# \[nginx\] IPv4 OK, IPv6 NOK

**URL:** <https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451>\
**Category:** Help\
**Created:** [April 8, 2026, 1:49pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451 "2026-04-08T13:49:42Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Winfried2025](https://avatars.discourse-cdn.com/v4/letter/w/4bbf92/32.png) [@Winfried2025](https://community.letsencrypt.org/u/Winfried2025)\
**Post date:** [April 8, 2026, 1:49pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/1 "2026-04-08T13:49:42Z")

</div>

Hello,

After successfully converting my home-based server from HTTP to HTTPS using Let's Encrypt, I'd like to add support for IPv6.

Did I make a mistake reconfiguring nginx for that purpose?

```nohighlight
#OK
curl -4 https://www.acme.com
#OK
curl -6 https://www.acme.com
#OK
Chrome http://[2a01:blah:7ac6]/
#NOK
Chrome https://[2a01:blah:7ac6]/
"Your connection to this site is not secure"

```

Thank you.

```nohighlight
~# cat /etc/nginx/sites-available/default
server {
        listen 80 default_server;
        listen [::]:80 default_server;

        root /var/www/html;

        index index.html index.htm index.nginx-debian.html;

        server_name _;

        location / {
                try_files $uri $uri/ =404;
        }
}

server {
        root /usr/share/nginx/acme;
        index index.html index.htm;
        server_name www.acme.com acme.com;

        error_page 404 /404.html;

        #Add to allow IPv6
        listen [::]:443 ssl;

        listen 443 ssl; # managed by Certbot
        ssl_certificate /etc/letsencrypt/live/www.acme.com/fullchain.pem; # managed by Certbot
        ssl_certificate_key /etc/letsencrypt/live/www.acme.com/privkey.pem; # managed by Certbot
        include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
        ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
}

server {
    if ($host = www.acme.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    server_name www.acme.com acme.com;
    listen 80;
    #Add to allow IPv6
    listen [::]:80;

    return 404; # managed by Certbot
}

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [April 8, 2026, 2:13pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/2 "2026-04-08T14:13:50Z")

</div>

> [@Winfried2025](#):
>
> ```nohighlight
> if ($host = www.acme.com) {
> return 301 https://$host$request_uri;
> } # managed by Certbot
> 
> server_name www.acme.com acme.com;
> 
> ```

Only the `www` is being redirected...  
What should happen when `acme.com` is requested?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [April 8, 2026, 3:03pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/3 "2026-04-08T15:03:59Z")

</div>

> [@Winfried2025](#):
>
> ```nohighlight
> Chrome https://[2a01:blah:7ac6]/
> "Your connection to this site is not secure"
> 
> ```

You cannot use the IP address in the HTTPS URL unless the IP address itself is also in the certificate. Chrome matches the URL hostname to the identifiers in the cert.

Let's Encrypt recently added support for IP addresses in the cert. However, this requires use of the `shortlived` profile and an ACME client that supports profiles, IP addresses, and is very reliable since shortlived certs expire in less than 7 days. For routine web servers a domain name is probably much better suited which allows longer lived certs. See: [Profiles - Let's Encrypt](https://letsencrypt.org/docs/profiles/#shortlived)

> [@Winfried2025](#):
>
> `curl -4 https://www.acme.com`

Someone owns and operates that domain. But it isn't you. Please don't use other people's domains in examples. Use something like `example.com` which is an industry acceptable name for such purposes.

We prefer seeing your actual domain name.

---

<div class="post-metadata">

**Author:** ![Winfried2025](https://avatars.discourse-cdn.com/v4/letter/w/4bbf92/32.png) [@Winfried2025](https://community.letsencrypt.org/u/Winfried2025)\
**Post date:** [April 8, 2026, 3:23pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/4 "2026-04-08T15:23:00Z")

</div>

Thanks for pointing it out.

I'll see how to rewrite the file to support both items.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [April 8, 2026, 3:24pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/5 "2026-04-08T15:24:17Z")

</div>

The `servername` takes care of which FQDNs will be handled by that section.  
There is no need for the `IF` case.

---

<div class="post-metadata">

**Author:** ![Winfried2025](https://avatars.discourse-cdn.com/v4/letter/w/4bbf92/32.png) [@Winfried2025](https://community.letsencrypt.org/u/Winfried2025)\
**Post date:** [April 8, 2026, 3:24pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/6 "2026-04-08T15:24:45Z")

</div>

I can't publish the actual domain name.

Is that error a problem in real life, or can I leave things as is?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [April 8, 2026, 3:26pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/7 "2026-04-08T15:26:34Z")

</div>

> [@Winfried2025](#):
>
> I can't publish the actual domain name.

That's fine. Just please don't use other people's valid names in the future.

> [@Winfried2025](#):
>
> Is that error a problem in real life, or can I leave things as is?

Do you mean the failure using the IP address in the URL?

If so, just don't do that 🙂use the domain name instead

Your IPv4 address would not work in the URL either.

---

<div class="post-metadata">

**Author:** ![Winfried2025](https://avatars.discourse-cdn.com/v4/letter/w/4bbf92/32.png) [@Winfried2025](https://community.letsencrypt.org/u/Winfried2025)\
**Post date:** [April 8, 2026, 3:31pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/8 "2026-04-08T15:31:36Z")

</div>

Should I rewrite it this way?

```nohighlight
#HTTPS
server {
	root /usr/share/nginx/acme;
	index index.html index.htm;
	server_name www.acme.com acme.com;

    #Add to allow IPv6
    listen [::]:443 ssl;

    listen 443 ssl; # managed by Certbot
    ssl_certificate /etc/letsencrypt/live/www.acme.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/www.acme.com/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}

#HTTP
server {
    #if ($host = www.acme.com) {
    # return 301 https://$host$request_uri;
    #} # managed by Certbot
    return 301 https://$host$request_uri;

    server_name www.acme.com acme.com;
    listen 80;
    #Add to allow IPv6
    listen [::]:80;

    return 404; # managed by Certbot
}

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [April 8, 2026, 3:32pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/9 "2026-04-08T15:32:45Z")

</div>

That should now redirect both FQDNs.  
[yes]

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [April 8, 2026, 4:22pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/10 "2026-04-08T16:22:56Z")

</div>

> [@Winfried2025](#):
>
> Should I rewrite it this way?

No, I wouldn't do it that way. While it redirects every HTTP request to HTTPS it would be better to exclude the HTTP Challenge request. Like this:

```nohighlight
server {
    listen 80;
    listen [::]:80;    
    server_name example.com www.example.com;

    location /.well-known/acme-challenge/ {
        root /usr/share/nginx/acme; # make/use folder as you prefer
    }
    location / {
       return 301 https://$host$request_uri;
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 8, 2026, 4:23pm UTC](https://community.letsencrypt.org/t/nginx-ipv4-ok-ipv6-nok/246451/11 "2026-05-08T16:23:13Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
