# Renew: Incorrect validation certificate for tls-sni-01 challenge

**URL:** <https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865>\
**Category:** Help\
**Created:** [June 20, 2018, 7:39pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865 "2018-06-20T19:39:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![RobJVargas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/robjvargas/32/25641_2.png) [@RobJVargas](https://community.letsencrypt.org/u/RobJVargas)\
**Post date:** [June 20, 2018, 7:39pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/1 "2018-06-20T19:39:55Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [robjvargas.com](http://robjvargas.com)

I ran this command: certbot --apache renew

It produced this output:

* * *

## All renewal attempts failed. The following certs could not be renewed: /etc/letsencrypt/live/robjvargas.com/fullchain.pem (failure)

1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): Apache 2.4.6-80.el7

The operating system my web server runs on is (include version): CentOS Linux release 7.5.1804 (Core)

My hosting provider, if applicable, is: VPS: Hudson Valley Host

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No

Initial certificate issuance was successful. I ran several dry runs during the period, and they showed no errors. Now the cert is expired and it won’t renew. I tried this within the last ten days before expiration, and then got diverted.

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [June 20, 2018, 7:42pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/2 "2018-06-20T19:42:35Z")

</div>

Hi,

TLS-SNI has been disabled for sursurity purpoese.

You might need to renew with those parameters:  
`sudo certbot renew --preferred-challenges http`

Thank you

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 20, 2018, 8:48pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/3 "2018-06-20T20:48:29Z")

</div>

> [@RobJVargas](#):
>
> certbot --apache renew

The correct form is normally just `certbot renew` if you're not intending to _change_ the validation method, although that doesn't explain the error that you saw.

> [@stevenzhu](#):
>
> TLS-SNI has been disabled for sursurity purpoese.

Nonetheless, this error doesn't directly relate to TLS-SNI-01 being disabled because the CA was willing to use it here. (Switching to HTTP-01 validation is still a good idea for the long term.)

> [@stevenzhu](#):
>
> `sudo certbot renew --preferred-challenges http`

Depending on your Certbot version, this might not have any effect because historically the Apache plugin only supported TLS-SNI-01 and not HTTP-01. See

> [@Solution: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA](https://community.letsencrypt.org/t/solution-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/49983):
>
> I…

for more information about that.

@RobJVargas, I would suggest following these instructions to switch to HTTP-01 validation even though it's not strictly necessary for your renewal. Trying to debug the TLS-SNI-01 problem may not be worth it because of the deprecation of this validation method.

---

<div class="post-metadata">

**Author:** ![RobJVargas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/robjvargas/32/25641_2.png) [@RobJVargas](https://community.letsencrypt.org/u/RobJVargas)\
**Post date:** [June 20, 2018, 9:00pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/4 "2018-06-20T21:00:28Z")

</div>

Thank you, schoen. I totally missed the deprecation of the tls-sni challenge

```
certbot renew --preferred-challenges http

```

That worked for me. Perfect.

Side note that I won't mess with, the solution you linked didn't work for me.

> certbot --authenticator webroot --installer apache \ --webroot-path [redacted] -d \>[robjvargas.com](http://robjvargas.com),[www.robjvargas.com](http://www.robjvargas.com)  
> usage:  
> certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...  
> Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,  
> it will attempt to use a webserver both for obtaining and installing the  
> certificate.  
> certbot: error: unrecognized arguments: --webroot-path

The certbot-auto comes back as an unrecognized command. And I don't have it in the yum repositories I have so far. An issue for later, I guess. As that link states, not all providers are up-to-date.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 20, 2018, 9:08pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/5 "2018-06-20T21:08:28Z")

</div>

> [@RobJVargas](#):
>
> The certbot-auto comes back as an unrecognized command. And I don’t have it in the yum repositories I have so far. An issue for later, I guess. As that link states, not all providers are up-to-date.

I think this is due to the `\ --webroot-path` instead of `--webroot-path`. The `\` is meant to be used only if you're breaking the command over two lines, and, if so, only immediately before the newline character. If the command is all on one line, no `\` should be used.

> [@RobJVargas](#):
>
> The certbot-auto comes back as an unrecognized command. And I don’t have it in the yum repositories I have so far.

To use `certbot-auto`, you have to separately download it first. It's never packaged in OS repositories, but is a downloader that works outside of OS package managers.

[https://certbot.eff.org/lets-encrypt/pip-apache](https://certbot.eff.org/lets-encrypt/pip-apache)

---

<div class="post-metadata">

**Author:** ![RobJVargas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/robjvargas/32/25641_2.png) [@RobJVargas](https://community.letsencrypt.org/u/RobJVargas)\
**Post date:** [June 20, 2018, 10:06pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/6 "2018-06-20T22:06:27Z")

</div>

> I think this is due to the \ --webroot-path instead of --webroot-path. The \ is meant to be used only if you’re breaking the command...  
> Dangit, I know that, too. I just copied and pasted without thinking.

In any event, the http-01 commant worked, so I'll put that into my cron job.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 20, 2018, 10:08pm UTC](https://community.letsencrypt.org/t/renew-incorrect-validation-certificate-for-tls-sni-01-challenge/64865/7 "2018-07-20T22:08:34Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
