# Renew Cert Failed - The client lacks sufficient authorization :: Invalid response

**URL:** <https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175>\
**Category:** Help\
**Created:** [April 2, 2020, 9:25am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175 "2020-04-02T09:25:34Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 9:25am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/21 "2020-04-07T09:25:59Z")

</div>

> [@stonesx](#):
>
> Added test.html to /var/www/certbot

did you add the location block? (and reload apache?)

> [@stonesx](#):
>
> collabora.oxigen.sg auto renews LE perfectly

because it's using another virtualhost and nothing is interfering

> [@stonesx](#):
>
> Maybe this will help. I installed nextcloud using this. [Install Nextcloud 17 on Debian 10 – Nerd on the Street](https://nerdonthestreet.com/wiki?find=Install+Nextcloud+17+on+Debian+10)

revert step 16 and retry, maybe.

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 9:33am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/22 "2020-04-07T09:33:17Z")

</div>

```nohighlight
root@nextcloud:~# ls -al /var/www/certbot/
total 12
drwxr-xr-x 2 www-data www-data 4096 Apr 7 17:27 .
drwxr-xr-x 5 root root 4096 Apr 7 16:39 ..
-rw-r--r-- 1 www-data www-data 11 Apr 7 17:13 test.html

```

Yes, reloaded apache  
The links still goes to nextcloud.

Reverted step 16. Restarted apache. Still same error

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 9:39am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/23 "2020-04-07T09:39:48Z")

</div>

you should add `--dry-run` to your certbot command.

that `.htaccess` is half absurd.

> [@stonesx](#):
>
> Still same error

Which one, from certbot or apache?

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 9:42am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/24 "2020-04-07T09:42:54Z")

</div>

> [@9peppe](#):
>
> Which one, from certbot or apache?

Tried both. Both got the same error.

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 9:46am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/25 "2020-04-07T09:46:59Z")

</div>

Dy run.

```nohighlight
Processing /etc/letsencrypt/renewal/collabora.oxigen.sg.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert not due for renewal, but simulating renewal for dry run
Plugins selected: Authenticator apache, Installer None
Renewing an existing certificate

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
new certificate deployed without reload, fullchain is
/etc/letsencrypt/live/collabora.oxigen.sg/fullchain.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/nextcloud.oxigen.sg.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator apache, Installer apache
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for nextcloud.oxigen.sg
Waiting for verification...
Cleaning up challenges
Attempting to renew cert (nextcloud.oxigen.sg) from /etc/letsencrypt/renewal/nextcloud.oxigen.sg.conf produced an unexpected error: Failed authorization procedure. nextcloud.oxigen.sg (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://nextcloud.oxigen.sg/.well-known/acme-challenge/MU10_T3rzaRAcB8DciiszML8wk7zf1Ns4adNM1kGlis [116.202.30.75]: "<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML 2.0//EN\">\n<html><head>\n<title>404 Not Found</title>\n</head><body>\n<h1>Not Found</h1>\n<p". Skipping.
The following certs could not be renewed:
  /etc/letsencrypt/live/nextcloud.oxigen.sg/fullchain.pem (failure)

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates below have not been saved.)

The following certs were successfully renewed:
  /etc/letsencrypt/live/collabora.oxigen.sg/fullchain.pem (success)

The following certs could not be renewed:
  /etc/letsencrypt/live/nextcloud.oxigen.sg/fullchain.pem (failure)
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates above have not been saved.)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: nextcloud.oxigen.sg
   Type: unauthorized
   Detail: Invalid response from
   http://nextcloud.oxigen.sg/.well-known/acme-challenge/MU10_T3rzaRAcB8DciiszML8wk7zf1Ns4adNM1kGlis
   [116.202.30.75]: "<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML
   2.0//EN\">\n<html><head>\n<title>404 Not
   Found</title>\n</head><body>\n<h1>Not Found</h1>\n<p"

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address.

```

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 9:50am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/26 "2020-04-07T09:50:57Z")

</div>

try running `a2dissite nextcloud && a2dissite nextcloud-le-ssl`

then run again steps 6, 7. and restart apache; show me any errors.

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 10:00am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/27 "2020-04-07T10:00:04Z")

</div>

all ran successfully. no error. should i run step 8?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 10:01am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/28 "2020-04-07T10:01:14Z")

</div>

no. run the command with `-a webroot` and `--dry-run`

(if you want to use `-w /var/www/certbot` you should add the location block to the port 80 virtualhost in nextcloud.conf)

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 10:06am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/29 "2020-04-07T10:06:05Z")

</div>

certbot renew -a webroot -w /var/www/nextcloud -i apache --dry-run

authorisation error

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 10:15am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/30 "2020-04-07T10:15:37Z")

</div>

this is extremely strange. go on with the steps (don’t overwrite stuff) but don’t add the `AllowOverride All`, instead, try `AllowOverride None`

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 10:29am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/31 "2020-04-07T10:29:31Z")

</div>

Can I skip steps 9 - 15 and do only 16 onwards? Because 9 - 15 will mess with the existing nextcloud setup?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 10:31am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/32 "2020-04-07T10:31:36Z")

</div>

you can skip them all, and use this text for step 16:

```auto
<IfModule mod_headers.c>
 Header always set Strict-Transport-Security "max-age=15552000; includeSubDomains"
</IfModule>

<Directory /var/www/nextcloud/>
 AllowOverride None
</Directory>

```

you can also skip 17, 18, 19

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 10:39am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/33 "2020-04-07T10:39:08Z")

</div>

Still the same error.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 10:39am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/34 "2020-04-07T10:39:38Z")

</div>

show me the details. command you ran, error you saw.

