Winacme ssl renewal fails with 'Authentication failed' behind cloudflare

We are behind Clodflare and when we set the record to ‘Proxied’ mode, lets encrypt SSL renewal fails with the error of ‘Authentication failed’ but if we change it to ‘DNS’ it renews the certificate without any issues. We need to have this record as ‘proxied’ in cloudflare. how can we get certificate renewed while in ‘Proxied’ mode

My domain is:

I ran this command: wacs.exe --renew --baseuri “

It produced this output: Authentication failed

My web server is (include version):windows server

The operating system my web server runs on is (include version): windows , IIS

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):NA

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):win-acme (wacs.exe)

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot):win-acme.v2.1.2.641.x64.pluggable

Hi @ffletsencrypt

what’s that “proxied mode”? That? See

There are redirects http -> https. That’s ok, Letsencrypt follows these redirects.

But then there is a wrong redirect:

Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0	302
Html is minified: 102,96 %	

To /Login.aspx, that can’t work, there isn’t your validation file.

So it’s not a Cloudflare-problem, it’s a problem of your website.

Remove that redirect if the path starts with /.well-known/acme-challenge.

