Root logging level set at 0 Saving debug log to /var/log/letsencrypt/letsencrypt.log Notifying user: Processing /etc/letsencrypt/renewal/ipv4-www.gollum.at.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/ipv4-www.gollum.at.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Requested authenticator and installer Starting new HTTP connection (1): r3.o.lencr.org:80 http://r3.o.lencr.org:80 "POST / HTTP/1.1" 200 503 OCSP response for certificate /etc/letsencrypt/archive/gollum.at/cert3.pem is signed by the certificate's issuer. OCSP certificate status for /etc/letsencrypt/archive/gollum.at/cert3.pem is: OCSPCertStatus.GOOD Should renew, less than 30 days before certificate expiry 2022-11-01 15:00:59 UTC. Certificate is due for renewal, auto-renewing... Requested authenticator apache and installer apache Apache version is 2.4.41 Single candidate plugin: * apache Description: Apache Web Server plugin Interfaces: Installer, Authenticator, Plugin Entry point: apache = certbot_apache._internal.entrypoint:ENTRYPOINT Initialized: Prep: True Single candidate plugin: * apache Description: Apache Web Server plugin Interfaces: Installer, Authenticator, Plugin Entry point: apache = certbot_apache._internal.entrypoint:ENTRYPOINT Initialized: Prep: True Selected authenticator and installer Plugins selected: Authenticator apache, Installer apache Picked account: ), creation_host='zeus-rs.gollum.at', register_to_eff=None))> Sending GET request to https://acme-v02.api.letsencrypt.org/directory. Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443 https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 659 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:37 GMT Content-Type: application/json Content-Length: 659 Connection: keep-alive Cache-Control: public, max-age=0, no-cache X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "8YPgRvrhxxs": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417", "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change", "meta": { "caaIdentities": [ "letsencrypt.org" ], "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.3-September-21-2022.pdf", "website": "https://letsencrypt.org" }, "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct", "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce", "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order", "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert" } Notifying user: Renewing an existing certificate for gollum.at and 4 more domains Renewing an existing certificate for gollum.at and 4 more domains Generating RSA key (2048 bits): /etc/letsencrypt/keys/0058_key-certbot.pem Creating CSR: /etc/letsencrypt/csr/0058_csr-certbot.pem Requesting fresh nonce Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce. https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:38 GMT Connection: keep-alive Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: C400BvPL_SmXdX43Ny0stMmnhmGW9ko6nn9WCYeHhouzHCU X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 Storing nonce: C400BvPL_SmXdX43Ny0stMmnhmGW9ko6nn9WCYeHhouzHCU JWS payload: b'{\n "identifiers": [\n {\n "type": "dns",\n "value": "gollum.at"\n },\n {\n "type": "dns",\n "value": "ipv4-www.gollum.at"\n },\n {\n "type": "dns",\n "value": "ipv6-www.gollum.at"\n },\n {\n "type": "dns",\n "value": "oc.gollum.at"\n },\n {\n "type": "dns",\n "value": "www.gollum.at"\n }\n ]\n}' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkM0MDBCdlBMX1NtWGRYNDNOeTBzdE1tbmhtR1c5a282bm45V0NZZUhob3V6SENVIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9uZXctb3JkZXIifQ", "signature": "VShY7MbelDiVAHzTFD2TaibIui8B6lzorWgIKLl84Duwb36onRCq2M-S_CtWG4GtbVjsGLMCn3Ju_kcfhvtAC88dxZS2YZ4TPw4Xg2_4KFKVeYGZLKEGFM1BzW1FubI2ktThblE4tn7jRAxUvTMiWEeAOm8yS_oeTArhLArw9IWJRGZW4Pqa9-tUjwKYo8G5C_dwcK2Lc4T5Pm6pgq31d6TbKzjo4Kj9jpw1Dy0YOkheH1Cl3qQaVrExsYJ4nLNlKe7rof_MphB3TrP_WdRIEDmDLwNXO1R_XZ1Neaf_LSjoS5yzry0nj_qVg4T308h3XNVQkPNRyAowJnfnzlEufg", "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogImdvbGx1bS5hdCIKICAgIH0sCiAgICB7CiAgICAgICJ0eXBlIjogImRucyIsCiAgICAgICJ2YWx1ZSI6ICJpcHY0LXd3dy5nb2xsdW0uYXQiCiAgICB9LAogICAgewogICAgICAidHlwZSI6ICJkbnMiLAogICAgICAidmFsdWUiOiAiaXB2Ni13d3cuZ29sbHVtLmF0IgogICAgfSwKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm9jLmdvbGx1bS5hdCIKICAgIH0sCiAgICB7CiAgICAgICJ0eXBlIjogImRucyIsCiAgICAgICJ2YWx1ZSI6ICJ3d3cuZ29sbHVtLmF0IgogICAgfQogIF0KfQ" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 887 Received response: HTTP 201 Server: nginx Date: Mon, 17 Oct 2022 17:06:39 GMT Content-Type: application/json Content-Length: 887 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Location: https://acme-v02.api.letsencrypt.org/acme/order/647427596/135451983466 Replay-Nonce: A5FEYPmt1bDmBoiJV-Ty9wXq9fobFQrtj9qsfRqv9dFJFJ0 X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "status": "pending", "expires": "2022-10-24T17:06:39Z", "identifiers": [ { "type": "dns", "value": "gollum.at" }, { "type": "dns", "value": "ipv4-www.gollum.at" }, { "type": "dns", "value": "ipv6-www.gollum.at" }, { "type": "dns", "value": "oc.gollum.at" }, { "type": "dns", "value": "www.gollum.at" } ], "authorizations": [ "https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676066", "https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676086", "https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676096", "https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676106", "https://acme-v02.api.letsencrypt.org/acme/authz-v3/165639467896" ], "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/647427596/135451983466" } Storing nonce: A5FEYPmt1bDmBoiJV-Ty9wXq9fobFQrtj9qsfRqv9dFJFJ0 JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676066: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkE1RkVZUG10MWJEbUJvaUpWLVR5OXdYcTlmb2JGUXJ0ajlxc2ZScXY5ZEZKRkowIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYwNjYifQ", "signature": "yS8ig_r6X6n0oh9dG9K1Pz0sBoCALX4evkD6aEhho-LqKm6gqsnbPytElI-gkMWp9J88Vbn3Lqz3ZA6_cFK2jB5FnxuDqn5HBNwQoynVZ9MCZEXFgXE8nb-dYDUENCKwECMbBox3ewpfjFg8YMwy-wBjGPfsyEc0v79IYKkLnFD-yFdrCE1TrZ_28N3sVRzS_cj5gZiBWGJPL4mxTiY3nzOtqAQQ-MrOw7NKz2yEkwTzdIUxqT8rWh1OJBj34JlvFTuwiqKvg4qE3MAsvT2qdXQQb8a9SgiM8PhdLMyVZbN_JKb1euejyWFLHdQK_XsuvHnVkdz0Udd2gYKpZRBYjA", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676066 HTTP/1.1" 200 780 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:39 GMT Content-Type: application/json Content-Length: 780 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: A5FEPWVIjuYCYl5a2KS-zREmSPQxMtLoulcVZuAH5G57Y6M X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:04Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676066/IdDC0w", "token": "-BQQoX6RVcShbWGcYk1tqIH_sF_muUWKWSBy8pfgN60", "validationRecord": [ { "url": "http://gollum.at/.well-known/acme-challenge/-BQQoX6RVcShbWGcYk1tqIH_sF_muUWKWSBy8pfgN60", "hostname": "gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85", "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:03Z" } ] } Storing nonce: A5FEPWVIjuYCYl5a2KS-zREmSPQxMtLoulcVZuAH5G57Y6M JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676086: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkE1RkVQV1ZJanVZQ1lsNWEyS1MtelJFbVNQUXhNdExvdWxjVlp1QUg1RzU3WTZNIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYwODYifQ", "signature": "1CYkwZ5pR58LeK6pt1VMTTi05uVrHioNkbduo52dfs8IY8Mqsp8fxw9HwustPhXD4V8BVXUlYAMjCRjqILyRBfb53lcCGBIU4-o_tZrOngrnCYN2J0jO66ph9m12Uf-pA7Ukgs2EbZRKtE5HiiVnt7BmEJU4Rnw0M-9SV1JT4ZZLIh14-k5ZO6UHzy_kWikPaWbx8PPIFeQb9jPKqy0v4jL7C7RZYoq2HoKPyVaMRPL8T9E0fZQUIX6LtS63iZa2wWSXakTULbEIdiX4P0nFVnG95FiWVHhailMtvI9XHi4MAPzTb8GekIqHLfhOFSHDWvRDm_eka9XsxKRDidRvSQ", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676086 HTTP/1.1" 200 779 