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 10:52am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/35 "2020-04-07T10:52:56Z")

</div>

```nohighlight
root@nextcloud:~# certbot renew -a webroot -w /var/www/nextcloud -i apache --dry-run
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/collabora.oxigen.sg.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert not due for renewal, but simulating renewal for dry run
Plugins selected: Authenticator webroot, Installer apache
Renewing an existing certificate

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
new certificate deployed with reload of apache server; fullchain is
/etc/letsencrypt/live/collabora.oxigen.sg/fullchain.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/nextcloud.oxigen.sg.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator webroot, Installer apache
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for nextcloud.oxigen.sg
Using the webroot path /var/www/nextcloud for all unmatched domains.
Waiting for verification...
Cleaning up challenges
Attempting to renew cert (nextcloud.oxigen.sg) from /etc/letsencrypt/renewal/nextcloud.oxigen.sg.conf produced an unexpected error: Failed authorization procedure. nextcloud.oxigen.sg (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://nextcloud.oxigen.sg/.well-known/acme-challenge/jCQ-M6Kc7Ia9RqsnXjCpUXiXbYOglPMMDg804IxH3hg [116.202.30.75]: "<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML 2.0//EN\">\n<html><head>\n<title>404 Not Found</title>\n</head><body>\n<h1>Not Found</h1>\n<p". Skipping.
The following certs could not be renewed:
  /etc/letsencrypt/live/nextcloud.oxigen.sg/fullchain.pem (failure)

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates below have not been saved.)

The following certs were successfully renewed:
  /etc/letsencrypt/live/collabora.oxigen.sg/fullchain.pem (success)

The following certs could not be renewed:
  /etc/letsencrypt/live/nextcloud.oxigen.sg/fullchain.pem (failure)
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates above have not been saved.)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: nextcloud.oxigen.sg
   Type: unauthorized
   Detail: Invalid response from
   http://nextcloud.oxigen.sg/.well-known/acme-challenge/jCQ-M6Kc7Ia9RqsnXjCpUXiXbYOglPMMDg804IxH3hg
   [116.202.30.75]: "<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML
   2.0//EN\">\n<html><head>\n<title>404 Not
   Found</title>\n</head><body>\n<h1>Not Found</h1>\n<p"

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address.

```

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 10:56am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/36 "2020-04-07T10:56:28Z")

</div>

I don’t know anymore, try with `certbot renew --apache --dry-run`

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 11:03am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/37 "2020-04-07T11:03:18Z")

</div>

Renewed on dry run successfully!! I did an actual renewal with certbot --apache, but I have this error while on browser.

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/e/e/eeac51e7b4fa1551847c8a8a452847a21b5805a9.png)

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 11:04am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/38 "2020-04-07T11:04:22Z")

</div>

~~run `certbot enhance --redirect` and it will go away.~~

you need to install the cert for nextcloud, with `certbot --apache` or `certbot install --apache` (no `renew`)

---

<div class="post-metadata">

**Author:** ![stonesx](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@stonesx](https://community.letsencrypt.org/u/stonesx)\
**Post date:** [April 7, 2020, 11:35am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/39 "2020-04-07T11:35:29Z")

</div>

Dry run is successful, but certbot renew --apache gets the same error. certbot install --apache installs the old cert.

```nohighlight
root@nextcloud:~# certbot renew --apache --dry-run
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/collabora.oxigen.sg.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert not due for renewal, but simulating renewal for dry run
Plugins selected: Authenticator apache, Installer apache
Renewing an existing certificate

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
new certificate deployed with reload of apache server; fullchain is
/etc/letsencrypt/live/collabora.oxigen.sg/fullchain.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/nextcloud.oxigen.sg.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator apache, Installer apache
Renewing an existing certificate

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
new certificate deployed with reload of apache server; fullchain is
/etc/letsencrypt/live/nextcloud.oxigen.sg/fullchain.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates below have not been saved.)

Congratulations, all renewals succeeded. The following certs have been renewed:
  /etc/letsencrypt/live/collabora.oxigen.sg/fullchain.pem (success)
  /etc/letsencrypt/live/nextcloud.oxigen.sg/fullchain.pem (success)
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates above have not been saved.)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

```

```nohighlight
root@nextcloud:~# certbot install --apache
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator None, Installer apache

Which certificate would you like to install?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: collabora.oxigen.sg
2: nextcloud.oxigen.sg
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2
Deploying Certificate to VirtualHost /etc/apache2/sites-enabled/nextcloud-le-ssl.conf

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2
Enhancement redirect was already set.

```

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [April 7, 2020, 11:37am UTC](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175/40 "2020-04-07T11:37:23Z")

</div>

> [@stonesx](#):
>
> Dry run is successful, but certbot renew --apache gets the same error.

This means there is no problem, I think. It validates, so it works.

[Previous page](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175.md?page=1)

[Next page](https://community.letsencrypt.org/t/renew-cert-failed-the-client-lacks-sufficient-authorization-invalid-response/118175.md?page=3)
