# Need help Incorrect validation certificate for tls-sni-01 challenge

**URL:** <https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159>\
**Category:** Server\
**Created:** [June 15, 2017, 4:07am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159 "2017-06-15T04:07:19Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ys588281](https://avatars.discourse-cdn.com/v4/letter/y/ba9def/32.png) [@ys588281](https://community.letsencrypt.org/u/ys588281)\
**Post date:** [June 15, 2017, 4:07am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/1 "2017-06-15T04:07:19Z")

</div>

Please fill out the fields below so we can help you better.

My domain is: [myfavoritecare.com](http://myfavoritecare.com)

I ran this command: ./letsencrypt-auto certonly --renew-by-default

It produced this output:  
Domain: [myfavoritecare.com](http://myfavoritecare.com)  
Type: unauthorized  
Detail: Incorrect validation certificate for tls-sni-01 challenge.  
Requested  
6687318197d9c2f2702b2d374c80a4c5.53da757358bbcc5392479762f168f6e1.acme.invalid  
from 139.162.55.19:443. Received 2 certificate(s), first  
certificate had names “[myfavoritecare.com](http://myfavoritecare.com)”

To fix these errors, please make sure that your domain name was  
entered correctly and the DNS A record(s) for that domain  
contain(s) the right IP address.

My web server is (include version): no apache and nginx

The operating system my web server runs on is (include version): contos6

My hosting provider, if applicable, is: linode

I can login to a root shell on my machine (yes or no, or I don’t know): i can login as root

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): just terminal

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 15, 2017, 5:12am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/2 "2017-06-15T05:12:09Z")

</div>

Hi @ys588281,

What did you mean when you said “no apache and nginx”? Do you mean that you’re using nginx but not Apache? Did you previously have a Let’s Encrypt certificate, and did you switch the web server software that you use? (I ask partly because `--renew-by-default` is the old name for `--force-renewal`, which is normally used when you have an existing certificate that you want to force to be renewed immediately.)

---

<div class="post-metadata">

**Author:** ![ys588281](https://avatars.discourse-cdn.com/v4/letter/y/ba9def/32.png) [@ys588281](https://community.letsencrypt.org/u/ys588281)\
**Post date:** [June 15, 2017, 5:54am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/3 "2017-06-15T05:54:03Z")

</div>

hi @schoen ,

I don’t use nginx and don’t use apache on my machine.  
I use Let’s Encrypt certificate about 1 year and never update Let’s Encrypt itself.  
I didn’t switch my web server software.  
Usually i renew Let’s Encrypt certificate easily and met this problem the first time.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [June 15, 2017, 4:06pm UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/4 "2017-06-15T16:06:11Z")

</div>

Can you place a test.txt file in the acme-challenge folder?

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 15, 2017, 4:39pm UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/5 "2017-06-15T16:39:31Z")

</div>

@rg305, that’s not going to be helpful in this case because this is a TLS-SNI-01 challenge, not an HTTP-01 challenge. TLS-SNI-01 doesn’t use `/.well-known/acme-challenge` at all.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 15, 2017, 4:42pm UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/6 "2017-06-15T16:42:02Z")

</div>

@ys588281, could you post the renewal configuration file from `/etc/letsencrypt/renewal`? That will explain what Certbot is trying to do here.

If you don’t use Apache or nginx, then the TLS-SNI-01 challenge could only succeed using the standalone authenticator. But this method requires stopping your web server temporarily when renewing your certificate.

---

<div class="post-metadata">

**Author:** ![ys588281](https://avatars.discourse-cdn.com/v4/letter/y/ba9def/32.png) [@ys588281](https://community.letsencrypt.org/u/ys588281)\
**Post date:** [June 18, 2017, 5:10am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/7 "2017-06-18T05:10:07Z")

</div>

hi @schoen,

below is my myfavoritecare.com.conf in renewal.

# renew\_before\_expiry = 30 days

version = 0.9.3  
cert = /etc/letsencrypt/live/myfavoritecare.com/cert.pem  
privkey = /etc/letsencrypt/live/myfavoritecare.com/privkey.pem  
chain = /etc/letsencrypt/live/myfavoritecare.com/chain.pem  
fullchain = /etc/letsencrypt/live/myfavoritecare.com/fullchain.pem

# Options used in the renewal process

[renewalparams]  
authenticator = standalone  
installer = None  
account = 11f9d2c1f4ddcbcf3ce9b7fcaf7ff114

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [June 18, 2017, 5:30am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/8 "2017-06-18T05:30:10Z")

</div>

> [@ys588281](#):
>
> ./letsencrypt-auto certonly --renew-by-default

Have you tried:  
./letsencrypt-auto certonly

Can you show:  
./letsencrypt-auto --version

---

<div class="post-metadata">

**Author:** ![ys588281](https://avatars.discourse-cdn.com/v4/letter/y/ba9def/32.png) [@ys588281](https://community.letsencrypt.org/u/ys588281)\
**Post date:** [June 18, 2017, 10:50am UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/9 "2017-06-18T10:50:32Z")

</div>

Hi @rg305,

The message from `./letsencrypt-auto --version` is `certbot 0.15.0`

I tried `./letsencrypt-auto certonly`, it failed again.

The error message is

Failed authorization procedure. [myfavoritecare.com](http://myfavoritecare.com) (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for tls-sni-01 challenge. Requested c4c096f23122ebd6762cf35e5379decd.ae5322a3de7019ae27712434c50e9a64.acme.invalid from 139.162.55.19:443. Received 2 certificate(s), first certificate had names “[myfavoritecare.com](http://myfavoritecare.com)”

IMPORTANT NOTES:

- The following errors were reported by the server:

My dns is in godaddy and it runs reallt good so far.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 18, 2017, 8:31pm UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/10 "2017-06-18T20:31:13Z")

</div>

So I’m pretty confused about why Certbot isn’t giving a more useful error (about inability to bind port 443), but the problem is almost certainly that `--standalone`, which is being used automatically for the renewal attempt, _requires you to temporarily stop your existing web server_ if you have one. From what you said, you do have one, and so you need to stop it temporarily when renewing with this method.

There are other methods which would might work and would not have this requirement if it turns out to be a problem for you. There are also `--pre-hook` and `--post-hook` options which can let you tell Certbot how to stop and restart your web server.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 18, 2017, 8:31pm UTC](https://community.letsencrypt.org/t/need-help-incorrect-validation-certificate-for-tls-sni-01-challenge/36159/11 "2017-07-18T20:31:14Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