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:39 GMT Content-Type: application/json Content-Length: 779 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: 2712UBPvh4QysXMtZW_Ddvlcla6MJ6k7IiT8wrzJxhJdbGo X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "ipv6-www.gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:05Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676086/l2p50w", "token": "IyzTrp16KjIDGgupBleKtZI36aqRysxdRFt2rSM0N0U", "validationRecord": [ { "url": "http://ipv6-www.gollum.at/.well-known/acme-challenge/IyzTrp16KjIDGgupBleKtZI36aqRysxdRFt2rSM0N0U", "hostname": "ipv6-www.gollum.at", "port": "80", "addressesResolved": [ "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:03Z" } ] } Storing nonce: 2712UBPvh4QysXMtZW_Ddvlcla6MJ6k7IiT8wrzJxhJdbGo JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676096: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIjI3MTJVQlB2aDRReXNYTXRaV19EZHZsY2xhNk1KNms3SWlUOHdyekp4aEpkYkdvIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYwOTYifQ", "signature": "musJf-HVttH7c6eB88CFkIF3uBIuWzbAmnAICRe-u1iBaPUdoMRhp1HhnV0n__fspiClMtiO6KRfL9P-fvw-CMrEyrPH1e0QBJit3HzEGLl3zMQZ4jTkkSleDpeJsnYNDvXVXISFLUbX-uWvmc55m7vN_aWVDEIKJ4S5jl5w5ozTFkj8sgIbj75O2HfkItbu8YReuOj5TFoYjm2t6CU1oXOZw2I9LfnvCBkwacxVeLsQmrAjzzMYUVN31K8S3fyaRfP1_36o5KrGoyMEor0NCiC9_HvaMBbNk1-Um0MsxNouSGJMwsx3YBUwuoJJUinlwmmVfX_HSUZQRIpyic6Y0A", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676096 HTTP/1.1" 200 789 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:39 GMT Content-Type: application/json Content-Length: 789 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: 2712kj8ZXCUTphaTe-5je_jrwwJJq485FEY2X7i5b9L-PJo X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "oc.gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:04Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676096/sqei9g", "token": "1PJkd3wOon2d2Am4XcSknWsiVV8LQ5HG1Jwe9oLAqV4", "validationRecord": [ { "url": "http://oc.gollum.at/.well-known/acme-challenge/1PJkd3wOon2d2Am4XcSknWsiVV8LQ5HG1Jwe9oLAqV4", "hostname": "oc.gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85", "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:04Z" } ] } Storing nonce: 2712kj8ZXCUTphaTe-5je_jrwwJJq485FEY2X7i5b9L-PJo JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676106: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIjI3MTJrajhaWENVVHBoYVRlLTVqZV9qcnd3SkpxNDg1RkVZMlg3aTViOUwtUEpvIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYxMDYifQ", "signature": "Y0YoXMy0sMsxLF0LFyS1vykwHCLrNnCYN9NRNv8GLbDEyAB2kiddZF_e3bqgsDqJ8Hvfv1kfXBnbc6-OCVmoNQyBpdiR5WLq50XiY5uHjte85RODzXJJP4YXh3sItahb3mi2-iH_naG1QNv4XdnOjHGDeHvpk_bK5C7LY5pmDzboT1LZNzpjGh_C6Erne07yOmZ3FMh8lURXZCzGWL5qqPtRvxop3jHqGfH477VQYwj2jpYHJUjaq6gcqGw0St63AOqHz8O_32kYvlP82keVX_RT6ZBMnHLCpbP75fNUPCg5gnlITxtUBp47pAnpRLm3RI9GyqQGMygcTznBhTOkmg", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676106 HTTP/1.1" 200 792 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:39 GMT Content-Type: application/json Content-Length: 792 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: 2712c_VbuHJJAlZmKggqaZ8HPuovNCmXi710iDQRI6XCjiM X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "www.gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:05Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676106/zr-XpA", "token": "h7PO38khggSEzWVbfRdfGHXIt-ZFACDpWNba6iDwEn4", "validationRecord": [ { "url": "http://www.gollum.at/.well-known/acme-challenge/h7PO38khggSEzWVbfRdfGHXIt-ZFACDpWNba6iDwEn4", "hostname": "www.gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85", "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:04Z" } ] } Storing nonce: 2712c_VbuHJJAlZmKggqaZ8HPuovNCmXi710iDQRI6XCjiM JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/165639467896: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIjI3MTJjX1ZidUhKSkFsWm1LZ2dxYVo4SFB1b3ZOQ21YaTcxMGlEUVJJNlhDamlNIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjU2Mzk0Njc4OTYifQ", "signature": "vHxQxpZfHifdruDC2j37IqiO1GT2AkxVquE27JLdAuct-W2oBrkHBXHFavS8Wj05FhtFiaUFXppufvs1UTkOnjND2gNaIs2N6kPhJrCyyvpQWrfUlK3Z7DVEGwK7SGT41cJKGw04LJtjGTAi3h52z86IVHaWfBRobjRaZEB6meNL2LZHxraKIiOygqeJqzBfTUrLh4v0J5_jhF2VTxMu5j14eV7mnojkXJsi9GtoEqmyO3DCpIW5tyCoM_ojD2w0LKBU0bCCLNxuZo6j6QOonMwyERyxMCSowif_7DUaeZXfYOmKWwwW710XvL45Pz3iFHmwoum7dpEZyZQl2eeclA", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/165639467896 HTTP/1.1" 200 802 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:40 GMT Content-Type: application/json Content-Length: 802 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: A5FEJK7WwRJ677GTLpwlLK_Wc45avmKTHhF3BykiY9MFVqk X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "ipv4-www.gollum.at" }, "status": "pending", "expires": "2022-10-24T17:06:39Z", "challenges": [ { "type": "http-01", "status": "pending", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/1GoOIQ", "token": "4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE" }, { "type": "dns-01", "status": "pending", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/Tsrjyg", "token": "4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE" }, { "type": "tls-alpn-01", "status": "pending", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/kj3jyw", "token": "4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE" } ] } Storing nonce: A5FEJK7WwRJ677GTLpwlLK_Wc45avmKTHhF3BykiY9MFVqk Performing the following challenges: http-01 challenge for ipv4-www.gollum.at Adding a temporary challenge validation Include for name: gollum.at in: /etc/apache2/sites-enabled/gollum.at-ssl.conf Adding a temporary challenge validation Include for name: gollum.at in: /etc/apache2/sites-enabled/gollum.at.conf writing a pre config file with text: RewriteEngine on RewriteRule ^/\.well-known/acme-challenge/([A-Za-z0-9-_=]+)$ /var/lib/letsencrypt/http_challenges/$1 [END] writing a post config file with text: Require all granted Require all granted Creating backup of /etc/apache2/sites-enabled/gollum.at-ssl.conf Creating backup of /etc/apache2/sites-enabled/gollum.at.conf JWS payload: b'{}' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/1GoOIQ: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkE1RkVKSzdXd1JKNjc3R1RMcHdsTEtfV2M0NWF2bUtUSGhGM0J5a2lZOU1GVnFrIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9jaGFsbC12My8xNjU2Mzk0Njc4OTYvMUdvT0lRIn0", "signature": "J2AHGrjDdXuhqekIxUSp01vwL3mpQojwPfdEAd5ZNsCTY7DNLJpWAxxri8TAA5EJenizjKwmY_54DxmL-lASEasIN-Q6lVh3M9Zdf-HQAGfKK7oGMpEblV4xDBbznb2HY0M_CLexgwSkPD5ZYNgjDn3b75DP5A064UUZSMcM4RVDrKVz-rumP6nEUWxMpvj4XXD3JTXnKxDj2_shYqFGLugcg52nSGaVoxPRw83uGdlDf-sMJwkKXV0yRcweNhHFqowyhgazpaS8NiNH2hv7qTmH8XyyUk3xJw1_xQGM5LjK-AUr8m-oSdT5QXR2ykndxvDlltHshfeiXYEbDxzU1A", "payload": "e30" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall-v3/165639467896/1GoOIQ HTTP/1.1" 200 187 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:43 GMT Content-Type: application/json Content-Length: 187 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index", ;rel="up" Location: https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/1GoOIQ Replay-Nonce: C400g8-1j93tcxrw0UlGTB0WUb3oY6puVAVGTvf3iZiwYBg X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "type": "http-01", "status": "pending", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/1GoOIQ", "token": "4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE" } Storing nonce: C400g8-1j93tcxrw0UlGTB0WUb3oY6puVAVGTvf3iZiwYBg Waiting for