# Renewing with apache

**URL:** <https://community.letsencrypt.org/t/renewing-with-apache/37290>\
**Category:** Help\
**Created:** [July 2, 2017, 8:28pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290 "2017-07-02T20:28:45Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![scottismyname](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@scottismyname](https://community.letsencrypt.org/u/scottismyname)\
**Post date:** [July 2, 2017, 8:28pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/1 "2017-07-02T20:28:45Z")

</div>

Please fill out the fields below so we can help you better.

My domain is: [socomusic.com](http://socomusic.com)

I ran this command: certbot renew

It produced this output:  
No vhost exists with servername or alias of: [socomusic.com](http://socomusic.com) (or it’s in a file with multiple vhosts, which Certbot can’t parse yet). No vhost was selected. Please specify ServerName or ServerAlias in the Apache config, or split vhosts into separate files.  
Falling back to default vhost \*:443…  
No vhost exists with servername or alias of: [socomusic.net](http://socomusic.net) (or it’s in a file with multiple vhosts, which Certbot can’t parse yet). No vhost was selected. Please specify ServerName or ServerAlias in the Apache config, or split vhosts into separate files.  
Falling back to default vhost \*:443…  
No vhost exists with servername or alias of: [www.socomusic.com](http://www.socomusic.com) (or it’s in a file with multiple vhosts, which Certbot can’t parse yet). No vhost was selected. Please specify ServerName or ServerAlias in the Apache config, or split vhosts into separate files.  
Falling back to default vhost \*:443…  
No vhost exists with servername or alias of: [www.socomusic.net](http://www.socomusic.net) (or it’s in a file with multiple vhosts, which Certbot can’t parse yet). No vhost was selected. Please specify ServerName or ServerAlias in the Apache config, or split vhosts into separate files.  
Falling back to default vhost \*:443…  
Waiting for verification…  
Cleaning up challenges  
Attempting to renew cert from /etc/letsencrypt/renewal/www.socomusic.com.conf produced an unexpected error: Failed authorization procedure. [socomusic.com](http://socomusic.com) (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for tls-sni-01 challenge.  
…

My web server is (include version): Apache

The operating system my web server runs on is (include version): Ubuntu 14.04

My hosting provider, if applicable, is: [vps.net](http://vps.net)

I can login to a root shell on my machine (yes or no, or I don’t know): Yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): No

My renewal configuration file looks like this.

# renew\_before\_expiry = 30 days

cert = /etc/letsencrypt/live/www.socomusic.com/cert.pem  
privkey = /etc/letsencrypt/live/www.socomusic.com/privkey.pem  
chain = /etc/letsencrypt/live/www.socomusic.com/chain.pem  
fullchain = /etc/letsencrypt/live/www.socomusic.com/fullchain.pem  
version = 0.12.0  
archive\_dir = /etc/letsencrypt/archive/www.socomusic.com

# Options and defaults used in the renewal process

[renewalparams]  
installer = apache  
authenticator = apache  
account = xxxxxxxxxxxxxxxxxxxx

I tried renewing with apache started first, and then i stopped the service and tried again, both result in the same error.

Of note, I auto redirect all traffic from port 80 to 443 in my vhosts file in apache:

```
<VirtualHost 68.169.46.243:80>
     ServerName socomusic.com
     Redirect / https://socomusic.com/
</VirtualHost>

```

I tried turning this off and renewing again, and it doesn’t work.

Any help would be appreciated!

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [July 2, 2017, 9:20pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/2 "2017-07-02T21:20:53Z")

</div>

Try disabling the redirection and adding something like:  
Alias /.well-known/acme-challenge /local/folder  
Alias /.well-known/acme-challenge/ /local/folder/

then place a “test.txt” file in that local folder.  
then after that file accessible from the Internet ([http://socomusic.com/.well-known/acme-challenge/test.txt](http://socomusic.com/.well-known/acme-challenge/test.txt))  
try renewing again.

---

<div class="post-metadata">

**Author:** ![scottismyname](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@scottismyname](https://community.letsencrypt.org/u/scottismyname)\
**Post date:** [July 2, 2017, 10:29pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/3 "2017-07-02T22:29:54Z")

</div>

Thanks for the reply. I have tried doing as you suggested but am still getting the same error.

I did verify that the test.txt file is accessible too, and it is. Do I need to stop apache before trying to restart?

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [July 2, 2017, 10:33pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/4 "2017-07-02T22:33:42Z")

</div>

I think this advice isn’t directly relevant because `/.well-known/acme-challenge` (indeed, making any actual web requests at all) is only used by the HTTP-01 challenge type, which is only supported by the Certbot webroot plugin. The apache plugin, which your configuration file says you’re using, only uses the TLS-SNI-01 challenge type, which makes a TLS connection and checks for a particular certificate, but doesn’t even need to make a web request.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [July 2, 2017, 10:34pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/5 "2017-07-02T22:34:50Z")

</div>

@bmw, could you take a look at this as another potential Apache configuration parsing issue?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [July 2, 2017, 10:44pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/6 "2017-07-02T22:44:20Z")

</div>

Agreed, in the interim, use of:  
–webroot  
–webroot-path  
might get the certs renewed.  
As, [http://socomusic.com/.well-known/acme-challenge/test.txt](http://socomusic.com/.well-known/acme-challenge/test.txt) works.

---

<div class="post-metadata">

**Author:** ![scottismyname](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@scottismyname](https://community.letsencrypt.org/u/scottismyname)\
**Post date:** [July 2, 2017, 11:15pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/7 "2017-07-02T23:15:30Z")

</div>

I’m curious what default configuration file it’s trying to use. When I was configuring stuff I did move some stuff out of the way that didn’t see to make a difference to my server serving properly. Perhaps I moved a default file out of the way?

```
No vhost exists with servername or alias of: socomusic.com (or it's in a file with multiple vhosts, which Certbot can't 
parse yet). No vhost was selected. Please specify ServerName or ServerAlias in the Apache config, or split vhosts 
into separate files.
```

---

<div class="post-metadata">

**Author:** ![scottismyname](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@scottismyname](https://community.letsencrypt.org/u/scottismyname)\
**Post date:** [July 2, 2017, 11:19pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/8 "2017-07-02T23:19:39Z")

</div>

When I tried to renew using --webroot and --webroot-path I get the following error:

Attempting to renew cert from /etc/letsencrypt/renewal/www.socomusic.com.conf produced an unexpected error: Failed authorization procedure. [socomusic.com](http://socomusic.com) (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [http://socomusic.com/.well-known/acme-challenge/4LM9yxnw4tS4YyKFsn\_hekHcPQl1P\_l75SQhg6XJwaE:](http://socomusic.com/.well-known/acme-challenge/4LM9yxnw4tS4YyKFsn_hekHcPQl1P_l75SQhg6XJwaE:) "

404 Not Found
# Not Found

---

<div class="post-metadata">

**Author:** ![scottismyname](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@scottismyname](https://community.letsencrypt.org/u/scottismyname)\
**Post date:** [July 2, 2017, 11:32pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/9 "2017-07-02T23:32:21Z")

</div>

I was able to solve the problem. Under my configuration, I had to move back the file that I had moved out of the way:  
/etc/apache2/sites-available/000-default-le-ssl.conf

Within that file, I made sure that my settings for port 443 were the same as in my live environment.

Certs were renewed successfully.

The only suggestion I have is for the error message to be a little more verbose on what it is trying to look at?

---

<div class="post-metadata">

**Author:** ![bmw](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bmw/32/7797_2.png) [@bmw](https://community.letsencrypt.org/u/bmw)\
**Post date:** [July 5, 2017, 3:03pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/10 "2017-07-05T15:03:50Z")

</div>

I’m glad you got it working!

Before moving `000-default-le-ssl.conf` back, Certbot was showing warnings about being unable to find a `VirtualHost` with a `ServerName` or `ServerAlias` matching the domain you requested. What additional output would you like to see from Certbot that would have helped you debug this more quickly?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 4, 2017, 3:04pm UTC](https://community.letsencrypt.org/t/renewing-with-apache/37290/11 "2017-08-04T15:04:12Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
