I’m unable to renew my certificates, and I only have a week to sort this out before expiry! I have three domains, darksteve.tk, cloud.darksteve.tk, and mail.darksteve.tk. I think I’m only having issues with the first (darksteve.tk) domain.
When I run (as root) the command:
I get the following error:
2016-08-06 14:34:28,120:WARNING:certbot.renewal:Attempting to renew cert from /usr/local/etc/letsencrypt/renewal/darksteve.tk.conf produced an unexpected error: Failed authorization procedure. darksteve.tk (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Could not connect to http://darksteve.tk/.well-known/acme-challenge/puoZnE0oeCx6bYqfOLqzH00s7yXgtfwJ2L5pfsvs2Zs. Skipping.
All renewal attempts failed. The following certs could not be renewed: /usr/local/etc/letsencrypt/live/darksteve.tk/fullchain.pem (failure) 1 renew failure(s), 0 parse failure(s) IMPORTANT NOTES: - The following errors were reported by the server: Domain: darksteve.tk Type: connection Detail: Could not connect to http://darksteve.tk/.well-known/acme-challenge/puoZnE0oeCx6bYqfOLqzH00s7yXgtfwJ2L5pfsvs2Zs To fix these errors, please make sure that your domain name was entered correctly and the DNS A record(s) for that domain contain(s) the right IP address. Additionally, please check that your computer has a publicly routable IP address and that no firewalls are preventing the server from communicating with the client. If you're using the webroot plugin, you should also verify that you are serving files from the webroot path you provided.
I’m running py27-certbot-0.8.1,1 on FreeBSD 10.3, with Apache 2.4.23. I’m running this out of my home, I’m not using a hosting provider. (My ISP is gracious enough to allow non-commercial home servers.) Naturally I have ssh access and I’m the admin so I have root access as well.
This has previously worked flawlessly, but I’ve recently had a 'net outage that lasted two weeks. This resulted in my domains being lost, though I was able to re-set them up again once I was back online. I think I’ve set things up properly again, but I’m concerned I’ve made a DNS error, even though I can remotely connect to all three domains.
My renew config contains the following:
# Options and defaults used in the renewal process [renewalparams] installer = None authenticator = webroot rsa_key_size = 4096 account = [redacted] [[webroot_map]] mail.darksteve.tk = /usr/local/www/roundcube/ darksteve.tk = /usr/local/www/DarkSteve.tk/ cloud.darksteve.tk = /usr/local/www/owncloud/
(I removed my account, just in case.) I didn’t realise that I’d lost my domains the first time I tried renewing, and I got the same error as above except it listed all three domains. Once I set DNS up again, I now only get the darksteve.tk error.
I’ve been using webroot since the beginning, and I’m currently able to remotely access text files I put in .well-known.
I’ve tried everything I can think of, but I’m now all out of ideas! Since the last time I’ve renewed, the client has updated, though nobody else seems to be having the same problem.
Does anybody have any suggestions? I’d appreciate any ideas