Please fill out the fields below so we can help you better.
My domain is: dbs9.dx30.net SNI (5 domains)
I ran this command: letsencrypt-auto renew --dry-run --agree-tos --apache (and many variations)
It produced this output:
Processing /etc/letsencrypt/renewal/dbs9.dx30.net.conf
Cert is due for renewal, auto-renewing…
Renewing an existing certificate
Performing the following challenges:
tls-sni-01 challenge for dbs9.dx30.net
tls-sni-01 challenge for www.harshawtrane.com
tls-sni-01 challenge for www.oksanamastersusa.com
tls-sni-01 challenge for www.stseducation-us.com
tls-sni-01 challenge for www.thecenteronline.org
Encountered vhost ambiguity but unable to ask for user guidance in non-interactive mode. Currently Certbot needs each vhost to be in its own conf file, and may need vhosts to be explicitly labelled with ServerName or ServerAlias directories.
Falling back to default vhost *:443…
Encountered vhost ambiguity but unable to ask for user guidance in non-interactive mode. Currently Certbot needs each vhost to be in its own conf file, and may need vhosts to be explicitly labelled with ServerName or ServerAlias directories.
Falling back to default vhost *:443…
Encountered vhost ambiguity but unable to ask for user guidance in non-interactive mode. Currently Certbot needs each vhost to be in its own conf file, and may need vhosts to be explicitly labelled with ServerName or ServerAlias directories.
Falling back to default vhost *:443…
Encountered vhost ambiguity but unable to ask for user guidance in non-interactive mode. Currently Certbot needs each vhost to be in its own conf file, and may need vhosts to be explicitly labelled with ServerName or ServerAlias directories.
Falling back to default vhost *:443…
Encountered vhost ambiguity but unable to ask for user guidance in non-interactive mode. Currently Certbot needs each vhost to be in its own conf file, and may need vhosts to be explicitly labelled with ServerName or ServerAlias directories.
Falling back to default vhost *:443…
Waiting for verification…
Cleaning up challenges
Attempting to renew cert from /etc/letsencrypt/renewal/dbs9.dx30.net.conf produced an unexpected error: Failed authorization procedure. dbs9.dx30.net (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for TLS-SNI-01 challenge. Requested 7555e3241e782cfe623d9989cabc9c3e.fb82ffedf865b0d88f79a2f29a3cbd04.acme.invalid from 23.253.213.249:443. Received 2 certificate(s), first certificate had names “dbs9.dx30.net, www.harshawtrane.com, www.oksanamastersusa.com, www.stseducation-us.com, www.thecenteronline.org”, www.harshawtrane.com (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for TLS-SNI-01 challenge. Requested 1dc2ed1a55939205f36996b763827285.9aadb37c9d0f7e5fe110cd019960fb59.acme.invalid from 23.253.213.249:443. Received 2 certificate(s), first certificate had names “dbs9.dx30.net, www.harshawtrane.com, www.oksanamastersusa.com, www.stseducation-us.com, www.thecenteronline.org”, www.oksanamastersusa.com (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for TLS-SNI-01 challenge. Requested a3e0e8e97ad89ec4334af45d02c779d2.969bccc166bc7092ab4e5ca7371f8ef0.acme.invalid from 23.253.213.249:443. Received 2 certificate(s), first certificate had names “dbs9.dx30.net, www.harshawtrane.com, www.oksanamastersusa.com, www.stseducation-us.com, www.thecenteronline.org”, www.stseducation-us.com (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for TLS-SNI-01 challenge. Requested b2a3b2d6a5ef1dc6c3e0e5014139b6f3.a6b68a54eb69f6180463b13e3ea01851.acme.invalid from 23.253.213.249:443. Received 2 certificate(s), first certificate had names “dbs9.dx30.net, www.harshawtrane.com, www.oksanamastersusa.com, www.stseducation-us.com, www.thecenteronline.org”. Skipping.
** DRY RUN: simulating ‘certbot renew’ close to cert expiry
** (The test certificates below have not been saved.)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/dbs9.dx30.net/fullchain.pem (failure)
** DRY RUN: simulating ‘certbot renew’ close to cert expiry
** (The test certificates above have not been saved.)
1 renew failure(s), 0 parse failure(s)
IMPORTANT NOTES:
-
The following errors were reported by the server:
Domain: dbs9.dx30.net
Type: unauthorized
Detail: Incorrect validation certificate for TLS-SNI-01 challenge.
Requested
7555e3241e782cfe623d9989cabc9c3e.fb82ffedf865b0d88f79a2f29a3cbd04.acme.invalid
from 23.253.213.249:443. Received 2 certificate(s), first
certificate had names “dbs9.dx30.net, www.harshawtrane.com,
www.oksanamastersusa.com, www.stseducation-us.com,
www.thecenteronline.org”Domain: www.harshawtrane.com
Type: unauthorized
Detail: Incorrect validation certificate for TLS-SNI-01 challenge.
Requested
1dc2ed1a55939205f36996b763827285.9aadb37c9d0f7e5fe110cd019960fb59.acme.invalid
from 23.253.213.249:443. Received 2 certificate(s), first
certificate had names “dbs9.dx30.net, www.harshawtrane.com,
www.oksanamastersusa.com, www.stseducation-us.com,
www.thecenteronline.org”Domain: www.oksanamastersusa.com
Type: unauthorized
Detail: Incorrect validation certificate for TLS-SNI-01 challenge.
Requested
a3e0e8e97ad89ec4334af45d02c779d2.969bccc166bc7092ab4e5ca7371f8ef0.acme.invalid
from 23.253.213.249:443. Received 2 certificate(s), first
certificate had names “dbs9.dx30.net, www.harshawtrane.com,
www.oksanamastersusa.com, www.stseducation-us.com,
www.thecenteronline.org”Domain: www.stseducation-us.com
Type: unauthorized
Detail: Incorrect validation certificate for TLS-SNI-01 challenge.
Requested
b2a3b2d6a5ef1dc6c3e0e5014139b6f3.a6b68a54eb69f6180463b13e3ea01851.acme.invalid
from 23.253.213.249:443. Received 2 certificate(s), first
certificate had names “dbs9.dx30.net, www.harshawtrane.com,
www.oksanamastersusa.com, www.stseducation-us.com,
www.thecenteronline.org”To fix these errors, please make sure that your domain name was
entered correctly and the DNS A record(s) for that domain
contain(s) the right IP address.
My operating system is (include version): Ubuntu 16.04 LTS
My web server is (include version): Apache/2.4.18 (Ubuntu)
My hosting provider, if applicable, is: self hosted
I can login to a root shell on my machine (yes or no, or I don’t know): Yes
I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No
==================
Other notes …
The current certs are working fine.
Attached the LE debug log.
Attached output of: openssl s_client -showcerts -connect dbs9.dx30.net:443 </dev/null > /tmp/openssl.out.txt
openssl.out.txt (5.6 KB)
letsencrypt.log.txt (60.3 KB)