I've been sucessfully and very happy using LetsEncrypt for a long time now, but suddently two days ago I've been getting errors:
Processing /etc/letsencrypt/renewal/tjkmaintenance.ca-0001.conf
Renewing an existing certificate for tjkmaintenance.ca and www.tjkmaintenance.ca
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
Domain: tjkmaintenance.ca
Type: connection
Detail: During secondary validation: Fetching http://tjkmaintenance.ca/.well-known/acme-challenge/wlPgg2qsCIiqnA1yKly9XR_ygkHh8QBc6eUxHm68B7s: Timeout during connect (likely firewall problem)
Domain: www.tjkmaintenance.ca
Type: connection
Detail: During secondary validation: Fetching http://www.tjkmaintenance.ca/.well-known/acme-challenge/nujg3dYYLNBzVQMVxbDgFv6dRdcmYPTLx0egZ6PmQ1M: Timeout during connect (likely firewall problem)
Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.
Failed to renew certificate tjkmaintenance.ca-0001 with error: Some challenges have failed.
Testing the validation at the same time I see this:
for crocusplains.com/.well-known/acme-challenge/nujg3dYYLNBzVQMVxbDgFv6dRdcmYPTLx0egZ6PmQ1M
URL tested crocusplains.com/.well-known/acme-challenge/nujg3dYYLNBzVQMVxbDgFv6dRdcmYPTLx0egZ6PmQ1M
Website Test performed from New York, NY on 2024-04-17 01:00:58 (GMT +00:00)
Status OK
Resolved as
Response Time 0.157 seconds
DNS 0.000 s
Connect 0.078 s
Redirect 0.000 s
First Byte 0.079 s
Last Byte 0.000 s
Size 87 bytes
Which seems to indicate that the firewall and all letsencrypt configurtions seem to be working. I'm struggling to determine where the problem is.
My domain is: tjkmaintenance.ca
I ran this command: certbot renew --agree-tos -w /data/letsencrypt
My web server is (include version): nginx version: nginx/1.20.2
The operating system my web server runs on is (include version): Centos 7
My hosting provider, if applicable, is: Self Hosted
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): certbot 1.16.0