Let encrypt renewal email got again


Hi ,

I got renewal email again today. I renewed last two week. When i check in SSL expiry website, it renewed already. Below is the screenshot when i checked about the ssl. Please have a look and advice for it. How can i check my website is renew or still need to renew.



Previously, on January 17th, you also got a certificate for a number of subdomains:


All those subdomains haven’t been renewed.

The most recent certificate is just for straatosphere.com, not even including the www subdomain.

You can check issued certificates on crt.sh: https://crt.sh/?q=%straatosphere.com

Without any information about the contents of your e-mail, we’re pretty much in the dark.


Hi Osiris,

So, how should i do that for this? Please advice for me.



Hi @aungsithu

you have some active certificates ( https://check-your-website.server-daten.de/?q=straatosphere.com ):

CRT-Id Issuer not before not after Domain names LE-Duplicate next LE
1334636340 CN=“cPanel, Inc. Certification Authority”, O=“cPanel, Inc.”, L=Houston, C=US, ST=TX 2019-03-30 23:00:00 2019-06-29 21:59:59 mail.straatosphere.com, webmail.straatosphere.com
1332173012 CN=Let’s Encrypt Authority X3, O=Let’s Encrypt, C=US 2019-03-28 22:25:17 2019-06-26 21:25:17 straatosphere.com
1119274248 CN=Let’s Encrypt Authority X3, O=Let’s Encrypt, C=US 2019-01-17 10:37:42 2019-04-17 09:37:42 cdn.straatosphere.com, cdn2.straatosphere.com, cdn3.straatosphere.com, cdn4.straatosphere.com, straatosphere.com, www.straatosphere.com
1109744862 CN=“cPanel, Inc. Certification Authority”, O=“cPanel, Inc.”, L=Houston, C=US, ST=TX 2019-01-13 23:00:00 2019-04-14 21:59:59 mail.straatosphere.com, webmail.straatosphere.com

But Letsencrypt doesn’t know if you use the certificate (2019-01-17) with a lot of domain names or if you don’t need that certificate.

So the mail is sent.

But: You have two dns entries:

Host T IP-Address is auth. ∑ Queries ∑ Timeout
straatosphere.com A yes 2 0
AAAA yes
www.straatosphere.com C straatosphere.com yes 1 0
A yes

Your certificate has only one domain name:

expires in 81 days	straatosphere.com - 1 entry

So your www version isn’t secure.

So you should create one certificate with both domain names (non-www and www) and use that.


Hi JuergenAuer,

I run below command

“sudo certbot certonly --nginx -d straatosphere.com -d www.straatosphere.com -d cdn.straatosphere.com -d cdn2.straatosphere.com -d cdn3.straatosphere.com -d cdn4.straatosphere.com

but i got this message. Please advice and how to continue?

"Saving debug log to /var/log/letsencrypt/letsencrypt.log

Plugins selected: Authenticator nginx, Installer nginx

Starting new HTTPS connection (1): acme-v01.api.letsencrypt.org

Cert is due for renewal, auto-renewing…

Renewing an existing certificate

Performing the following challenges:

Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA.

Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA."




How can i renew only for www version please help me and let me know. I run many command line.

It doesn’t work. Please advice me thanks.


How old is your Certbot?

There is a standard template from #help

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot):


This means your certbot version is out of date and it’s likely defaulting to SNI authentication. Update your certbot to have it default to --http or just put --http on the command line. ( --dns is the other option.)


Hi @JuergenAuer,
My version is the following.



That’s quite old.

The Certbot PPA currently has version 0.31.0.

How is Certbot installed? Why isn’t it a newer version?


Hi @mnordhoff,

I don’t know how to upgrade the Certbot version.

When i ran this command “sudo certbot renew --dry-run”, i got this message

" Saving debug log to /var/log/letsencrypt/letsencrypt.log

Processing /etc/letsencrypt/renewal/straatosphere.com-0001.conf

Cert not due for renewal, but simulating renewal for dry run

Plugins selected: Authenticator standalone, Installer nginx

Starting new HTTPS connection (1): acme-staging.api.letsencrypt.org

Running pre-hook command: service nginx stop

Renewing an existing certificate

Performing the following challenges:

http-01 challenge for straatosphere.com

Waiting for verification…

Cleaning up challenges

nginx: [error] open() “/run/nginx.pid” failed (2: No such file or directory)

new certificate deployed with reload of nginx server; fullchain is


Processing /etc/letsencrypt/renewal/straatosphere.com.conf

Cert is due for renewal, auto-renewing…

Plugins selected: Authenticator nginx, Installer nginx

Starting new HTTPS connection (1): acme-staging.api.letsencrypt.org

Renewing an existing certificate

Performing the following challenges:

Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA.

Attempting to renew cert (straatosphere.com) from /etc/letsencrypt/renewal/straatosphere.com.conf produced an unexpected error: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA… Skipping.

The following certs could not be renewed:

/etc/letsencrypt/live/straatosphere.com/fullchain.pem (failure)

** DRY RUN: simulating ‘certbot renew’ close to cert expiry

** (The test certificates below have not been saved.)

The following certs were successfully renewed:

/etc/letsencrypt/live/straatosphere.com-0001/fullchain.pem (success)

The following certs could not be renewed:

/etc/letsencrypt/live/straatosphere.com/fullchain.pem (failure)

** DRY RUN: simulating ‘certbot renew’ close to cert expiry

** (The test certificates above have not been saved.)

Running post-hook command: service nginx start

Hook command “service nginx start” returned error code 1

Error output from service:

Job for nginx.service failed because the control process exited with error code. See “systemctl status nginx.service” and “journalctl -xe” for details.

1 renew failure(s), 0 parse failure(s)".

Please advice me. Thanks.


You use only the standard nginx - option.


to find a newer version.

Or switch to certbot-auto.


Hi @JuergenAuer,

Let me try on this, I will let you know the result. Thanks.



Can i use this instruction?


You’re probably already using the Certbot PPA. It just hasn’t been updated for some reason.

While you can switch to certbot-auto, it’s a bit complicated to do so without causing more problems.

Before doing major surgery, you should confirm how Certbot is installed now.

What do “which certbot”, “sudo which certbot” and “dpkg -l '*certbot*'” show?


Hi @JuergenAuer and @mnordhoff,

how can i continue? Please advice me.



Don’t try certbot-auto for now.

Please answer the questions I asked before.

certbot-auto did show that your system has tons of packages that need to be upgraded.

Try running “sudo apt update”, “sudo apt upgrade” and “sudo apt full-upgrade”.

If Certbot is installed using the PPA packages, that should also upgrade it, and help resolve your other problem.


Hi @mnordhoff,

Can i run below command?



You should run those three commands.

(Actually, since you’re logged in as root, you don’t need to prefix them with “sudo”.)

Can you also run the other commands I asked about to investigate the Certbot situation?


Hi @mnordhoff,

Now i running so many installing. What will be happening? :anguished: . Please let me know.