OCSP check failed for /etc/letsencrypt/archive//****er.com.cn/cert1.pem (are we offline?)
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator apache, Installer apache
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for /****er.com.cn
Waiting for verification...
Challenge failed for domain /****er.com.cn
http-01 challenge for /****er.com.cn
Cleaning up challenges
Attempting to renew cert (/****er.com.cn) from /etc/letsencrypt/renewal//****er.com.cn.conf produced an unexpected error: Some challenges have failed.. Skipping.
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live//****er.com.cn/fullchain.pem (failure)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live//****er.com.cn/fullchain.pem (failure)
To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
Thanks. Right now, your server's DNS name is CNAMEd to personapp.chinanorth2.cloudapp.chinacloudapi.cn—is that the same server where you're running this Certbot command? Is it possible that this is a shared server which is different from the one where you're running Certbot?
@rg305, I agree that the nameservers are sometimes giving problems, and that that could interfere with issuance of @KingChen's certificate—but I don't think that's the problem that he encountered here, because the error from Let's Encrypt would be different in that case. (When I re-ran the Let's Debug test, it was very slow, but it eventually succeeded.)
@KingChen, could you please clarify whether is your own server, that you are the administrator of?