NET::ERR_CERT_DATE_INVALID in nginx error log file = SSL_do_handshake() failed (SSL: error:1417D18C:SSL routines:tls_process_client_hello:version too low) while SSL handshaking , client: xx.xx.xx.x, server:


My domain is:

I ran this command:
1/ went to
2/ tried to force renewel doing the following:
sudo certbot --force-renewal --cert-name
3/ tried renew again:
sudo certbot renew --cert-name --nginx

It produced this output:
1/The error shown in the browser:
the error shown in the nginx log file:
[crit] 14242#14242: *656 SSL_do_handshake() failed (SSL: error:1417D18C: ) while SSL handshaking, client:, server:

2/ error from trying to force renew (I restarted nginx after each time):
Timeout during connect (likely firewall problem)

To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address

3/ after trying it a few more times with a new command I got this error:
Cert is due for renewal, auto-renewing…
Plugins selected: Authenticator nginx, Installer nginx
Renewing an existing certificate
Attempting to renew cert ( from /etc/letsencrypt/renewal/ produced an unexpected error: urn:ietf:params:acme:error:rateLimited :: There were too many requests of a given type :: Error creating new order :: too many failed authorizations recently: see Skipping.

All renewal attempts failed. The following certs could not be renewed:

/etc/letsencrypt/live/ (failure)

My web server is (include version):
nginx/1.14.0 (Ubuntu)

The operating system my web server runs on is (include version):
ID_LIKE = debian

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):
I use sudo

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot):certbot 0.26.1

please help !


Upgrade your Certbot using the instructions at .

Wait up to one hour for the rate limit message to subside.

Then run (do NOT stop nginx):

certbot renew --dry-run --nginx

If that’s successful, then run (do NOT stop nginx):

certbot --renew --nginx

and that should be all you need to do.


Ah, you also have a different problem with your DNS setup, which might explain (parts of) your trouble:     60      IN      A     60      IN      A

One of these IPs is the GoDaddy domain parking page, and one of these is your nginx server.

You need to get rid of the DNS record for from your GoDaddy DNS management, in addition to the steps I outlined in the previous post.


I used the following comand after upgrading certbot:
certbot renew --nginx

along with everything else you recommended and everything works! thank you!!!