Dannik
Verified User
Let's Encrypt Invalid challenge and time out [SOLVED]
Hi,
I have been using Let's Encrypt for a while on several VPS's. Since a few days however I'm receiving errors the certifcates cannot be renewed. Both domain certificates as the server certficate. When I try to renew manual using DA, the script tells me something is wrong:
The strange thing is that when I check the Apache logs, it seems another URL is being called:
I deleted all banned entries in BruteBlock, so it cannot be Let's Encrypt servers are being blocked. I also checked out and succesfully tested the help for manually debugging https://help.directadmin.com/item.php?id=646, and this seems to be configured properly too:
I was running DA-version 1.51.3, until this morning, but then I updated to version 1.51.4, hoping this could solve the problem. Unfortunately it did not...data:image/s3,"s3://crabby-images/7a5e8/7a5e80f7b48c588b184c6616a76ba94b98cadc59" alt="Frown :( :("
I'm running letsencrypt=1, /var/www/html/.well-known/acme-challenge/ exists and is set as an alias in /etc/httpd/conf/extra/httpd-alias.conf. And as the testresult already showed eveything else seems to be configured well (should be, it worked well for more than a year!). No recent maintenance was done.
Who can help me out? Thanx!
Danny
Hi,
I have been using Let's Encrypt for a while on several VPS's. Since a few days however I'm receiving errors the certifcates cannot be renewed. Both domain certificates as the server certficate. When I try to renew manual using DA, the script tells me something is wrong:
Getting challenge for mydomain.tld from acme-server...
Waiting for domain verification...
Challenge is invalid. Details: Fetching http://mydomain.tld/.well-known/acme-challenge/gHmNnfVco0p4mYKzmygvCaN4t2xEIsZqdGiVPDvw8H4: Timeout. Exiting...
The strange thing is that when I check the Apache logs, it seems another URL is being called:
But it says status 200 and 206 (so that's ok). No further checks for the can be found in the logs.{my_own_ip} - - [27/Jun/2017:20:12:16 +0200] "GET /.well-known/acme-challenge/letsencrypt_1498587134 HTTP/1.1" 200 206 "-" "curl/7.50.1"
I deleted all banned entries in BruteBlock, so it cannot be Let's Encrypt servers are being blocked. I also checked out and succesfully tested the help for manually debugging https://help.directadmin.com/item.php?id=646, and this seems to be configured properly too:
[root@myserver]# /usr/local/bin/curl -I -L -k -X GET http://mydomain.tld/.well-known/acme-challenge/test.txt
HTTP/1.1 200 OK
Date: Tue, 27 Jun 2017 18:28:56 GMT
Server: Apache/2
Last-Modified: Tue, 27 Jun 2017 18:28:44 GMT
ETag: "5-552f53cccd45b"
Accept-Ranges: bytes
Content-Length: 5
Vary: User-Agent
Content-Type: text/plain
I was running DA-version 1.51.3, until this morning, but then I updated to version 1.51.4, hoping this could solve the problem. Unfortunately it did not...
data:image/s3,"s3://crabby-images/7a5e8/7a5e80f7b48c588b184c6616a76ba94b98cadc59" alt="Frown :( :("
I'm running letsencrypt=1, /var/www/html/.well-known/acme-challenge/ exists and is set as an alias in /etc/httpd/conf/extra/httpd-alias.conf. And as the testresult already showed eveything else seems to be configured well (should be, it worked well for more than a year!). No recent maintenance was done.
Who can help me out? Thanx!
Danny
Last edited: