# Request to unblock rate limit

**URL:** <https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839>\
**Category:** Help\
**Created:** [June 26, 2017, 11:15am UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839 "2017-06-26T11:15:53Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmlogic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dmlogic/32/14432_2.png) [@dmlogic](https://community.letsencrypt.org/u/dmlogic)\
**Post date:** [June 26, 2017, 11:15am UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/1 "2017-06-26T11:15:54Z")

</div>

Hi

Running `certbot renew` produces:

> There were too many requests of a given type :: Your IP, 2a03:b0c0:1:d0::65:b001, has been blocked due to ridiculously excessive traffic. Once this is corrected you may request this be reviewed on our forum [https://community.letsencrypt.org](https://community.letsencrypt.org)

I have traced the problem to having both Nginx and Caddy webservers installed and this problem has now been corrected (in favour of Nginx). I have waited a week but still get the rate limit message.

Please could somebody advise the procedure for unblocking the server so I can renew the certificate?

many thanks

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [June 26, 2017, 3:28pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/2 "2017-06-26T15:28:16Z")

</div>

Hi @dmlogic,

Glad to hear you were able to sort out the problem that was causing you to submit so many requests!

> [@dmlogic](#):
>
> I have waited a week but still get the rate limit message.

As the error message mentions the only way out of this state is by opening a community forum thread (like this one!).

> [@dmlogic](#):
>
> Please could somebody advise the procedure for unblocking the server so I can renew the certificate?

I've raised a ticket with operations to have `2a03:b0c0:1:d0::65:b001` cleared. I will let you know via this thread when the change has been made in production.

Thanks for addressing your misconfiguration! We appreciate it!

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [June 26, 2017, 3:30pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/3 "2017-06-26T15:30:56Z")

</div>

That’s the first time that I’ve heard of the “ridiculously excessive traffic” rate limit. Should it be documented somewhere, or is it just meant as a failsafe for super-extreme situations that nobody should anticipate encountering? 🙂

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [June 26, 2017, 4:09pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/4 "2017-06-26T16:09:23Z")

</div>

> [@schoen](#):
>
> or is it just meant as a failsafe for super-extreme situations that nobody should anticipate encountering?

It's this - reserved for cases where someone has been hitting a 429 excessively for a considerable period. I think documenting it will be of limited value since the error message explains the only recourse already and the only way to find yourself in this position is from hitting an already documented rate limit in excess for long enough to have ops apply this block adhoc.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [June 26, 2017, 5:01pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/5 "2017-06-26T17:01:32Z")

</div>

> [@dmlogic](#):
>
> Please could somebody advise the procedure for unblocking the server so I can renew the certificate?

Hi again @dmlogic,

The block on `2a03:b0c0:1:d0::65:b001` has been removed. Please let me know if you still experience the same error.

Thanks!

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [June 26, 2017, 5:28pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/6 "2017-06-26T17:28:02Z")

</div>

@dmlogic, can you provide more details on how the interaction between Nginx and Caddy produced such excessive traffic? I’d love to work with @mholt on reducing Caddy’s impact in error situations like this one. Was Caddy failing to start because it couldn’t bind a port it needed?

---

<div class="post-metadata">

**Author:** ![dmlogic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dmlogic/32/14432_2.png) [@dmlogic](https://community.letsencrypt.org/u/dmlogic)\
**Post date:** [June 26, 2017, 6:12pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/7 "2017-06-26T18:12:43Z")

</div>

> [@jsha](#):
>
> Was Caddy failing to start because it couldn't bind a port it needed

Yeah, pretty sure that was something like that. I had a report the site was down, found the server basically dead through lack of disk space caused by a full /tmp folder. Realised pretty quickly that an aborted experiment with installing Caddy had been left running and I think it was just constantly fighting Nginx for the ports. I didn't attempt to investigate beyond that, just cleared out /tmp, got rid of the Caddy service and it all came back up.

---

<div class="post-metadata">

**Author:** ![mholt](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mholt/32/70171_2.png) [@mholt](https://community.letsencrypt.org/u/mholt)\
**Post date:** [June 26, 2017, 6:22pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/8 "2017-06-26T18:22:55Z")

</div>

Did you use Let’s Encrypt’s staging endpoint for your experimental setups?

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [June 26, 2017, 6:31pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/9 "2017-06-26T18:31:25Z")

</div>

Was this with systemd or init? If systemd, were you using the systemd scripts provided in the Caddy repo?

Thanks,  
Jacob

---

<div class="post-metadata">

**Author:** ![dmlogic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dmlogic/32/14432_2.png) [@dmlogic](https://community.letsencrypt.org/u/dmlogic)\
**Post date:** [June 27, 2017, 7:07am UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/10 "2017-06-27T07:07:58Z")

</div>

sorry I don’t remember exactly how it was set up. I dumped Caddy in a hurry when I realised what was going on.

From memory, It was using init.d based on examples included with Caddy, but I didn’t keep the script.

---

<div class="post-metadata">

**Author:** ![dmlogic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dmlogic/32/14432_2.png) [@dmlogic](https://community.letsencrypt.org/u/dmlogic)\
**Post date:** [June 27, 2017, 8:51am UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/11 "2017-06-27T08:51:38Z")

</div>

> [@cpu](#):
>
> Please let me know if you still experience the same error

I've updated certbot and renewed the certificate with `certbot --nginx certonly -d {domain}`, but attempting `certbot renew --dry-run` produces the same error as before. Would it be best to just clear everything out and start again?

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [June 27, 2017, 1:19pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/12 "2017-06-27T13:19:01Z")

</div>

> [@dmlogic](#):
>
> but attempting certbot renew --dry-run produces the same error as before. Would it be best to just clear everything out and start again?

Interesting! Thanks for reporting that. Since `--dry-run` uses the staging environment I suspect our operations team only removed the block for the production environment. I'll ask about getting this fixed and report back when I know more. Thanks for your patience.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [June 27, 2017, 4:37pm UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/13 "2017-06-27T16:37:26Z")

</div>

Hi again @dmlogic,

I’m told the staging ban has been lifted. You should be good to go with `--dry-run` as well. Thanks again.

---

<div class="post-metadata">

**Author:** ![dmlogic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dmlogic/32/14432_2.png) [@dmlogic](https://community.letsencrypt.org/u/dmlogic)\
**Post date:** [June 28, 2017, 6:17am UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/14 "2017-06-28T06:17:24Z")

</div>

> [@cpu](#):
>
> You should be good to go with --dry-run as well. Thanks again.

Lovely, thanks for all the help

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 28, 2017, 6:17am UTC](https://community.letsencrypt.org/t/request-to-unblock-rate-limit/36839/15 "2017-07-28T06:17:37Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
