# IPv6 domain fails during renewal

**URL:** <https://community.letsencrypt.org/t/ipv6-domain-fails-during-renewal/30055>\
**Category:** Help\
**Created:** [March 17, 2017, 1:16am UTC](https://community.letsencrypt.org/t/ipv6-domain-fails-during-renewal/30055 "2017-03-17T01:16:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hogweed](https://avatars.discourse-cdn.com/v4/letter/h/8dc957/32.png) [@hogweed](https://community.letsencrypt.org/u/hogweed)\
**Post date:** [March 17, 2017, 1:16am UTC](https://community.letsencrypt.org/t/ipv6-domain-fails-during-renewal/30055/1 "2017-03-17T01:16:46Z")

</div>

I have a certificate which involves several domains, including one IPv6-only domain.  
I had no trouble creating the certificate, and as of a few weeks ago, all was well when I tested the renewal with the following command:

certbot renew --standalone --dry-run

But now that it is time to do the renewal, it consistently fails with the following mesage:

Attempting to renew cert from /etc/letsencrypt/renewal/gentoo.toadpen.com.conf produced an unexpected error: Failed authorization procedure. [nonmicrosoft.com](http://nonmicrosoft.com) (tls-sni-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Failed to connect to [2600:3c01::f03c:91ff:fe69:89e9]:443 for TLS-SNI-01 challenge, [www.nonmicrosoft.com](http://www.nonmicrosoft.com) (tls-sni-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Failed to connect to [2600:3c01::f03c:91ff:fe69:89e9]:443 for TLS-SNI-01 challenge. Skipping.

I can’t see any problems with my DNS settings, nor any problems communicating with the IPv6 address of the server. It has a perfectly good AAAA record.

The server is running Gentoo, with Apache 2.4.25

Does anyone have any ideas what might be going on here?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 17, 2017, 2:46am UTC](https://community.letsencrypt.org/t/ipv6-domain-fails-during-renewal/30055/2 "2017-03-17T02:46:35Z")

</div>

`certbot --standalone` doesn’t support IPv6. ☹

> <https://github.com/certbot/certbot/issues/1466>

_Let’s Encrypt_ supports it; Certbot’s standalone server just doesn’t.

You can use DNS-01, or HTTP-01 or TLS-SNI-01 with a web server, or even set up some sort of proxy in front of Certbot… Just not, uh, this.

---

<div class="post-metadata">

**Author:** ![hogweed](https://avatars.discourse-cdn.com/v4/letter/h/8dc957/32.png) [@hogweed](https://community.letsencrypt.org/u/hogweed)\
**Post date:** [March 17, 2017, 3:18pm UTC](https://community.letsencrypt.org/t/ipv6-domain-fails-during-renewal/30055/3 "2017-03-17T15:18:10Z")

</div>

Well that explains what the problem is, although I guess I’ll never know why it successfully did a dry run a few weeks ago.

Anyway, using the command ‘certbot renew --apache’ it renewed with no errors, so all is well.

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 16, 2017, 3:18pm UTC](https://community.letsencrypt.org/t/ipv6-domain-fails-during-renewal/30055/4 "2017-04-16T15:18:33Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
