# Letsencrypt crashes because curl can't access letsencrypt.org

**URL:** https://community.letsencrypt.org/t/letsencrypt-crashes-because-curl-cant-access-letsencrypt-org/20963
**Category:** Server
**Created:** [October 11, 2016, 5:20pm UTC](https://community.letsencrypt.org/t/letsencrypt-crashes-because-curl-cant-access-letsencrypt-org/20963 "2016-10-11T17:20:20Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![fowie](https://avatars.discourse-cdn.com/v4/letter/f/f6c823/32.png) [@fowie](https://community.letsencrypt.org/u/fowie)
#### Post date: [October 11, 2016, 5:20pm UTC](https://community.letsencrypt.org/t/letsencrypt-crashes-because-curl-cant-access-letsencrypt-org/20963/1 "2016-10-11T17:20:20Z")

</div>

After an OS reinstall (Ubuntu 16.04) I can't get letsencrypt to work. After specifying my apache domains and typing in my email, letsencrypt crashes with:

> 2016-10-11 17:11:11,676:DEBUG:letsencrypt.cli:Root logging level set at 30  
> 2016-10-11 17:11:11,687:INFO:letsencrypt.cli:Saving debug log to /var/log/letsencrypt/letsencrypt.log  
> 2016-10-11 17:11:11,688:DEBUG:letsencrypt.cli:letsencrypt version: 0.4.1  
> 2016-10-11 17:11:11,688:DEBUG:letsencrypt.cli:Arguments:   
> 2016-10-11 17:11:11,689:DEBUG:letsencrypt.cli:Discovered plugins: PluginsRegistry(PluginEntryPoint#apache,PluginEntryPoint#webroot,PluginEntryPoint#null,PluginEntryPoint#manual,PluginEntryPoint#standalone)  
> 2016-10-11 17:11:11,698:DEBUG:letsencrypt.cli:Requested authenticator None and installer None  
> 2016-10-11 17:11:12,438:DEBUG:letsencrypt.display.ops:Single candidate plugin: \* apache  
> Description: Apache Web Server - Alpha  
> Interfaces: IAuthenticator, IInstaller, IPlugin  
> Entry point: apache = letsencrypt\_apache.configurator:ApacheConfigurator  
> Initialized: \<letsencrypt\_apache.configurator.ApacheConfigurator object at 0x7fc06d73ab90\>  
> Prep: True  
> 2016-10-11 17:11:12,439:DEBUG:letsencrypt.cli:Selected authenticator \<letsencrypt\_apache.configurator.ApacheConfigurator object at 0x7fc06d73ab90\> and installer \<letsencrypt\_apache.configurator.ApacheConfigurator object at 0x7fc06d73ab90\>  
> 2016-10-11 17:11:18,798:DEBUG:root:Sending GET request to [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory). args: (), kwargs: {}  
> 2016-10-11 17:11:18,803:INFO:requests.packages.urllib3.connectionpool:Starting new HTTPS connection (1): [acme-v01.api.letsencrypt.org](http://acme-v01.api.letsencrypt.org)  
> 2016-10-11 17:11:18,904:DEBUG:letsencrypt.cli:Exiting abnormally:  
> Traceback (most recent call last):  
> File "/usr/bin/letsencrypt", line 9, in   
> load\_entry\_point('letsencrypt==0.4.1', 'console\_scripts', 'letsencrypt')()  
> File "/usr/lib/python2.7/dist-packages/letsencrypt/cli.py", line 1986, in main  
> return config.func(config, plugins)  
> File "/usr/lib/python2.7/dist-packages/letsencrypt/cli.py", line 660, in run  
> le\_client = \_init\_le\_client(config, authenticator, installer)  
> File "/usr/lib/python2.7/dist-packages/letsencrypt/cli.py", line 206, in \_init\_le\_client  
> acc, acme = \_determine\_account(config)  
> File "/usr/lib/python2.7/dist-packages/letsencrypt/cli.py", line 191, in \_determine\_account  
> config, account\_storage, tos\_cb=\_tos\_cb)  
> File "/usr/lib/python2.7/dist-packages/letsencrypt/client.py", line 116, in register  
> acme = acme\_from\_config\_key(config, key)  
> File "/usr/lib/python2.7/dist-packages/letsencrypt/client.py", line 41, in acme\_from\_config\_key  
> return acme\_client.Client(config.server, key=key, net=net)  
> File "/usr/lib/python2.7/dist-packages/acme/client.py", line 63, in **init**  
> self.net.get(directory).json())  
> File "/usr/lib/python2.7/dist-packages/acme/client.py", line 627, in get  
> self.\_send\_request('GET', url, \*\*kwargs), content\_type=content\_type)  
> File "/usr/lib/python2.7/dist-packages/acme/client.py", line 609, in \_send\_request  
> response = requests.request(method, url, \*args, \*\*kwargs)  
> File "/usr/lib/python2.7/dist-packages/requests/api.py", line 53, in request  
> return session.request(method=method, url=url, \*\*kwargs)  
> File "/usr/lib/python2.7/dist-packages/requests/sessions.py", line 468, in request  
> resp = self.send(prep, \*\*send\_kwargs)  
> File "/usr/lib/python2.7/dist-packages/requests/sessions.py", line 576, in send  
> r = adapter.send(request, \*\*kwargs)  
> File "/usr/lib/python2.7/dist-packages/requests/adapters.py", line 447, in send  
> raise SSLError(e, request=request)  
> SSLError: unknown error (\_ssl.c:2831)

I believe the SSL error is because any attempt to access [letsencrypt.org](http://letsencrypt.org) using curl fails:

> $ curl [https://helloworld.letsencrypt.org](https://helloworld.letsencrypt.org)  
> curl: (60) server certificate verification failed. CAfile: /etc/ssl/certs/ca-certificates.crt CRLfile: none  
> More details here: [curl - SSL CA Certificates](http://curl.haxx.se/docs/sslcerts.html)

> curl performs SSL certificate verification by default, using a "bundle"  
> of Certificate Authority (CA) public keys (CA certs). If the default  
> bundle file isn't adequate, you can specify an alternate file  
> using the --cacert option.  
> If this HTTPS server uses a certificate signed by a CA represented in  
> the bundle, the certificate verification probably failed due to a  
> problem with the certificate (it might be expired, or the name might  
> not match the domain name in the URL).  
> If you'd like to turn off curl's verification of the certificate, use  
> the -k (or --insecure) option.

should I be adding some certificate to my ca-certificates.crt? I've tried dpkg-reconfigure ca-certificates and update-ca-certificates and see no change...

---

<div class="post-metadata">

### Author: ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)
#### Post date: [October 11, 2016, 5:26pm UTC](https://community.letsencrypt.org/t/letsencrypt-crashes-because-curl-cant-access-letsencrypt-org/20963/2 "2016-10-11T17:26:36Z")

</div>

`helloworld.letsencrypt.org` is not an appropriate site to test connectivity to Let’s Encrypt’s CA server.

Try `curl`ing `https://acme-v01.api.letsencrypt.org/directory`, possibly adding `-v` as well to see some debug output.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [November 10, 2016, 5:35pm UTC](https://community.letsencrypt.org/t/letsencrypt-crashes-because-curl-cant-access-letsencrypt-org/20963/3 "2016-11-10T17:35:01Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
