# Requests.exceptions.ConnectionError: HTTPSConnectionPool(host='acme-v02.api.letsencrypt.org', port=443): Max retries exceeded with url: /directory (Caused by NewConnectionError('\<urllib3.connection.HTTPSConnection object at 0x7ff299f5b850\>

**URL:** <https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966>\
**Category:** Help\
**Created:** [March 22, 2023, 5:05am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966 "2023-03-22T05:05:00Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![bobbb23332](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bobbb23332/32/68803_2.png) [@bobbb23332](https://community.letsencrypt.org/u/bobbb23332)\
**Post date:** [March 22, 2023, 5:05am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/1 "2023-03-22T05:05:00Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:

[cutegirlsinshorts.org](http://cutegirlsinshorts.org)

I ran this command:

certbot certonly

It produced this output:

Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2  
An unexpected error occurred:  
requests.exceptions.ConnectionError: HTTPSConnectionPool(host='[acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)', port=443): Max retries exceeded with url: /directory (Caused by NewConnectionError('\<urllib3.connection.HTTPSConnection object at 0x7feb86ee24a0\>: Failed to establish a new connection: [Errno -3] Temporary failure in name resolution'))

My web server is (include version):

OpenLiteSpeed 1.7.16

The operating system my web server runs on is (include version):

Linux  
#1 SMP Thu Dec 15 20:31:06 MSK 2022

My hosting provider, if applicable, is:

OpenLiteSpeed (EC2 Instance launched on AWS)

I can login to a root shell on my machine (yes or no, or I don't know):

Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

Yes

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):

1.21.0

p.s. I went to [https://check-host.net/](https://check-host.net/) and tried all the tabs. They all responded with normal statuses. But when I went to try the "Ping" tab, all results came up as "Result 0/4 traceroute"

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [March 22, 2023, 6:23am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/2 "2023-03-22T06:23:29Z")

</div>

Hi @bobbb23332,

This error suggests that your server can't make the necessary outgoing connection to the Let's Encrypt API server. Can you think of a reason why that could be? Is there any firewall or configuration that you would expect to be blocking outgoing connections from your server?

Can you try something like this?

`curl -v https://acme-v02.api.letsencryp.org/directory`

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 22, 2023, 6:56am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/3 "2023-03-22T06:56:54Z")

</div>

I commonly see such DNS resolving errors by misconfigured Docker instances.

---

<div class="post-metadata">

**Author:** ![bobbb23332](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bobbb23332/32/68803_2.png) [@bobbb23332](https://community.letsencrypt.org/u/bobbb23332)\
**Post date:** [March 22, 2023, 7:16am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/4 "2023-03-22T07:16:57Z")

</div>

> [@schoen](#):
>
> curl -v [https://acme-v02.api.letsencryp.org/directory](https://acme-v02.api.letsencryp.org/directory)

Could it be the EC2 instance? Does the EC2 have the ability to block these operations coming from this server? If so then maybe it can be a port forwarding issue I don't know. I checked security groups and ports 22, 80 and 443 are all allowed.

I ran curl -v [https://acme-v02.api.letsencryp.org/directory](https://acme-v02.api.letsencryp.org/directory) and this is the result:

```nohighlight
* Could not resolve host: acme-v02.api.letsencryp.org
* Closing connection 0
curl: (6) Could not resolve host: acme-v02.api.letsencryp.org

```

---

<div class="post-metadata">

**Author:** ![JamesLE](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jamesle/32/49364_2.png) [@JamesLE](https://community.letsencrypt.org/u/JamesLE)\
**Post date:** [March 22, 2023, 7:42am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/5 "2023-03-22T07:42:21Z")

</div>

Oops, try again with the missing `t` in `letsencrypt` added?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 22, 2023, 10:37am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/7 "2023-03-22T10:37:19Z")

</div>

Try it this way:  
`curl -v https://acme-v02.api.letsencrypt.org/directory`

---

<div class="post-metadata">

**Author:** ![bobbb23332](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bobbb23332/32/68803_2.png) [@bobbb23332](https://community.letsencrypt.org/u/bobbb23332)\
**Post date:** [March 22, 2023, 2:40pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/8 "2023-03-22T14:40:45Z")

</div>

I received this:

- Could not resolve host: [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)
- Closing connection 0  
curl: (6) Could not resolve host: [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 22, 2023, 2:58pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/9 "2023-03-22T14:58:23Z")

</div>

Please fix your systems DNS resolving capabilities and try again after DNS has been fixed.

---

<div class="post-metadata">

**Author:** ![bobbb23332](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bobbb23332/32/68803_2.png) [@bobbb23332](https://community.letsencrypt.org/u/bobbb23332)\
**Post date:** [March 22, 2023, 3:42pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/10 "2023-03-22T15:42:43Z")

</div>

Is this what you are talking about? I have these DNS settings set where my domain was bought from:

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/1/d/1d108bff1f74d8f6f5002b0867f530a92c19837b.png)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 22, 2023, 4:31pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/11 "2023-03-22T16:31:45Z")

</div>

No, that's the DNS settings for your domain. That's something else than the DNS **resolving** capabilities of a system. See **for example** stuff like [curl - amazon ec2 instance unable to resolve host - Stack Overflow](https://stackoverflow.com/questions/22614374/amazon-ec2-instance-unable-to-resolve-host)

---

<div class="post-metadata">

**Author:** ![bobbb23332](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bobbb23332/32/68803_2.png) [@bobbb23332](https://community.letsencrypt.org/u/bobbb23332)\
**Post date:** [March 22, 2023, 5:12pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/12 "2023-03-22T17:12:23Z")

</div>

So I'm guessing the area I need to be checking is the server of the VPS? I bought this from OpenLiteSpeed which is the VPS hoster which I used to launch an EC2 instance. Is this where I should fix the DNS resolving issues ?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 22, 2023, 5:13pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/13 "2023-03-22T17:13:09Z")

</div>

Probably.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [March 23, 2023, 7:21am UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/14 "2023-03-23T07:21:35Z")

</div>

> [@JamesLE](#):
>
> Oops, try again with the missing `t` in `letsencrypt` added?

(oops!)

---

<div class="post-metadata">

**Author:** ![bobbb23332](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bobbb23332/32/68803_2.png) [@bobbb23332](https://community.letsencrypt.org/u/bobbb23332)\
**Post date:** [March 23, 2023, 3:14pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/15 "2023-03-23T15:14:44Z")

</div>

I have found the reason for this, my AWS account services was limited by the AWS support team due to a recent compromise in security credentials. Kind of a bummer that they don't explicitly mentioned the services that were affected! It is working now.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 22, 2023, 3:14pm UTC](https://community.letsencrypt.org/t/requests-exceptions-connectionerror-httpsconnectionpool-host-acme-v02-api-letsencrypt-org-port-443-max-retries-exceeded-with-url-directory-caused-by-newconnectionerror-urllib3-connection-httpsconnection-object-at-0x7ff299f5b850/194966/16 "2023-04-22T15:14:53Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
