# Setting up certificates error - 403

**URL:** <https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143>\
**Category:** Help\
**Created:** [October 15, 2022, 12:24pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143 "2022-10-15T12:24:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 12:24pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/1 "2022-10-15T12:24:01Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [sending-news.com](http://sending-news.com)

I ran this command: wacs.exe

It produced this output: [[sending-news.com](http://sending-news.com)] Authorizing... [[sending-news.com](http://sending-news.com)]  
Authorizing using http-01 validation (SelfHosting)  
[[sending-news.com](http://sending-news.com)] Authorization result:  
invalid [[sending-news.com](http://sending-news.com)]  
{ "type": "urn:ietf:params:acme:error:unauthorized",  
"detail": "2001:8d8:100f:f000::200:  
Invalid response from  
[http://sending-news.com/.well-known/acme-challenge/tvR2mDX3mH1Fn5VEFewvoGZ\_uI\_WflrRYa5d0t1KNX8:](http://sending-news.com/.well-known/acme-challenge/tvR2mDX3mH1Fn5VEFewvoGZ_uI_WflrRYa5d0t1KNX8:)  
204", "status": 403

My web server is (include version):windows server 2016 IIS 10

The operating system my web server runs on is (include version): windows server 2016

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): win-acme.v2.1.22.1289.x86.pluggable

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 15, 2022, 1:34pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/2 "2022-10-15T13:34:27Z")

</div>

Welcome @maheshjain

I don't know Windows well enough to help but I see a couple odd things. You say you are using Windows IIS server but I see Apache and nginx responding. Having two servers is odd by itself not to mention neither is what you say it should be. Can you explain?

```nohighlight
curl -i6 sending-news.com/.well-known/acme-challenge/TestChallenge123
HTTP/1.1 204
Server: nginx
Date: Sat, 15 Oct 2022 13:28:48 GMT

curl -i6 sending-news.com
HTTP/1.1 302 Found
Server: Apache
Location: http://130.185.119.113/sending-news.com

```

Also, the second test request gets redirected (the 302). But, the Location looks wrong. You have an IP address in front of your domain name. And, that IP is not the one in the DNS for your server even. This is not affecting the HTTP Challenge but points to a likely problem elsewhere.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 15, 2022, 2:31pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/3 "2022-10-15T14:31:42Z")

</div>

> [@maheshjain](#):
>
> "detail": "2001:8d8:100f:f000::200:

What happened to the IPv6 address?

```nohighlight
Name: eddienetworks.ddnsfree.com
Address: 101.112.48.248

```

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 4:33pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/4 "2022-10-15T16:33:22Z")

</div>

@MikeMcQ

I am using server is windows 2016 and IIS version 10

I don’t know how it shows different servers nginx and apache.

Do you think is it related to something wrong in dns entry?

Also I don’t know why it showing IP address im front of domain while browsing.

Please explain me what needs to be done I order to troubleshoot further.  
Thank you

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 4:35pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/5 "2022-10-15T16:35:10Z")

</div>

Ipv6 address but it ping and telnet port 80 443 from outside..

What to do further troubleshooting?

Thank you

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 15, 2022, 5:01pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/6 "2022-10-15T17:01:13Z")

</div>

Please show the IP address found by: `http://ifconfig.co/`

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 5:31pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/7 "2022-10-15T17:31:30Z")

</div>

# [ifconfig.co](http://ifconfig.co) — What is my IP address?

`130.185.119.113`

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [October 15, 2022, 5:39pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/8 "2022-10-15T17:39:46Z")

</div>

DNS Records for [sending-news.com](http://sending-news.com) **[DNS Lookup - Check DNS Records](https://dnschecker.org/all-dns-records-of-domain.php?query=sending-news.com&rtype=ALL&dns=google)**

