Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: safeandtacticalfirearmstraining.com
I ran this command:
It produced this output:
My web server is (include version): Apache
The operating system my web server runs on is (include version): OpenSuse 15.4
My hosting provider, if applicable, is: GoDaddy
I can login to a root shell on my machine (yes or no, or I don't know): Yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot):
I recently set up DDNS service No-IP. GoDaddy now forwards users to stft.ddns.net, which shows in the address bar. My website appears but with a warning that it is not secure. I have run certbot to renew both URL's and received the following output:
certbot -v
Saving debug log to /var/log/letsencrypt/letsencrypt.log
ssl_module is statically linked but --apache-bin is missing; not disabling session tickets.
Plugins selected: Authenticator apache, Installer apache
Which names would you like to activate HTTPS for?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: safeandtacticalfirearmstraining.com
2: www.safeandtacticalfirearmstraining.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Requesting a certificate for safeandtacticalfirearmstraining.com
Performing the following challenges:
http-01 challenge for safeandtacticalfirearmstraining.com
Waiting for verification...
Challenge failed for domain safeandtacticalfirearmstraining.com
http-01 challenge for safeandtacticalfirearmstraining.com
Certbot failed to authenticate some domains (authenticator: apache). The Certificate Authority reported these problems:
Domain: safeandtacticalfirearmstraining.com
Type: unauthorized
Detail: 3.33.251.168: Invalid response from http://safeandtacticalfirearmstraining.com/.well-known/acme-challenge/TjGOqg0OFaZFZzMSTGtmBYcRrAXwDcL3pZnsBQg-_Ok: 403
Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet.
Cleaning up challenges
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
I also connected thru openSSL and received the following:
penssl s_client -connect safeandtacticalfirearmstraining.com:443 MMSServer safeandtacticalfirearmstraining.com
s_client: Use -help for summary.
geno@safeandtacticalfirearmstraining:~> openssl s_client -connect safeandtacticalfirearmstraining.com:443
CONNECTED(00000003)
depth=2 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", CN = Go Daddy Root Certificate Authority - G2
verify return:1
depth=1 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2
verify return:1
depth=0 CN = safeandtacticalfirearmstraining.com
verify return:1
---
Certificate chain
0 s:CN = safeandtacticalfirearmstraining.com
i:C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2
1 s:C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2
