[Thu Aug 23 11:16:38 CEST 2018] original='{ "type": "http-01", "status": "invalid", "error": { "type": "urn:acme:error:connection", "detail": "Fetching http://sub.example.com/.well-known/acme-challenge/FH6K-FkTi402Yxnz4GgGH2QmgQ04ZZ7KGlbWbJ3_vIg: Timeout during connect (likely firewall problem)", "status": 400 }, "uri": "https://acme-staging.api.letsencrypt.org/acme/challenge/KIcdLYd-AGixisDwtryje-eCEjmXPl59j1A2Wj14Nho/162774506", "token": "FH6K-FkTi402Yxnz4GgGH2QmgQ04ZZ7KGlbWbJ3_vIg", "keyAuthorization": "FH6K-FkTi402Yxnz4GgGH2QmgQ04ZZ7KGlbWbJ3_vIg.Dw8O-XYchKlLNiCK7AvuJE-v2gfYOVv9uF1tfsKz2to", "validationRecord": [ { "url": "http://sub.example.com/.well-known/acme-challenge/FH6K-FkTi402Yxnz4GgGH2QmgQ04ZZ7KGlbWbJ3_vIg", "hostname": "sub.example.com", "port": "80", "addressesResolved": [ "X.X.X.X" ], "addressUsed": "X.X.X.X" } ]}'
[Thu Aug 23 11:16:39 CEST 2018] original='{ "type": "urn:acme:error:malformed", "detail": "Unable to update challenge :: The challenge is not pending.", "status": 400}'
[Thu Aug 23 11:16:46 CEST 2018] Diagnosis versions:openssl:opensslOpenSSL 1.0.2k-freebsd 26 Jan 2017apache:apache doesn't exists.nginx:nginx doesn't exists.socat:[...]
[Fri Aug 24 10:15:03 CEST 2018] original='{ "type": "http-01", "status": "invalid", "error": { "type": "urn:acme:error:unauthorized", "detail": "Invalid response from http://sub.example.com/.well-known/acme-challenge/<token>: \"\u003c!doctype html\u003e\n\u003c!--[if IE 8 ]\u003e\u003chtml lang=\"en\" class=\"ie ie8 lte9 lte8 no-js\"\u003e\u003c![endif]--\u003e\n\u003c!--[if IE 9 ]\u003e\u003chtml lang=\"en\" class=\"", "status": 403 }, "uri": "https://acme-staging.api.letsencrypt.org/acme/challenge/<challenge>/163133057", "token": "<token>", "keyAuthorization": "<token>.<key>", "validationRecord": [ { "url": "http://sub.example.com/.well-known/acme-challenge/<token>", "hostname": "sub.example.com", "port": "80", "addressesResolved": [ "X.X.X.X" ], "addressUsed": "X.X.X.X" }, { "url": "https://sub.example.com/.well-known/acme-challenge/<token>", "hostname": "sub.example.com", "port": "443", "addressesResolved": [ "X.X.X.X" ], "addressUsed": "X.X.X.X" }, { "url": "https://sub.example.com/?url=/.well-known/acme-challenge/<token>", "hostname": "sub.example.com", "port": "443", "addressesResolved": [ "X.X.X.X" ], "addressUsed": "X.X.X.X" } ]}'
nat on WAN_IF inet from $LOCAL to !LOCAL -> WAN_CARP_IP port 1024:65535