And here is what I find for an IPv4 address for [sending-news.com](http://sending-news.com)

```nohighlight
$ ping sending-news.com
PING sending-news.com (217.160.0.237) 56(84) bytes of data.
64 bytes from 217-160-0-237.elastic-ssl.ui-r.com (217.160.0.237): icmp_seq=1 ttl=34 time=174 ms
64 bytes from 217-160-0-237.elastic-ssl.ui-r.com (217.160.0.237): icmp_seq=2 ttl=34 time=172 ms
64 bytes from 217-160-0-237.elastic-ssl.ui-r.com (217.160.0.237): icmp_seq=3 ttl=34 time=173 ms
^C
--- sending-news.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2002ms
rtt min/avg/max/mdev = 172.108/173.036/173.908/0.735 ms

$ nslookup
> sending-news.com
Server: 127.0.0.1
Address: 127.0.0.1#53

Non-authoritative answer:
Name: sending-news.com
Address: 217.160.0.237
> set q=soa
> sending-news.com
Server: 127.0.0.1
Address: 127.0.0.1#53

Non-authoritative answer:
sending-news.com
        origin = ns1026.ui-dns.biz
        mail addr = hostmaster.1und1.com
        serial = 2017060113
        refresh = 28800
        retry = 7200
        expire = 604800
        minimum = 600

Authoritative answers can be found from:
> server ns1026.ui-dns.biz
Default server: ns1026.ui-dns.biz
Address: 217.160.81.26#53
> sending-news.com
Server: ns1026.ui-dns.biz
Address: 217.160.81.26#53

sending-news.com
        origin = ns1026.ui-dns.biz
        mail addr = hostmaster.1und1.com
        serial = 2017060113
        refresh = 28800
        retry = 7200
        expire = 604800
        minimum = 600
> set q=a
> sending-news.com
Server: ns1026.ui-dns.biz
Address: 217.160.81.26#53

Name: sending-news.com
Address: 217.160.0.237
>

```

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [October 15, 2022, 5:44pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/9 "2022-10-15T17:44:50Z")

</div>

And as @MikeMcQ has pointed out the redirects, using this [https://www.redirect-checker.org/](https://www.redirect-checker.org/)

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/0/a/0a32d3e0d0f62cabea97a43c720055b7cd32091a.png)

![image](https://global.discourse-cdn.com/letsencrypt/original/3X/d/3/d37a4fb8d30309d53d2f15e23c1e0f75f6a708eb.png)  
And I do not know how Let's Encrypt handles a HTML Response code of 302

> **[HTTP 302](https://en.wikipedia.org/wiki/HTTP_302)**
>
> The HTTP response status code 302 Found is a common way of performing URL redirection. The HTTP/1.0 specification (RFC 1945) initially defined this code, and gave it the description phrase "Moved Temporarily" rather than "Found".
> An HTTP response with this status code will additionally provide a URL in the header field Location. This is an invitation to the user agent (e.g. a web browser) to make a second, otherwise identical, request to the new URL specified in the location field. The end resu...

> **[302 Found - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/302)**
>
> The HyperText Transfer Protocol (HTTP) 302 Found redirect
> status response code indicates that the resource requested has been temporarily moved to
> the URL given by the Location header. A browser redirects to this page
> but search engines don't...

I feel sure other volunteers do know how Let's Encrypt handles a HTML Response code of 302.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 15, 2022, 5:59pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/10 "2022-10-15T17:59:53Z")

</div>

> [@maheshjain](#):
>
> `ifconfig.co` — What is my IP address?
> 
> `130.185.119.113`

That's a problem. Your DNS A record should be your public IP address but it is this instead:

```nohighlight
nslookup sending-news.com
A Address: 217.160.0.237
AAAA Address: 2001:8d8:100f:f000::200

```

I don't know how to check IPv6 address on a Windows Server 2016 but your AAAA address is also probably wrong. You could delete that until you find out what it should be. Let's Encrypt will try to use IPv6 address if one is present.

Your www subdomain has the same wrong IP addresses in the DNS

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [October 15, 2022, 6:01pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/11 "2022-10-15T18:01:24Z")

</div>

Testing and debugging are best done using the **[Staging Environment](https://letsencrypt.org/docs/staging-environment/)** as the **[Rate Limits](https://letsencrypt.org/docs/rate-limits/)** are much higher. Rate Limits are per week (rolling).

