Hi guys.
I restored a previous instance of my aws server yesterday and not it is not renewing the cert. I never had this before.
I looked in the renewal directory and the conf file in there, is the webroot stanza dynamically generated? I don’t remember putting the cdn.grabaguru.com in there.
Anyway, I did not do anything out of the ordinary so not sure why it’s balking. Should I turn CloudFront off. For some reason it’s failing and denying there. I invalidated everything there as well but no dice yet.
My domain is:grabaguru.com
I ran this command:
It produced this output:
[ec2-user@www renewal]$ /opt/letsencrypt/letsencrypt-auto --no-bootstrap renew
Requesting to rerun /opt/letsencrypt/letsencrypt-auto with root privileges…
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Processing /etc/letsencrypt/renewal/grabaguru.com.conf
Cert is due for renewal, auto-renewing…
Plugins selected: Authenticator webroot, Installer None
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for cdn.grabaguru.com
Waiting for verification…
Challenge failed for domain cdn.grabaguru.com
http-01 challenge for cdn.grabaguru.com
Cleaning up challenges
Attempting to renew cert (grabaguru.com) from /etc/letsencrypt/renewal/grabaguru.com.conf produced an unexpected error: Some challenges have failed… Skipping.
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/grabaguru.com/fullchain.pem(failure)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/grabaguru.com/fullchain.pem(failure)
1 renew failure(s), 0 parse failure(s)
IMPORTANT NOTES:
-
The following errors were reported by the server:
Domain: cdn.grabaguru.com
Type: unauthorized
Detail: Invalid response from
http://cdn.grabaguru.com/.well-known/acme-challenge/H2q4oVhACboi_-nw7TbnkQCXkgrwmXGkOQ2_t19vMyc
[2600:9000:2038:4c00:1d:b292:12c0:93a1]: "<!DOCTYPE HTML PUBLIC
“-//W3C//DTD HTML 4.01 Transitional//EN”
“http://www.w3.org/TR/html4/loose.dtd”>\n<META
HTTP-EQ"
To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
My web server is (include version):http2
The operating system my web server runs on is (include version): Amazon linux
My hosting provider, if applicable, is:Aws
I can login to a root shell on my machine (yes or no, or I don’t know): yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):no
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you’re using Certbot):