Renewed My Cert, But Still Have Error in Browser About Invalid Response and Such

Could it be that it just doesn't work sometimes, in --standalone mode, and that it might be fine if I try again some other time? Since @rg305 said there's a very small window of accessibility with --standalone. That said, though: how do I check what's up with port 80 so I can report it here and ask what I can do?

You'd have to run some kind of listener on port 80.
Then test access to it from the Internet.

Okay, so I tried curl 0.0.0.0:80 and got:

curl 0.0.0.0:80
curl: (7) Failed to connect to 0.0.0.0 port 80 after 0 ms: Connection refused

And when I tried curl 39.48.202.121:80, I got this (Basically some HTTP that outputs to this, but it's only the head element with a script tag, and no body element.):

HTTP/1.1 200 Ok Server: micro_httpd Cache-Control: no-cache Date: Tue, 19 Jul 2022 23:43:40 GMT Content-Type: text/html Connection: close Broadband Router

This will NEVER work:

Okay, so how do I run a listener on it? And by accessing it from the internet, do you mean in my browser?

There are many ways:

  • use a web server
  • use the ACME client [with --manual OR --debug mode]
  • use tcpdump (wireshark) to "listen" on the wire

I mean from any other system - one that must reach your server OVER the Internet.
[like from your phone (using cellular)]

I can't connect to port 80. How do I open it for this? Is there a way to do port forwarding on it such that only things like Apache or acme.sh when I run them can get through?

I tried using Telnet on Windows (not WSL, just the host Windows Command Prompt shell) to try to get to port 80 on 0.0.0.0 and my public IP address, and I got an error saying it can't connect to the host on that port. So yeah, now I need to know how to fix it. Could it just be that it's blocked by my firewall?

Edit: Doesn't seem to have worked. I ran:

telnet 39.48.202.121 80

And got this error:

Connecting To 39.48.202.121...Could not open connection to the host, on port 80: Connect
failed

I still got this error even after allowing port 80 through the Windows Firewall.

There is no way to connect to IP "0.0.0.0" - it doesn't exist. Try the real IP of the local system instead.

Connecting to the public IP form the private (LAN) side can be tricky. If the router isn't setup to do hairpining, that will also fail.

If your ultimate aim is get a cert (basically from your windows machine) the simplest thing to do is run an acme client on Windows, then take the resulting certificate and deploy it to your app. You can just run certbot on Windows (for instance) then copy the cert fullchain.pem and private key file to wherever you need it. If you are actually hosting your app in WSL you could even just point to the files in the /mnt/c/certbot/live/

If you're not hosting your app in WSL and just hosting it in Windows you could also just use https://certifytheweb.com (add the Deploy to Generic Server task under Tasks to convert the cert to the files you need). It's a bit less complicated than trying to get acme.sh working/renewing under windows and can do things like restarting your app (if it's a service service) when the cert renews.

You could alternatively setup IIS (on windows) as a reverse proxy to your http (boost) app, then just renew the cert in IIS instead, skipping SSL in your app entirely (Setup IIS with URL Rewrite as a reverse proxy for real world apps - Microsoft Tech Community).

Likewise you could just run Caddy (on windows) as a reverse proxy to your app and let it handle the cert stuff for you.

Thanks. I'll try that.

I'm not hosting the app on WSL but just regular Windows. The app root is in a separate Drive on the hard disk (i.e. not C Drive). That's what I do with all the programming stuff.

I have a TXT record on the root directory in .well-known/acme_challenge. It doesn't seem to be what the DNS challenge needs. So how do I use certbot in this case?

A TXT record is a DNS entry in your DNS control panel for your domain, it's not a text file on disk. It's used when you are using DNS validation (not http validation).

If you are using DNS validation and you are asked to create a TXT record, edit your DNS control panel and add the required TXT record (or use an automated DNS api, you will have to do this for every renewal).

I can't really advise for certbot Dynu DNS but for Certify The Web (which I develop) you would:

  • Create a new managed certificate in the app, add your website domains to the list of names to include in the app.
  • On the authorization tab, select dns-01 instead of http-01, select Dynu (via Posh-ACME) as the DNS provider. Enter/save your Dynu DNS API credentials (Dynu - Posh-ACME)
  • Click test to try adding and deleting a test TXT record record in your DNS
  • If all OK, click Request Certificate to order a new cert from Let's Encrypt
  • If that's all completed, add a Deploy to Generic Server task under Tasks, set the full output file names (including path) under Tasks Parameters for fullchain.pem and privkey.pem (for instance). Save and Run the Task to generate the output files.
  • You now have a cert, whether your app understands that or not is the other half of your problem.

As a general aside regarding talking to port 80 for your app etc, a binding to a local IP (like 127.0.0.1) will only be accessible on the machine itself, but a binding to 0.0.0.0:80 will listen on all IPs. To access your app from any other machine you still have to use a network IP (or a hostname pointing to that IP). So if you were forwarding public port 80 traffic from your router to port 80 on your machine, your machine needs to be listening on the network IP (or all IPs), not just localhost.

What do I need to do for "Filter" under "Domains and Subdomains" when setting up a certificate on the CertifyTheWeb app?

And I couldn't connect to port 80 on my private IP address either, by the way.

Failed to register with Certify DNS.

To add a CNAME record on the DNS, would a record on Dynu be okay? How would I point the app to my account on Dynu.net, though?

I got the cert and setup a task to deploy it, but I don't have the ca.cer file which would be presumably be the CA cert for verifying the actual certs. I think it's because of that I'm getting this exception in my code:

Line 186: Error: load_verify_file: No such file or directory (system library, fopen) [asio.ssl:33558530]

It seems to be an error from boost::asio::ssl::context::load_verify_file().

What I did was set it to provide a PEM certificate file with the cert chain but without the key. What's the correct option to select if I want the cert chain and key in separate files, plus the CA cert in its own file as well?

Messaging here for update.

I still get these messages in my browser when trying to visit my app while the server is running:

# The connection for this site is not secure
**dragonosman.dynu.net** sent an invalid response.
* [Try running Windows Network Diagnostics](javascript:diagnoseErrors()).
ERR_SSL_PROTOCOL_ERROR

And I get this result from running the openssl command I was given here:

CONNECTED(00000148)
11784:error:1409442E:SSL routines:ssl3_read_bytes:tlsv1 alert protocol version:ssl\record\rec_layer_s3.c:1544:SSL alert number 70
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 7 bytes and written 322 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)

Then it exited on its own this time, and in my server app's console window I got this error:
handshake: unsupported protocol (SSL routines, tls_early_post_process_client_hello)

Which I assume is due to a HTTP/2 request inside a TLS ClientHello message.

Is it possible that the SSL error is because of that upgrade request not being supported (yet)?

Edit: @rg305 Thanks for fixing the message formatting.

Sorry, beyond getting an actual certificate I can't really provide any help with your app itself.

If you need the files split into cert file, intermediates + root chain file and key file then that would would be the cert, CA chain and key output file options in Deploy to Generic Server. There is also another Export Certificate task which has more fine grained options and you can use multiple tasks in order to get all the files you need, but there isn't any option to just export the CA root certificate (if that's what you need).