verification... JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676066: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkM0MDBnOC0xajkzdGN4cncwVWxHVEIwV1ViM29ZNnB1VkFWR1R2ZjNpWml3WUJnIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYwNjYifQ", "signature": "B5hdLU81TYVFeGFCbXm_DkIeL3_8mzb1bRq8Sppd4-TexfDr7F8ZY-CP0NYuRSpu4tIAlJJ-Hx-_njYezYMXn9J7APSGwjRxaQwv4FQW8LZXkDHcvUpeHunhFbSPxNt--wgNMWfJGF94SKY61ukQ-8yJtMAFsshDuOlgoEjDegGNNVobXJeptvdgxCiq3J7260hAPZ1LBcYcxKD45Xjrnh3z5IKlPY27jrSOMfmpQ6J2K3UdeC3mBE7Y3_kyStCFB9y6Hs44MPH8ShdgV51zObab4mvnymaWRHJpYXHTe1jzp-BXrg4JhAYP2dvlGHA_4b1Wdaj0z1Ka78qmbjsgSQ", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676066 HTTP/1.1" 200 780 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:44 GMT Content-Type: application/json Content-Length: 780 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: 2712ZPl5Bc2nnLZUqI-tBZB0oYfZkRB5fyKoUcm0mWEiWHA X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:04Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676066/IdDC0w", "token": "-BQQoX6RVcShbWGcYk1tqIH_sF_muUWKWSBy8pfgN60", "validationRecord": [ { "url": "http://gollum.at/.well-known/acme-challenge/-BQQoX6RVcShbWGcYk1tqIH_sF_muUWKWSBy8pfgN60", "hostname": "gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85", "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:03Z" } ] } Storing nonce: 2712ZPl5Bc2nnLZUqI-tBZB0oYfZkRB5fyKoUcm0mWEiWHA JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676086: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIjI3MTJaUGw1QmMybm5MWlVxSS10QlpCMG9ZZlprUkI1ZnlLb1VjbTBtV0VpV0hBIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYwODYifQ", "signature": "Gf1jhslHh3atkznh1i061ez-A28LwGeMcoYB4hzYgipa02faWlYHvLc9qWzzazMGWWDhVTFrxYyJ4ykWumc-dGPy6Q3PANj5LbScu3harsXlccjO9VsVO-zpFKetCpiVCCjx4fddcufLTBB1eF6H4mbzb9abOsVpsFLbzN-wmwMCGHj6ZQyUP6cFN4dItAt5YnuVMsmGFc1dhKrG7jmkXwQhEEkSaqLZHzGnf6EVdES6IzqVZzpF_X8w-5FdzWEdgd1YiuSpy3lnc3rEGRLMRSl_gUHwmIO_YwtSTPU0KQlVi45R8neFUenW6G5DN26rdQ6UfMqXWS4Atqx7PV1esw", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676086 HTTP/1.1" 200 779 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:45 GMT Content-Type: application/json Content-Length: 779 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: A5FEZ7T13ssmxTrleSJWXCGPfjMLQSrffZ3u0F_r3VAoSHw X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "ipv6-www.gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:05Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676086/l2p50w", "token": "IyzTrp16KjIDGgupBleKtZI36aqRysxdRFt2rSM0N0U", "validationRecord": [ { "url": "http://ipv6-www.gollum.at/.well-known/acme-challenge/IyzTrp16KjIDGgupBleKtZI36aqRysxdRFt2rSM0N0U", "hostname": "ipv6-www.gollum.at", "port": "80", "addressesResolved": [ "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:03Z" } ] } Storing nonce: A5FEZ7T13ssmxTrleSJWXCGPfjMLQSrffZ3u0F_r3VAoSHw JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676096: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkE1RkVaN1QxM3NzbXhUcmxlU0pXWENHUGZqTUxRU3JmZlozdTBGX3IzVkFvU0h3IiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYwOTYifQ", "signature": "9d6I8nzaQPPthec_O5bzljtWZEKrU4MJ1Z2BE21XHAomdga0sFYY48gFohZPk7DRXS0W45CHDmu6rEJ1kny7blAvXr0YSxDlTQqH8ZrENesT6xqdsAuGJS03IEnb_le7MmLJl4KQRLcd0n06RCG4mwA7mP2cC0kc0Q87yS8eIpJzEevpjttEe06F2tb-CFabq5iK0l0ekOFglngITxMSSZzK5k3pqx_HKyDcuLpKdiDc_T8A2NzazsS4tb3Zyq6nbu_Gb9k3a3C2oae28e7euLh4sgBJrigs3pN5AeozwVcTo1WtvjnCslaPAHv0TsJFAsyjPRokSfUyl9gTwk9BnQ", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676096 HTTP/1.1" 200 789 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:45 GMT Content-Type: application/json Content-Length: 789 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: C400F27uLcfUsgTiVoJqkQphlBdpXixx61OR3F2q24d2Rto X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "oc.gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:04Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676096/sqei9g", "token": "1PJkd3wOon2d2Am4XcSknWsiVV8LQ5HG1Jwe9oLAqV4", "validationRecord": [ { "url": "http://oc.gollum.at/.well-known/acme-challenge/1PJkd3wOon2d2Am4XcSknWsiVV8LQ5HG1Jwe9oLAqV4", "hostname": "oc.gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85", "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:04Z" } ] } Storing nonce: C400F27uLcfUsgTiVoJqkQphlBdpXixx61OR3F2q24d2Rto JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/160248676106: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIkM0MDBGMjd1TGNmVXNnVGlWb0pxa1FwaGxCZHBYaXh4NjFPUjNGMnEyNGQyUnRvIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjAyNDg2NzYxMDYifQ", "signature": "1u-Tn71JI-JeS3TpIjH6ilvFpXLpGhcPgH0G1xNekh-tydJLIC15avNurqwJbCk_l3HRQf6Gd4hRFq6SdWSCTNIV9JxyyEBdwEAQ4Xkeo1t0udccg_V_Cy68_FzdQPhJNa_YMbzKfsEMzJgEUhtEqsx6kwE5-2MCqLj6H-NLmt_VJmr-YLoelOQXCHNVf87TO2Q8fznAXyM7nzFkTkyImkOP6YErSyqvlKOtiYxdx2ySU-w0O-hnM1PrB0A4rmKc1FFH0XaTMthy1lwTIdPf1wl0xdut45M1pxxqt1FJQarYaR-ppYjkn1DozHojSQTVPIiijt_1iO774dppDopcVA", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/160248676106 HTTP/1.1" 200 792 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:45 GMT Content-Type: application/json Content-Length: 792 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: 2712mSfIt9X4za7isuW1oJGmz1kSb7EcZIS3-ZahDtRitRY X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "www.gollum.at" }, "status": "valid", "expires": "2022-11-02T05:00:05Z", "challenges": [ { "type": "http-01", "status": "valid", "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/160248676106/zr-XpA", "token": "h7PO38khggSEzWVbfRdfGHXIt-ZFACDpWNba6iDwEn4", "validationRecord": [ { "url": "http://www.gollum.at/.well-known/acme-challenge/h7PO38khggSEzWVbfRdfGHXIt-ZFACDpWNba6iDwEn4", "hostname": "www.gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85", "2001:470:6cb8:2::2" ], "addressUsed": "2001:470:6cb8:2::2" } ], "validated": "2022-10-03T05:00:04Z" } ] } Storing nonce: 2712mSfIt9X4za7isuW1oJGmz1kSb7EcZIS3-ZahDtRitRY JWS payload: b'' Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz-v3/165639467896: { "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvNjQ3NDI3NTk2IiwgIm5vbmNlIjogIjI3MTJtU2ZJdDlYNHphN2lzdVcxb0pHbXoxa1NiN0VjWklTMy1aYWhEdFJpdFJZIiwgInVybCI6ICJodHRwczovL2FjbWUtdjAyLmFwaS5sZXRzZW5jcnlwdC5vcmcvYWNtZS9hdXRoei12My8xNjU2Mzk0Njc4OTYifQ", "signature": "poi2QbqORNYnYQPl4-r505iiHKPmsCVsEkEOLnIqvNuSXrEcmXLRHYV7g3wYsMFtOznEs7o7s1ARVaC_hmQeNE-6ly_QaKPS7EmOqNefY0qGwBcPmTvMxf4OEIddEnBnEQaEKYBIqZvjtcqlQvHy9nOEWyF-dAByTfLdd_q9pz9Jit-d0wpdC7bka83JXMW7mPnEXWSk4aAKSsOGNwlpRGBHiP6EVgI57s-MIk5oIK3BCXVBEVOC4HYLKTw6bEep0rFe-RkMYLmHZetHKrej6QQN_g88TajmzqEReE5558jo3-7EQxm3lJ58dnHY_VSkoIxqsygxqWsa9tM9oh2aDw", "payload": "" } https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz-v3/165639467896 HTTP/1.1" 200 1037 Received response: HTTP 200 Server: nginx Date: Mon, 17 Oct 2022 17:06:45 GMT Content-Type: application/json Content-Length: 1037 Connection: keep-alive Boulder-Requester: 647427596 Cache-Control: public, max-age=0, no-cache Link: ;rel="index" Replay-Nonce: F977uk9pbBD8PNk6Xk-Z7NztL2Mk7aEUEX0yPPyLvQpiGR4 X-Frame-Options: DENY Strict-Transport-Security: max-age=604800 { "identifier": { "type": "dns", "value": "ipv4-www.gollum.at" }, "status": "invalid", "expires": "2022-10-24T17:06:39Z", "challenges": [ { "type": "http-01", "status": "invalid", "error": { "type": "urn:ietf:params:acme:error:connection", "detail": "80.64.140.85: Fetching http://ipv4-www.gollum.at/.well-known/acme-challenge/4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE: Connection refused", "status": 400 }, "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/165639467896/1GoOIQ", "token": "4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE", "validationRecord": [ { "url": "http://ipv4-www.gollum.at/.well-known/acme-challenge/4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE", "hostname": "ipv4-www.gollum.at", "port": "80", "addressesResolved": [ "80.64.140.85" ], "addressUsed": "80.64.140.85" } ], "validated": "2022-10-17T17:06:43Z" } ] } Storing nonce: F977uk9pbBD8PNk6Xk-Z7NztL2Mk7aEUEX0yPPyLvQpiGR4 Challenge failed for domain ipv4-www.gollum.at http-01 challenge for ipv4-www.gollum.at Notifying user: Certbot failed to authenticate some domains (authenticator: apache). The Certificate Authority reported these problems: Domain: ipv4-www.gollum.at Type: connection Detail: 80.64.140.85: Fetching http://ipv4-www.gollum.at/.well-known/acme-challenge/4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE: Connection refused Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet. Certbot failed to authenticate some domains (authenticator: apache). The Certificate Authority reported these problems: Domain: ipv4-www.gollum.at Type: connection Detail: 80.64.140.85: Fetching http://ipv4-www.gollum.at/.well-known/acme-challenge/4BythktYEtfZw7TdbGhkbqpOpupKAZg_zyeQszoqlJE: Connection refused Hint: The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot. Ensure that the listed domains point to this Apache server and that it is accessible from the internet. Encountered exception: Traceback (most recent call last): File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/auth_handler.py", line 106, in handle_authorizations self._poll_authorizations(authzrs, max_retries, best_effort) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/auth_handler.py", line 206, in _poll_authorizations raise errors.AuthorizationError('Some challenges have failed.') certbot.errors.AuthorizationError: Some challenges have failed. Calling registered functions Cleaning up challenges Failed to renew certificate ipv4-www.gollum.at with error: Some challenges have failed. Traceback was: Traceback (most recent call last): File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/renewal.py", line 484, in handle_renewal_request main.renew_cert(lineage_config, plugins, renewal_candidate) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/main.py", line 1541, in renew_cert renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/main.py", line 129, in _get_and_save_cert renewal.renew_cert(config, domains, le_client, lineage) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/renewal.py", line 344, in renew_cert new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/client.py", line 442, in obtain_certificate orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/client.py", line 510, in _get_order_and_authorizations authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/auth_handler.py", line 106, in handle_authorizations self._poll_authorizations(authzrs, max_retries, best_effort) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/auth_handler.py", line 206, in _poll_authorizations raise errors.AuthorizationError('Some challenges have failed.') certbot.errors.AuthorizationError: Some challenges have failed. Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - All renewals failed. The following certificates could not be renewed: /etc/letsencrypt/live/gollum.at/fullchain.pem (failure) Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Exiting abnormally: Traceback (most recent call last): File "/snap/certbot/2414/bin/certbot", line 8, in sys.exit(main()) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/main.py", line 19, in main return internal_main.main(cli_args) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/main.py", line 1744, in main return config.func(config, plugins) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/main.py", line 1630, in renew renewal.handle_renewal_request(config) File "/snap/certbot/2414/lib/python3.8/site-packages/certbot/_internal/renewal.py", line 510, in handle_renewal_request raise errors.Error( certbot.errors.Error: 1 renew failure(s), 0 parse failure(s) 1 renew failure(s), 0 parse failure(s) Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.