acme: error: 400 :: urn:ietf:params:acme:error:connection - Let's Encrype

51660

New member
Joined
Aug 13, 2021
Messages
4
HI,
I am very new in this technology. I have installed Direct Admin to host our customer in my company and I had a problem when I try to renew the domain SSL.
In the past, I have never had any issue, but after I switched from nginx_apache to just apache, I cannot renew SSL certificate for most of my domain.

2022/07/12 18:55:48 [INFO] [www.domain.me] acme: Obtaining SAN certificate
2022/07/12 18:55:48 [INFO] [www.domain.me] AuthURL: https://acme-v02.api.letsencrypt.org/acme/authz-v3/129651302936
2022/07/12 18:55:48 [INFO] [www.domain.me] acme: Could not find solver for: tls-alpn-01
2022/07/12 18:55:48 [INFO] [www.domain.me] acme: use http-01 solver
2022/07/12 18:55:48 [INFO] [www.domain.me] acme: Trying to solve HTTP-01
2022/07/12 18:56:00 [INFO] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz-v3/129651302936
2022/07/12 18:56:00 Could not obtain certificates:
error: one or more domains had a problem:
[www.onlineorder.me] acme: error: 400 :: urn:ietf:params:acme:error:connection :: xxx.xxx.xxx.xxx : Fetching http://www.domain.me/.well-known/acme-challenge/zuax98SaHLYr_dKll7TbqO6yehPG4lUMcYwHZUw3RmE: Timeout during connect (likely firewall problem)
Certificate generation failed.

I can renew SSL for domain.me but not for www.domain.me ( I guest, it is subdomain). But I can do some domain, I can do. All domain hosted from the same registra and same DNS. I just don't know how come some can and some cannot. I try to unclick SSL from the domain and click to enable SSL and try but not successful. I don't have any firewall. I just don't know how to fix.. I am using Centos 7

If anyone can please help me.. I will be appreciated.. even I have to pay.. but the problem is.. I don't know who is the expert in Directadmin and cannot help. My support has already expired...

Please please.. help Thx
 
Try looking in the server logs.
What let’s encrypt is saying is: 400 due to timeout. (meaning the server took too long to respond.)
And it is suggesting to look at the firewall but unless you run it from a nat I would not expect it to be a firewall issue.
 
Back
Top