certbot --apache renew

[but i’m going through a dance to remove a site from the cert on this machine, since it no longer exists]. In the past, I’ve just gone through a bunch of help articles and recipes involving manually hacking on /etc/letsencrypt, until the errors go away.

Now I got this error:

There were too many requests of a given type :: Error creating new authz :: too many failed authorizations recently: see Skipping.
All renewal attempts failed. The following certs could not be renewed:

OK, this is news :wink: . So Looking here

There’s all sorts of limits in here. Which one did I hit? When will it clear up, and how do I keep this from bringing my site down…

There's no way to look up this rate limit publicly because it is based on your ACME account and other semi-private information that only the CA can see. In this case though, the rate limit is one hour in duration so it's not long to wait.

The domain-based rate limits, it's another story. You can use or lectl or to check them.

Most importantly: use --dry-run on the end of your Certbot commands, while testing things, to avoid hitting rate limits. It will use the test servers which have extremely high rate limits.

Regarding why you might be experiencing problems, I think that your web server might not be listening on port 443 on its IPv6 address: Let's Debug

# curl -i -6 -L
HTTP/1.1 301 Moved Permanently
Date: Mon, 04 Jun 2018 10:37:48 GMT
Server: Apache/2.4.18 (Ubuntu)
Content-Length: 401
Content-Type: text/html; charset=iso-8859-1

curl: (7) Failed connect to; Connection refused
Got lectl … that is pretty sweet.

It’d be helpful if the help page and the error page language could be synced.

The error page says " Failed Validation limit of 5 failures per account, per hostname, per hour. ".

The error generated by certbot says:

“too many failed authorizations recently”.

I wasn’t able to connect the dots.



