Happy I am with LE, let me start with a thank you for your lovely certs service. I am trying to replace an existing certificate on my server. Below is as much as I know. I tried solving it myself reading the LE forum, but still stuck on the same (general) error. Any help is much appreciated.
My domain is: droeska.nl
I ran this command: first I tried to "renew" the existing expired cert without success, then "add new" replacing the existing cert. In the last case I have provided the domain, an email and subject althernative names: vpn.droeska.nl;nas.droeska.nl;music.droeska.nl;unifi.droeska.nl;foto.droeska.nl;file.droeska.nl;www.droeska.nl;67.droeska.nl;www.cubicletree.nl;cubicletree.nl;mail.droeska.nl;mail.cubicletree.nl;3in1winkel.droeska.nl;portainer.droeska.nl;code.droeska.nl
It produced this output (for both cases): "Please check if your IP, reverse proxy and firewall rules are correctly configured then try again"
My web server is (include version): Sysnology Web Station, nginx
The operating system my web server runs on is (include version): DSM 7.2
My hosting provider, if applicable, is: yourhosting (DNS only), hosted locally
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): not sure, couldn't retreive
What I already checked:
- It managed to obtain the previous ssl cert from let's encrypt (but changes made?)
- I tripple checked my forwarding rules and firewall (even disabled didn't help); 80 and 443 are open.
- https://letsdebug.net is providing an 'all clear', after I removed my ddns domain form the subject alternative name list.
The server has reverse proxy setup for most of these (sub)domains, I have the feeling this might be (part of) the issue, but find it hard to debug
Could the following be the culprit?
$ curl -I4 -m8 http://www.droeska.nl
HTTP/1.1 301 Moved Permanently
Date: Thu, 09 Oct 2025 19:53:45 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Keep-Alive: timeout=20
Location: https://droeska.nl/
