Renewal failure


#1

Renewal fails. This appears to be because letsencrypt is attempting to contact a domain called
vogon.net.well-known rather than vogon.net.

This is important. My certificate has expired.

Worked (untouched) for many renewals. Nothing on my side has changed.


My domain is: vogon.net

I ran this command: certbot renew

It produced this output:

-------------------------------------------------------------------------------
Processing /etc/letsencrypt/renewal/vogon.net.conf
-------------------------------------------------------------------------------
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator webroot, Installer None
Starting new HTTPS connection (1): acme-v01.api.letsencrypt.org
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for vogon.net
Waiting for verification...
Cleaning up challenges
Attempting to renew cert (vogon.net) from /etc/letsencrypt/renewal/vogon.net.conf produced an unexpected error: Failed authorization procedure. vogon.net (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Fetching https://vogon.net.well-known/acme-challenge/7FqWNPIilLL9iPkwdOvj0wwMaY9kMmn7Seghul-ShL4: Error getting validation data. Skipping.

-------------------------------------------------------------------------------
Processing /etc/letsencrypt/renewal/or-chl.com.conf
-------------------------------------------------------------------------------
Cert not yet due for renewal
Plugins selected: Authenticator webroot, Installer None

-------------------------------------------------------------------------------
Processing /etc/letsencrypt/renewal/or-firearms-info.com.conf
-------------------------------------------------------------------------------
Cert not yet due for renewal
Plugins selected: Authenticator webroot, Installer None

-------------------------------------------------------------------------------
Processing /etc/letsencrypt/renewal/thoughtsoftheguru.com.conf
-------------------------------------------------------------------------------
Cert not yet due for renewal
Plugins selected: Authenticator webroot, Installer None
All renewal attempts failed. The following certs could not be renewed:
  /etc/letsencrypt/live/vogon.net/fullchain.pem (failure)

-------------------------------------------------------------------------------

The following certs are not due for renewal yet:
  /etc/letsencrypt/live/or-chl.com/fullchain.pem expires on 2018-10-30 (skipped)
  /etc/letsencrypt/live/or-firearms-info.com/fullchain.pem expires on 2018-10-01 (skipped)
  /etc/letsencrypt/live/thoughtsoftheguru.com/fullchain.pem expires on 2018-11-04 (skipped)
All renewal attempts failed. The following certs could not be renewed:
  /etc/letsencrypt/live/vogon.net/fullchain.pem (failure)
-------------------------------------------------------------------------------
1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: vogon.net
   Type:   connection
   Detail: Fetching
   https://vogon.net.well-known/acme-challenge/7FqWNPIilLL9iPkwdOvj0wwMaY9kMmn7Seghul-ShL4:
   Error getting validation data

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address. Additionally, please check that
   your computer has a publicly routable IP address and that no
   firewalls are preventing the server from communicating with the
   client. If you're using the webroot plugin, you should also verify
   that you are serving files from the webroot path you provided.

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is: N/A

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No


#2

Your HTTP -> HTTPS redirect is malfunctioning. To be more specific: it’s missing a /.

You’re redirecting http://vogon.net/.well-known/ to https://vogon.net.well-known/ while it should be https://vogon.net/.well-known/

See the difference?


#3

AH! you are right. The redirect was missing the trailing /.
Thanks!! I stared at this for ages, not seeing it … as usual, a fresh set of eyes sees it right away.


#4

The DNS error when I tried to open the challenge gave it away :wink:


#5

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.