# Wildcard request: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA

**URL:** <https://community.letsencrypt.org/t/wildcard-request-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/57199>\
**Category:** Help\
**Created:** [March 20, 2018, 10:28pm UTC](https://community.letsencrypt.org/t/wildcard-request-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/57199 "2018-03-20T22:28:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [March 20, 2018, 10:43pm UTC](https://community.letsencrypt.org/t/wildcard-request-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/57199/2 "2018-03-20T22:43:42Z")

</div>

> [@Solution: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA](https://community.letsencrypt.org/t/solution-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/49983/94):
>
> What is HTTP-01?

The method by which your server proves control to the CA that it controls `power-forums.com`. Previously Certbot used a different method, TLS-SNI-01, which was later disabled, so now you are left with either HTTP-01 or DNS-01.

> [@Solution: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA](https://community.letsencrypt.org/t/solution-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/49983/94):
>
> What am I supposed to do

As written in the post, update your Certbot to a newer version, and it should automatically deal with renewal.

> [@dalu](#):
>
> certbot certonly --server [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory) -d \*.power-forums.com -w /var/www/acme/

That's not going to work, because wildcards are only available by DNS-01 (which requires automatically or manually adding TXT records to your domain's DNS).

Are you sure you need a wildcard? Based on your [previous certificates](https://crt.sh/?q=%25power-forums.com), it wouldn't seem that way.

If you only need `[power-forums.com www.power-forums.com]`, perhaps you can try:

```
certbot certonly --preferred-challenges http -d www.power-forums.com -d power-forums.com -w /var/www/acme/

```

---

_[View the full topic](https://community.letsencrypt.org/t/wildcard-request-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/57199)._
