# NXDOMAIN error unable to get certificate

**URL:** <https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927>\
**Category:** Help\
**Created:** [July 17, 2018, 9:05am UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927 "2018-07-17T09:05:29Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![CKR81](https://avatars.discourse-cdn.com/v4/letter/c/a183cd/32.png) [@CKR81](https://community.letsencrypt.org/u/CKR81)\
**Post date:** [July 17, 2018, 9:05am UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/1 "2018-07-17T09:05:30Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [cloud03.lstmed.ac.uk](http://cloud03.lstmed.ac.uk)

I ran this command: sudo ./certbot-auto --apache --agree-tos --rsa-key-size 4096 --email [user@domain.org](mailto:user@domain.org) --redirect -d [nc.domain.org](http://nc.domain.org)

My web server is (include version): Apache 2.4

The operating system my web server runs on is (include version): Ubuntu 16.04

It produced this output:

Saving debug log to /var/log/letsencrypt/letsencrypt.log  
Plugins selected: Authenticator apache, Installer apache  
Obtaining a new certificate  
Performing the following challenges:  
http-01 challenge for [cloud03.lstmed.ac.uk](http://cloud03.lstmed.ac.uk)  
Waiting for verification…  
Cleaning up challenges  
Failed authorization procedure. [cloud03.lstmed.ac.uk](http://cloud03.lstmed.ac.uk) (http-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for [cloud03.lstmed.ac.uk](http://cloud03.lstmed.ac.uk)

IMPORTANT NOTES:

- The following errors were reported by the server:

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 17, 2018, 9:17am UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/2 "2018-07-17T09:17:26Z")

</div>

You need to setup a DNS record to point your domain to your web server.

---

<div class="post-metadata">

**Author:** ![CKR81](https://avatars.discourse-cdn.com/v4/letter/c/a183cd/32.png) [@CKR81](https://community.letsencrypt.org/u/CKR81)\
**Post date:** [July 17, 2018, 9:24am UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/3 "2018-07-17T09:24:32Z")

</div>

> [@\_az](#):
>
> record

I have this on my DNS server - I have this issue a few times, all affected servers have a DNS A record.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [July 17, 2018, 9:29am UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/4 "2018-07-17T09:29:06Z")

</div>

Well, you may have it on a non-authoritative nameserver, or perhaps one only presented to your local network.

The DNS record needs to be resolveable on the wide internet, which it isn’t currently.

---

<div class="post-metadata">

**Author:** ![CKR81](https://avatars.discourse-cdn.com/v4/letter/c/a183cd/32.png) [@CKR81](https://community.letsencrypt.org/u/CKR81)\
**Post date:** [July 17, 2018, 2:37pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/5 "2018-07-17T14:37:16Z")

</div>

After some config, we moved onto this:

Failed authorization procedure. [cloud03.lstmed.ac.uk](http://cloud03.lstmed.ac.uk) (http-01): urn:ietf:params:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching [http://cloud03.lstmed.ac.uk/.well-known/acme-challenge/PpjJfmh-saiazkw7JLSoDPljrPze8nTIm\_ww6zU5j88:](http://cloud03.lstmed.ac.uk/.well-known/acme-challenge/PpjJfmh-saiazkw7JLSoDPljrPze8nTIm_ww6zU5j88:) Timeout during connect (likely firewall problem)

IMPORTANT NOTES:

- The following errors were reported by the server:

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [July 17, 2018, 3:42pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/6 "2018-07-17T15:42:44Z")

</div>

I can connect to [https://cloud03.lstmed.ac.uk/](https://cloud03.lstmed.ac.uk/), but [http://cloud03.lstmed.ac.uk/](http://cloud03.lstmed.ac.uk/) times out.

Is a firewall on the computer or network blocking port 80?

---

<div class="post-metadata">

**Author:** ![CKR81](https://avatars.discourse-cdn.com/v4/letter/c/a183cd/32.png) [@CKR81](https://community.letsencrypt.org/u/CKR81)\
**Post date:** [July 17, 2018, 3:59pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/7 "2018-07-17T15:59:57Z")

</div>

Port 80 is open, but the apache\site config has a re-direct to https…

I’ll disable that temporarily, and try once more…

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [July 17, 2018, 4:01pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/8 "2018-07-17T16:01:30Z")

</div>

> [@CKR81](#):
>
> Port 80 is open, but the apache\site config has a re-direct to https…
> 
> I’ll disable that temporarily, and try once more…

Redirecting is fine. Port 80 **isn't** open.

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [July 17, 2018, 4:01pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/9 "2018-07-17T16:01:48Z")

</div>

A redirect from 80 to 443 is just fine, but LE must be able to connect on port 80 initially. The error you’re seeing says it can’t.

---

<div class="post-metadata">

**Author:** ![CKR81](https://avatars.discourse-cdn.com/v4/letter/c/a183cd/32.png) [@CKR81](https://community.letsencrypt.org/u/CKR81)\
**Post date:** [July 17, 2018, 4:33pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/10 "2018-07-17T16:33:14Z")

</div>

Ok - Port is enabled.

sudo ufw status confirms this…

Too many attempts today…

Can anyone help with a guide on how to do this? Please bear in mind I’m relatively new to Linux (Base server builds are fine, SSL certificates always tend to fail with me though)

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [July 17, 2018, 4:35pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/11 "2018-07-17T16:35:12Z")

</div>

[http://cloud03.lstmed.ac.uk/](http://cloud03.lstmed.ac.uk/) still times out.

ufw might be configured to allow port 80, but it seems something isn’t.

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [July 17, 2018, 4:37pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/12 "2018-07-17T16:37:58Z")

</div>

> [@CKR81](#):
>
> Can anyone help with a guide on how to do this?

Any such guide would have to be based on all the details of your configuration, thus no such guide is possible. Something is blocking connections to port 80 from the Internet at large. Until you resolve that, you won't be able to get a cert using the HTTP validator. If that something happens to be your ISP (as isn't unusual for residential ISPs, for example), you may be out of luck.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 16, 2018, 4:38pm UTC](https://community.letsencrypt.org/t/nxdomain-error-unable-to-get-certificate/66927/13 "2018-08-16T16:38:02Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
