.amerstage.dxcidam.com](http://authb.tfs.amerstage.dxcidam.com)

the three domains have three different ip-addresses. So if you run the command on the webserver of [gateway.tfs.amerstage.dxcidam.com](http://gateway.tfs.amerstage.dxcidam.com) - can this certbot really copy files to the /.well-known/acme-challenge/ - subdomains of the other two domains?

---

<div class="post-metadata">

### Author: ![bushwacker](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bushwacker](https://community.letsencrypt.org/u/bushwacker)
#### Post date: [July 19, 2018, 5:46pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/3 "2018-07-19T17:46:23Z")

</div>

Hello,

Thank you so much for the quick reply. That is a great question, and I am not sure. All I know is I see the requests reach the other two servers from their access logs. It usually shows four requests from different IPs come in from let’s encrypt:

13.58.30.69 - - [19/Jul/2018:13:44:07 -0400] “GET /.well-known/acme-challenge/UkM95S9DWZhPxp3OeQGvR2dSoLOVUAEzBOTb\_VtOv4Y HTTP/1.1” 404 1140  
66.133.109.36 - - [19/Jul/2018:13:44:07 -0400] “GET /.well-known/acme-challenge/UkM95S9DWZhPxp3OeQGvR2dSoLOVUAEzBOTb\_VtOv4Y HTTP/1.1” 404 1140  
34.213.106.112 - - [19/Jul/2018:13:44:07 -0400] “GET /.well-known/acme-challenge/UkM95S9DWZhPxp3OeQGvR2dSoLOVUAEzBOTb\_VtOv4Y HTTP/1.1” 404 1140  
52.29.173.72 - - [19/Jul/2018:13:44:07 -0400] “GET /.well-known/acme-challenge/UkM95S9DWZhPxp3OeQGvR2dSoLOVUAEzBOTb\_VtOv4Y HTTP/1.1” 404 1140

Thanks,  
Chris

---

<div class="post-metadata">

### Author: ![bushwacker](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bushwacker](https://community.letsencrypt.org/u/bushwacker)
#### Post date: [July 19, 2018, 5:50pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/4 "2018-07-19T17:50:25Z")

</div>

Also, if I put a test page in the acme-challenge folder of any of these servers I can reach them from the server issuing the certbot command, or from a browser with no issues.

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [July 19, 2018, 7:12pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/5 "2018-07-19T19:12:47Z")

</div>

> [@bushwacker](#):
>
> That is a great question, and I am not sure. All I know is I see the requests reach the other two servers from their access logs.

Is there one server with three ip-addresses? If yes, that may work.

If you have three different server, then run certbot on every server, only with

-d domainofthisserver

Actual, you want to create one certificate with three names. But that requires, that certbot can copy the test-files correct.

Instead: Create per website / ip-address one certificate with one name -\> run certbot on every website.

---

<div class="post-metadata">

### Author: ![bushwacker](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bushwacker](https://community.letsencrypt.org/u/bushwacker)
#### Post date: [July 19, 2018, 9:27pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/6 "2018-07-19T21:27:33Z")

</div>

That was it. Thank you so much JuergenAuer… I am new to let’s encrypt / certbot and wasn’t thinking that certbot generates the file in acme-challenge locally that let’s encrypt then reaches in to get for verification - so of course it wouldn’t be able to create on the other servers. Temporarily pointing the other dns records to the same server allowed me to get the cert with all the subject alternative names.

Thank you again.

---

<div class="post-metadata">

### Author: ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)
#### Post date: [July 19, 2018, 10:55pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/7 "2018-07-19T22:55:39Z")

</div>

> [@bushwacker](#):
>
> Temporarily pointing the other dns records to the same server allowed me to get the cert with all the subject alternative names.

A problem with this is that you'll have to repeat this at every subsequent renewal time. If you can't do that, maybe you could make the web servers on the other machines redirect `http://b.example.com/.well-known/acme-challenge` to `http://a.example.com/.well-known/acme-challenge` with an HTTP 301 redirect, where `a.example.com` is the machine where you're running Certbot. (Or else run Certbot separately on each machine, as @JuergenAuer suggested.)

---

<div class="post-metadata">

### Author: ![bushwacker](https://avatars.discourse-cdn.com/v4/letter/b/9de053/32.png) [@bushwacker](https://community.letsencrypt.org/u/bushwacker)
#### Post date: [July 19, 2018, 10:59pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/8 "2018-07-19T22:59:17Z")

</div>

Hello Schoen,

That is a great suggestion. What I did today is definitely untenable it was just a workaround to see if the SANS resolved another issue of mine. I will try to implement what you suggested.

Thanks again.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [August 18, 2018, 10:59pm UTC](https://community.letsencrypt.org/t/invalid-response-error-client-lacks-sufficient-authorization/67176/9 "2018-08-18T22:59:18Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
