English Forums > 22.7 Legacy Series

ACME NGINX HTTP 400 Again.

(1/3) > >>

itngo:
We had this issue in the past, but now it is ongoing for 2 days for a newly created Certificate. Existing Certs with HTTP-Challenge are working for renewal. We just copied and existing Cert and also a WEB in NGINX from a working one.

We can Download the challenge-file with any browser from any side. (Using DEBUG-Mode 3 so file does not get deleted)
However Let's Encrypt says


--- Quote ---{
  "type": "http-01",
  "status": "invalid",
  "error": {
    "type": "urn:ietf:params:acme:error:connection",
    "detail": "removed but is correct: Fetching http://removed but is correct/.well-known/acme-challenge/znc28dKFOGTaUY1o8GW1gbtQ_o40aecyyAmhXT-ur8g: Timeout during connect (likely firewall problem)",
    "status": 400
  },
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/removed but is correct/seTRuQ",
  "token": "removed but is correct",
  "validationRecord": [
    {
      "url": "http://removed but is correct/.well-known/acme-challenge/znc28dKFOGTaUY1o8GW1gbtQ_o40aecyyAmhXT-ur8g",
      "hostname": "removed but is correct",
      "port": "80",
      "addressesResolved": [
        "remove but is correct"
      ],
      "addressUsed": "removed but is correct"
    }
  ],
  "validated": "2022-10-18T06:00:33Z"
}
--- End quote ---

Any ideas what to do next?

itngo:
When I compare "rights" of an working and a non working acme-challenge file after starting renewal I can see a difference. Is that normal? See attachment....

itngo:
Created an ZeroSSL-Account had repeated the Issue/Renewal. It works. So something with the Let's Encrypt Challenge for HTTP-01 is not working here.

What can we do? Any suggestions?

Fright:
what is set in "HTTP Service" dropdown in HTTP-01 challenge settings?
any Port Forward rules involving tcp80?

itngo:
Hi,
see attachment...

no port forwarding. About 200 Webs are running with this config and about 50 Certs already issued with let's...

Navigation

[0] Message Index

[#] Next page

Go to full version