Unable to generate ssl certificates fro bitnami

#1

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: bigrockdirtpark.com

I ran this command: ./certbot-auto certonly --webroot -w /opt/bitnami/apps/wordpress/htdocs/ -d bigrockdirtpark.com
in /tmp/certbot

It produced this output: bitnami@ip-172-31-29-144:/tmp/certbot$ ./certbot-auto certonly --webroot -w /opt/bitnami/apps/wordpress/htdocs/ -d bigrockdirtpark.com
Requesting to rerun ./certbot-auto with root privileges…
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator webroot, Installer None
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for bigrockdirtpark.com
Using the webroot path /opt/bitnami/apps/wordpress/htdocs for all unmatched domains.
Waiting for verification…
Cleaning up challenges
Failed authorization procedure. bigrockdirtpark.com (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://bigrockdirtpark.com/.well-known/acme-challenge/J7Q5mI0BsdmNexpkP0ne8OR4b_FLJpPV2GFuW158D_U [18.219.171.196]: "\r\n<html xmlns=“http”

IMPORTANT NOTES:

My web server is (include version):

The operating system my web server runs on is (include version): Linux ip-172-31-29-144 4.4.0-1065-aws #75-Ubuntu SMP Fri Aug 10 11:14:32 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot):

#2

Hi @singamndevops

if webroot doesn’t work, please check your webroot.

Create the two required subdirectories

/opt/bitnami/apps/wordpress/htdocs/.well-known/acme-challenge

there a file (file name 1234) and try to load this file via

http://bigrockdirtpark.com/.well-known/acme-challenge/1234

Oh - perhaps this is completely wrong.

Checked your domain via https://check-your-website.server-daten.de/?q=bigrockdirtpark.com

Domainname Http-Status redirect Sec. G
http://bigrockdirtpark.com/
18.219.171.196 200 0.224 H
Content-Type: text/html
Last-Modified: Mon, 18 Feb 2019 22:44:16 GMT
Accept-Ranges: bytes
ETag: “0a0c7adbc7d41:0”
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Wed, 27 Feb 2019 10:40:37 GMT
Connection: close
Content-Length: 2508
http://www.bigrockdirtpark.com/
18.219.171.196 200 0.223 H
Content-Type: text/html
Last-Modified: Mon, 18 Feb 2019 22:44:16 GMT
Accept-Ranges: bytes
ETag: “0a0c7adbc7d41:0”
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Wed, 27 Feb 2019 10:40:37 GMT
Connection: close
Content-Length: 2508
https://bigrockdirtpark.com/
18.219.171.196 404 2.293 N
Not Found
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Wed, 27 Feb 2019 10:40:38 GMT
Connection: close
Content-Length: 315
https://www.bigrockdirtpark.com/
18.219.171.196 200 2.320 N
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Content-Type: text/html
Last-Modified: Mon, 18 Feb 2019 22:44:16 GMT
Accept-Ranges: bytes
ETag: “0a0c7adbc7d41:0”
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Wed, 27 Feb 2019 10:40:41 GMT
Connection: close
Content-Length: 2508
http://bigrockdirtpark.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
18.219.171.196 404 0.223 A
Not Found
Content-Type: text/html
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Wed, 27 Feb 2019 10:40:43 GMT
Connection: close
Content-Length: 1245
http://www.bigrockdirtpark.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
18.219.171.196 404 0.284 A
Not Found
Content-Type: text/html
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Wed, 27 Feb 2019 10:40:43 GMT
Connection: close
Content-Length: 1245

http is running with a Microsoft IIS, so you must use the webroot of that IIS.

And that IIS doesn’t have access to your linux-webroot.

closed #3

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.