Let's Encrypt stopped working

cbolt

Verified User
Joined
Feb 6, 2008
Messages
31
Wondering if I could get some advice on how to debug this please?
A few days ago all Let's Encrypt certificates stopped renewing/issuing on one of my servers, but ZeroSSL certificates are still renewing without issues.
The error looks like a network or firewall issue so I've tested disabling the firewall but that didn't help.
And I've checked that the server can connect out to acme-v02.api.letsencrypt.org over https and that works fine.
The server is under very little and load and is fast and responsive.
I have another da server on the same network/datacenter and Let's Encrypt still works fine there.

Example of error (domain and IP redacted):

2025/12/10 11:00:16 [INFO] [xyz.com] acme: Obtaining SAN certificate
2025/12/10 11:00:17 [INFO] [xyz.com] AuthURL: https://acme-v02.api.letsencrypt.org/acme/authz/123
2025/12/10 11:00:17 [INFO] [xyz.com] acme: Could not find solver for: tls-alpn-01
2025/12/10 11:00:17 [INFO] [xyz.com] acme: use http-01 solver
2025/12/10 11:00:17 [INFO] [xyz.com] acme: Trying to solve HTTP-01
2025/12/10 11:00:33 [INFO] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz/123
2025/12/10 11:00:33 Could not obtain certificates:
error: one or more domains had a problem:
[opencountry.draftsite.co.nz] invalid authorization: acme: error: 400 :: urn:ietf:params:acme:error:connection :: 123.123.123.123 Fetching https://xyz.com/.well-known/acme-challenge/xyz: Timeout after connect (your server may be slow or overloaded)
Failed to issue new certificate
 
is the domain behind cloudflare?
No not behind cloudflare or any other proxy. And it's not just one domain, all domains on this server that are using Let's Encrypt are affected. Domains using ZeroSSL are ok.
 
Back
Top