惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
D
Docker
月光博客
月光博客
MongoDB | Blog
MongoDB | Blog
Vercel News
Vercel News
美团技术团队
博客园 - 叶小钗
I
InfoQ
Jina AI
Jina AI
博客园 - 司徒正美
雷峰网
雷峰网
B
Blog
Y
Y Combinator Blog
A
About on SuperTechFans
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent Announcements
Recent Announcements
V
V2EX
N
Netflix TechBlog - Medium

Let's Encrypt Community Support - Latest posts

Fail to renew NGINX cert Installing across 2 servers Transitioning to 45-day certs: How to handle certificates with >25 SANs (blocked by `tlsserver` limit) TSplus certificate installation error Certsage Urn:ietf:params:acme:error:malformed [Let's Encrypt Blog] A Post-Quantum Future for Let's Encrypt Guidance on Security Review for Let’s Encrypt Adoption 2026.06.03 CRLs Temporarily Missing Revoked Serials ACME 404 errors for existing end-to-end tests: “No such authorization” / “Certificate not found” Certbot fullchain missing intermediates Can't generate certificate - Unable to validate JWS Unable to renew certificate on RHEL 8 Lost where my certificate is renewed from Want get R13 (ISRG Root X1) with acme.sh or certbot script Error renewing certificates, Error finalizing order :: authorizations for these identifiers not found: Error getting certificates ACME 404 errors for existing end-to-end tests: “No such authorization” / “Certificate not found” Certificate creation failed with message [Fail to load resource from 'https://acme-v02.api.letsencrypt.org/acme/finalize/ SSL certificate expired Certbot Code 1, Installing AMP for MC on CachyOS Certonly --force-renewal Need newby help with getting cert for my nas with my zip file Creating ssl certificate synology IKEv2 (strongSwan) fails with Let's Encrypt YR2 chain (works with other servers / chain mismatch suspected) Client can't connect ikev2 server HTTP-01 and AWS challenge Trouble with dns-rfc2136 plugin Getssl hangs, Lets Encrypt not requesting token Has there been a recent change in order/authorization reuse behavior for the Classic profile? Invalid response from web address so cannot validate
Not able to renew certificates
@MikeMcQ Mik · 2026-04-18 · via Let's Encrypt Community Support - Latest posts

April 17, 2026, 5:36am 1

Dear Team,
I am not able to renew certificate getting error.

Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 20
Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.ntsipl.com/cert9.pem
Certificate is due for renewal, auto-renewing...
Renewing an existing certificate for mail.ntsipl.com
Performing the following challenges:
http-01 challenge for mail.ntsipl.com
Waiting for verification...
Challenge failed for domain mail.ntsipl.com
http-01 challenge for mail.ntsipl.com

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: mail.ntsipl.com
Type: connection
Detail: 103.239.124.251: Fetching http://mail.ntsipl.com/.well-known/acme-challenge/2_fkHUh0A8JjVddLjxRWTKcqT_yMXOlRTC59Ceg2OFM: Error getting validation data

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Cleaning up challenges
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

--

MikeMcQ April 17, 2026, 1:45pm 2

Welcome @jitendra.sharma In the future please post problems in the Help section. That will show you a form to provide info that we often need. I moved your topic there and we will later show that form if this post is not enough to help you.

Your mail.ntispl.com domain is not responding to HTTP requests on port 80. This is required to satisfy the HTTP Challenge you used previously to get the cert. It must have worked when you got the cert originally and any renewals. But, is no longer working.

The Let's Encrypt server reported this as "Error getting validation data". I saw connection problems from every testing tool I tried so it is not unique to Let's Encrypt.

I can reach that domain using HTTPS on port 443. Just not HTTP and port 80. Interestingly, the cert used for connections to the mail subdomain use a wildcard cert for *.ntispl.com

For example, see: Check website performance and response : Check host - online website monitoring

3 Likes

letsencrypt.txt (1.9 MB)
Dear Sir,
please check the logs. It's happening after iredadmin-pro upgradation

1 Like

Dear Team,
Issue is resolved
Thanks

1 Like

MikeMcQ April 18, 2026, 12:55pm 5

Would you please explain what you did to resolve this? It might help us instruct someone else in the future if this happens again. Thanks

1 Like