Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: bstpoc.serviceconnect.defence.gov.au
I ran this command: C:\Windows\system32>certbot certonly --webroot and then C:\Program Files\Apache\Tomcat 9.0\webapps\ROOT
It produced this output:
C:\Windows\system32>certbot certonly --webroot
Saving debug log to C:\Certbot\log\letsencrypt.log
Please enter the domain name(s) you would like on your certificate (comma and/or
space separated) (Enter 'c' to cancel): bstpoc.serviceconnect.defence.gov.au
Requesting a certificate for bstpoc.serviceconnect.defence.gov.au
Input the webroot for bstpoc.serviceconnect.defence.gov.au: (Enter 'c' to
cancel): C:\Program Files\Apache\Tomcat 9.0\webapps\ROOT
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: Domain: bstpoc.serviceconnect.defence.gov.au
Type: unauthorized
Detail: 20.70.4.114: Invalid response from http://bstpoc.serviceconnect.defence.gov.au/.well-known/acme-challenge/xFVql5iB-O9Lq0GMQgtTmGkqIiLAoa5UoDjB3rOsLas: 502
Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile C:\Certbot\log\letsencrypt.log or re-run Certbot with -v for more details.
My web server is (include version): Apache Tomcat 9.0
The operating system my web server runs on is (include version): Windows Server 2019
My hosting provider, if applicable, is: defence.gov.au
I can login to a root shell on my machine (yes or no, or I don't know): Not a Linux machine
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): 2.6.0

