Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: sakshi.ddns.net
I ran this command: sudo /usr/syno/sbin/syno-letsencrypt new-cert -d sakshi.ddns.net -m sathishbs@gmail.com -v
It produced this output:
DEBUG: ==== start to new cert ====
DEBUG: Server: https://acme-v02.api.letsencrypt.org/directory
DEBUG: Email: sathishbs@gmail.com
DEBUG: Domain: sakshi.ddns.net
DEBUG: ==========================
DEBUG: setup acme url https://acme-v02.api.letsencrypt.org/directory
DEBUG: GET Request: https://acme-v02.api.letsencrypt.org/directory
DEBUG: GET Request: https://acme-v02.api.letsencrypt.org/acme/new-nonce
DEBUG: Found registed account. used old account. [/usr/syno/etc/letsencrypt/account/DarUbx/]
DEBUG: apply certs with type: RSA
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/new-order
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/new-order
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: dns-01 is not support for sakshi.ddns.net
DEBUG: Setup challenge for sakshi.ddns.net with type http-01
DEBUG: Failed to port map router detect. [1]
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/chall-v3/193343117117/qg5QPA
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/chall-v3/193343117117/qg5QPA
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post JWS Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Post Request: https://acme-v02.api.letsencrypt.org/acme/authz-v3/193343117117
DEBUG: Failed to do challenge for sakshi.ddns.net with type http-01.
DEBUG: close port 80.
{"error":101,"file":"client_v2-base.cpp","msg":"Failed to new certificate."}
My web server is (include version): Apache 2.4
The operating system my web server runs on is (include version): Synology
My hosting provider, if applicable, is:
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): Certbot is not available on Synology
My nmap results:
PORT STATE SERVICE
80/tcp open http
139/tcp open netbios-ssn
443/tcp open https
445/tcp open microsoft-ds
3261/tcp open winshadow
5000/tcp open upnp
5001/tcp open commplex-link
5357/tcp open wsdapi
My Router:
port 80 and 443 are opened on the router too:
my IPV6:
inet6 is disabled
my logs /var/log/messages
syno-letsencrypt[13323]: client_v2-disk.cpp:117 Failed to open port
Demon syno-letsencrypt[13323]: client_v2-base.cpp:603 Failed to do new authorization, may retry with another type. [{"error":101,"file":"client_v2-base.cpp","msg":"148.76.48.218: Fetching http://sakshi.ddns.net/.well-known/acme-challenge/VHPRyvc4HPJSCNMBypd_MSJj_wcpxOSP898GZeHVlPU: Timeout during connect (likely firewall problem)"}
myfirewall status:
Disabled,
when enabled port 80 and 443 is allowed traffic.