# PROBLEM : Correct zName not found for TLS SNI challenge

**URL:** <https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551>\
**Category:** Help\
**Created:** [May 10, 2016, 11:38am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551 "2016-05-10T11:38:40Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![PlugN](https://avatars.discourse-cdn.com/v4/letter/p/e56c9b/32.png) [@PlugN](https://community.letsencrypt.org/u/PlugN)\
**Post date:** [May 10, 2016, 11:38am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/1 "2016-05-10T11:38:40Z")

</div>

Hello,  
I know there are others topics about that problem, but I can’t find my answer in these topics, so I am making a new one. I leave you the result of the commands just here :

plugn:certbot-master plugn$ sudo ./letsencrypt-auto certonly --debug --standalone  
Checking for new version…  
Requesting root privileges to run letsencrypt…  
/Users/PlugN/.local/share/letsencrypt/bin/letsencrypt certonly --debug --standalone

```
                                                             ┌──────────────────────────────────────────────────────────────────────┐
                                                             │ Please enter in your domain name(s) (comma and/or space separated) │  
                                                             │ ┌──────────────────────────────────────────────────────────────────┐ │  
                                                             │ │plugn.tk │ │  
                                                             │ └──────────────────────────────────────────────────────────────────┘ │  
                                                             ├──────────────────────────────────────────────────────────────────────┤  
                                                             │ < OK > <Cancel> │  
                                                             └──────────────────────────────────────────────────────────────────────┘  

```

Traceback (most recent call last):  
File “/Users/PlugN/.local/share/letsencrypt/bin/letsencrypt”, line 11, in   
sys.exit(main())  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/main.py”, line 692, in main  
return config.func(config, plugins)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/main.py”, line 509, in obtain\_cert  
\_, action = \_auth\_from\_domains(le\_client, config, domains, lineage)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/main.py”, line 93, in \_auth\_from\_domains  
lineage = le\_client.obtain\_and\_enroll\_certificate(domains)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/client.py”, line 274, in obtain\_and\_enroll\_certificate  
certr, chain, key, \_ = self.obtain\_certificate(domains)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/client.py”, line 246, in obtain\_certificate  
self.config.allow\_subset\_of\_names)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/auth\_handler.py”, line 74, in get\_authorizations  
self.\_respond(resp, best\_effort)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/auth\_handler.py”, line 131, in \_respond  
self.\_poll\_challenges(chall\_update, best\_effort)  
File “/Users/PlugN/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/auth\_handler.py”, line 195, in \_poll\_challenges  
raise errors.FailedChallenges(all\_failed\_achalls)  
FailedChallenges: Failed authorization procedure. [plugn.tk](http://plugn.tk) (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Correct zName not found for TLS SNI challenge. Found ‘’

IMPORTANT NOTES:

- The following errors were reported by the server:

If you have any solution to this, I would really appreciate your help !  
Thank you in advance,  
PlugN

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [May 10, 2016, 11:43am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/2 "2016-05-10T11:43:04Z")

</div>

Did you shut down your existing apache website when using letsencrypt in standalone mode ?

---

<div class="post-metadata">

**Author:** ![PlugN](https://avatars.discourse-cdn.com/v4/letter/p/e56c9b/32.png) [@PlugN](https://community.letsencrypt.org/u/PlugN)\
**Post date:** [May 10, 2016, 11:45am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/3 "2016-05-10T11:45:45Z")

</div>

Yes, using sudo apachectl stop (I had a first warning before that telling me that the server was open, so I closed it.

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [May 10, 2016, 11:48am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/4 "2016-05-10T11:48:59Z")

</div>

OK, and you don’t have anything that automatically restarts it for you if it’s down ? The most common reason for this error is that some other apache / nginx responds on that port, rather than the standalone client.

Since you have apache working on your site currently, can I ask why you are using the standalone method, rather than using your apache ?

---

<div class="post-metadata">

**Author:** ![PlugN](https://avatars.discourse-cdn.com/v4/letter/p/e56c9b/32.png) [@PlugN](https://community.letsencrypt.org/u/PlugN)\
**Post date:** [May 10, 2016, 11:50am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/5 "2016-05-10T11:50:29Z")

</div>

Simply because the SSL certificate is for another server (not on the same computer)

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [May 10, 2016, 11:54am UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/6 "2016-05-10T11:54:05Z")

</div>

I’m confused.

Are you trying to get a certificate for [plugn.tk](http://plugn.tk) ? which is on that server

are are you trying to obtain a certificate for a different domain ?

or do you simply want to use the [plugn.tk](http://plugn.tk) on a different server for some reason ?

---

<div class="post-metadata">

**Author:** ![PlugN](https://avatars.discourse-cdn.com/v4/letter/p/e56c9b/32.png) [@PlugN](https://community.letsencrypt.org/u/PlugN)\
**Post date:** [May 10, 2016, 12:11pm UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/7 "2016-05-10T12:11:12Z")

</div>

Okay, here is my particular case :  
I have a Windows 10 machine that is my server (running XAMPP). But Let’s Encrypt Client isn’t made to run on Windows, so I decided to make it from my Mac (my personal computer), and transfer the certificate. But the Windows 10 PC (that is the server) is really connected to [plugn.tk](http://plugn.tk) (you can try [http://www.plugn.tk](http://www.plugn.tk), and you will see that there is no problem), and I want to acquire the certificate for that domain.  
Thank you for you fast answer !

---

<div class="post-metadata">

**Author:** ![serverco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/serverco/32/4251_2.png) [@serverco](https://community.letsencrypt.org/u/serverco)\
**Post date:** [May 10, 2016, 12:16pm UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/8 "2016-05-10T12:16:48Z")

</div>

OK, Thanks for the explanation, that helps.

There are a couple of options. There are[alternate clients](https://github.com/certbot/certbot/wiki/Links) ( some of which run in windows )

If you want to use letsencrypt on your MAC, that’s fine, however you will need to change the port forwards on your firewall to send traffic to your MAC, rather than your windows server, whilst you do the challenge. to that when the letsencrypt server tries to obtain the token from [plugn.tk/.well-known/acme-challenge](http://plugn.tk/.well-known/acme-challenge) it obtains it from the correct place (your MAC, not the windows server )

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 9, 2016, 12:16pm UTC](https://community.letsencrypt.org/t/problem-correct-zname-not-found-for-tls-sni-challenge/15551/9 "2016-06-09T12:16:56Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