i:C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", CN = Go Daddy Root Certificate Authority - G2
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIGqzCCBZOgAwIBAgIIYIB/5A5fIowwDQYJKoZIhvcNAQELBQAwgbQxCzAJBgNV
BAYTAlVTMRAwDgYDVQQIEwdBcml6b25hMRMwEQYDVQQHEwpTY290dHNkYWxlMRow
GAYDVQQKExFHb0RhZGR5LmNvbSwgSW5jLjEtMCsGA1UECxMkaHR0cDovL2NlcnRz
LmdvZGFkZHkuY29tL3JlcG9zaXRvcnkvMTMwMQYDVQQDEypHbyBEYWRkeSBTZWN1
cmUgQ2VydGlmaWNhdGUgQXV0aG9yaXR5IC0gRzIwHhcNMjUwMzA0MTkxMjE2WhcN
MjYwMzA0MTkxMjE2WjAuMSwwKgYDVQQDEyNzYWZlYW5kdGFjdGljYWxmaXJlYXJt
c3RyYWluaW5nLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKP4
UvzgKWpwTPIGQ3TSQZ/+5DU+ZkLcypKnlkYUYUs9yRYRhUQGX169WV8l9e2DR/Ha
Vs2yiWeQvWR2Vi13ADnph1fpu5T+IxKN38QJcgv/SxQ/xFaG5fKVnF03wDNpHdtR
4rhBjG2f35Pb4eBPx/udTw3HS+VNh1rAw3VKH0aYq1B5CxhNS/Cxj3hS2szU4d1k
u3FzGmWUrS19zxYNdU7kQWaywHoa2Lsd+kVnKjybbWyIrKCnQtolHlmL22bRMD9A
cc6tGJ4TNRHHXpEVwMfuXSU3Og8+IwqyjBeZ/gsdkeGjutZK0aFeXZ0qU6pGyjLS
i4a4m0+xQ30H8CyE6t0CAwEAAaOCA0QwggNAMAwGA1UdEwEB/wQCMAAwHQYDVR0l
BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA4GA1UdDwEB/wQEAwIFoDA5BgNVHR8E
MjAwMC6gLKAqhihodHRwOi8vY3JsLmdvZGFkZHkuY29tL2dkaWcyczEtNDA5NTAu
Y3JsMF0GA1UdIARWMFQwSAYLYIZIAYb9bQEHFwEwOTA3BggrBgEFBQcCARYraHR0
cDovL2NlcnRpZmljYXRlcy5nb2RhZGR5LmNvbS9yZXBvc2l0b3J5LzAIBgZngQwB
AgEwdgYIKwYBBQUHAQEEajBoMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5nb2Rh
ZGR5LmNvbS8wQAYIKwYBBQUHMAKGNGh0dHA6Ly9jZXJ0aWZpY2F0ZXMuZ29kYWRk
eS5jb20vcmVwb3NpdG9yeS9nZGlnMi5jcnQwHwYDVR0jBBgwFoAUQMK9J47MNIMw
ojPX+2yz8LQsgM4wLgYDVR0RBCcwJYIjc2FmZWFuZHRhY3RpY2FsZmlyZWFybXN0
cmFpbmluZy5jb20wHQYDVR0OBBYEFIR3xF7j2FFpNcm+zS5Iauv5EdclMIIBfQYK
KwYBBAHWeQIEAgSCAW0EggFpAWcAdgAOV5S8866pPjMbLJkHs/eQ35vCPXEyJd0h
qSWsYcVOIQAAAZVikrflAAAEAwBHMEUCIQD0WYLO5JCw4+ILlJO1LE28M1wGpz+3
1dm/RzBHDAsEpQIgLAHETn8UMIocOOnGmgoEVMTSnzzoXs0KHC46Q9LGBNsAdQBk
EcRspBLsp4kcogIuALyrTygH1B41J6vq/tUDyX3N8AAAAZVikrjVAAAEAwBGMEQC
IDcXLhbH4+QRmLRF9YggyE8+al8idkFU0XDGC8MF7HYoAiBLkq36+tsren/sxgAw
i59N+DvpkzBmbIc+aWZBLkApUAB2AMs49xWJfIShRF9bwd37yW7ymlnNRwppBYWw
yxTDFFjnAAABlWKSuYoAAAQDAEcwRQIgF4PXGrMIL8KsjRhedHb/1aIa2Rzh2iNr
WKMjTTd8aPoCIQDYUoFCYgdMGzWckWnTZpVuC9fKOqZdXAUlfu8j8nSdrTANBgkq
hkiG9w0BAQsFAAOCAQEAgrXibZscOIvDBL9NYqfIt/UUy/fsUVtShHFQH0jDOQxd
sLqOE9QiaY1T5Sr+mtX1RomtVkd3QrxOjFypLtOByBnGDP9ANgGa4C7VfawnFnPN
5/1oOsllr1BKRrXWES48hN7Yr1jjrQ79RKj0fKeZsEoknWsPcxxh9EouzHSnBa4b
hUDZApMcGmfoDKKLTiKfcHqQk0njXdpE5n43dFHO4UdQKVUukJ+OYrL3ktWDj3KC
WHO5JsiHGr8fhp4hSpgBI3GS+wh/LwCTGue6u4QNnzDIaeGnPlemdieH2omLoHcT
c8IlIw+UyT28ZB0NsqfTz45ZMMjOxo1CJIjwfhw7+w==
-----END CERTIFICATE-----
subject=CN = safeandtacticalfirearmstraining.com
issuer=C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 3492 bytes and written 409 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
closed
How can I further troubleshoot this problem?
Thanks,
Gene