And to assist with debugging there is a great place to start is [Let's Debug](https://letsdebug.net/).

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 6:07pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/12 "2022-10-15T18:07:23Z")

</div>

Thanks guys,

So I need to stop redirects then only will I be able to use letsencrypt ssl or other ssl?  
Any idea what could have been triggered this?  
How to fix it?

Many thanks

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [October 15, 2022, 6:12pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/13 "2022-10-15T18:12:25Z")

</div>

> [@maheshjain](#):
>
> So I need to stop redirects then only will I be able to use letsencrypt ssl or other ssl?  
> Any idea what could have been triggered this?  
> How to fix it?

I do not know if you need to stop redirects, but I would think that they should be HTTP Response of 301 instead of 302.

> **[HTTP 301](https://en.wikipedia.org/wiki/HTTP_301)**
>
> HTTP 301 is the HTTP response status code for 301 Moved Permanently. It is used for permanent redirecting, meaning that links or records returning this response should be updated. The new URL should be provided in the Location field, included with the response. The 301 redirect is considered a best practice for upgrading users from HTTP to HTTPS.
> RFC 2616 states that:
> Client request:
> Server response:

> **[301 Moved Permanently - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/301)**
>
> The HyperText Transfer Protocol (HTTP) 301 Moved Permanently redirect status response code indicates that the requested resource has been definitively moved to the URL given by the Location headers. A browser redirects to the new URL and search...

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 15, 2022, 6:13pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/14 "2022-10-15T18:13:57Z")

</div>

> [@maheshjain](#):
>
> So I need to stop redirects then only will I be able to use letsencrypt ssl or other ssl?

No. The first step is to fix your DNS records

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 6:19pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/15 "2022-10-15T18:19:33Z")

</div>

So I will change my DNS A record and www sub record to follow ip-

130.185.119.113

Many thanks

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 15, 2022, 6:25pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/16 "2022-10-15T18:25:25Z")

</div>

ok

I will do that first.

Thanks

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [October 15, 2022, 6:26pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/17 "2022-10-15T18:26:37Z")

</div>

@maheshjain please be aware that DNS has caching with a Time To Live (TTL) that is in the DNS SOA record, so your DNS A record change may not be instantaneously to the Internet.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 15, 2022, 7:16pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/18 "2022-10-15T19:16:42Z")

</div>

It looks like your DNS now points to your IIS Server.

You might want to try getting a Let's Encrypt cert. I see you got a cert from ZeroSSL about 6H ago. Although, your server is not using it and your https config in IIS seems faulty.

Since you are just starting and seem inexperienced, you might try using _Certify The Web_ instead of win-acme. It's a popular gui and may be easier to use. It is on the Let's Encrypt list ([here](https://letsencrypt.org/docs/client-options/#clients-windows-/-iis))

Nothing wrong with win-acme. Just giving you another option.

---

<div class="post-metadata">

**Author:** ![maheshjain](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@maheshjain](https://community.letsencrypt.org/u/maheshjain)\
**Post date:** [October 16, 2022, 5:22pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/19 "2022-10-16T17:22:14Z")

</div>

@mikeMcQ

Yes Its pointing to my IIS server now after I changed dns to my new webhosting dns.

Also lets encrypt ssl done now..

Issue left is when I browse "[sending-news.com](http://sending-news.com)" from local IIS or public internet my default webpage is not loading and just blank. But when I type Url like - "[sending-news.com/sending-news.com](http://sending-news.com/sending-news.com)" it loads the default page..I don't know why this new issue appeared.

Please any help would be appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 16, 2022, 5:36pm UTC](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143/20 "2022-10-16T17:36:46Z")

</div>

Glad to hear your certificate is working. I see it working too.

But, this is not a forum to help with general IIS configuration. There are many other sources for that info. google is good place to start

[Next page](https://community.letsencrypt.org/t/setting-up-certificates-error-403/186143.md?page=2)
