Maybe my IP is blocked?

When im trying to update certificate getting error:

An unexpected error occurred:
requests.exceptions.ConnectionError: HTTPSConnectionPool(host='acme-v02.api.letsencrypt.org', port=443): Max retries exceeded with url: /directory (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7f1ae981fd30>: Failed to establish a new connection: [Errno -3] Temporary failure in name resolution'))

My cerbot version 1.26.0

Dig output
dig acme-v02.api.letsencrypt.org

; <<>> DiG 9.16.1-Ubuntu <<>> acme-v02.api.letsencrypt.org
;; global options: +cmd
;; connection timed out; no servers could be reached

Hi @Tweekend, and welcome to the LE community forum :slight_smile:

There seems to be a problem with your DNS server(s).

Please show:
cat /etc/resolv.conf

5 Likes

cat /etc/resolv.conf

# This file is managed by man:systemd-resolved(8). Do not edit.
#
# This is a dynamic resolv.conf file for connecting local clients to the
# internal DNS stub resolver of systemd-resolved. This file lists all
# configured search domains.
#
# Run "resolvectl status" to see details about the uplink DNS servers
# currently in use.
#
# Third party programs must not access this file directly, but only through the
# symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way,
# replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 127.0.0.53
options edns0 trust-ad

Seems like it might not be as rugged as you need.
Try these instead:
dig acme-v02.api.letsencrypt.org @8.8.8.8
dig acme-v02.api.letsencrypt.org @1.1.1.1
dig acme-v02.api.letsencrypt.org @9.9.9.9

5 Likes

Thanks! Now i see. That is strange, all working before)

2 Likes

Maybe you were running your own DNS resolver on localhost before?

4 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.