惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
量子位
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Google DeepMind News
Google DeepMind News
博客园_首页
云风的 BLOG
云风的 BLOG
月光博客
月光博客
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Vercel News
Vercel News
美团技术团队
Microsoft Security Blog
Microsoft Security Blog
P
Proofpoint News Feed
D
Docker
F
Fortinet All Blogs
N
Netflix TechBlog - Medium
博客园 - 叶小钗
Martin Fowler
Martin Fowler
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13
Not able to renew certificates
@MikeMcQ Mik · 2026-04-18 · via Let's Encrypt Community Support - Latest topics

April 17, 2026, 5:36am 1

Dear Team,
I am not able to renew certificate getting error.

Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 20
Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.ntsipl.com/cert9.pem
Certificate is due for renewal, auto-renewing...
Renewing an existing certificate for mail.ntsipl.com
Performing the following challenges:
http-01 challenge for mail.ntsipl.com
Waiting for verification...
Challenge failed for domain mail.ntsipl.com
http-01 challenge for mail.ntsipl.com

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: mail.ntsipl.com
Type: connection
Detail: 103.239.124.251: Fetching http://mail.ntsipl.com/.well-known/acme-challenge/2_fkHUh0A8JjVddLjxRWTKcqT_yMXOlRTC59Ceg2OFM: Error getting validation data

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Cleaning up challenges
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

--

MikeMcQ April 17, 2026, 1:45pm 2

Welcome @jitendra.sharma In the future please post problems in the Help section. That will show you a form to provide info that we often need. I moved your topic there and we will later show that form if this post is not enough to help you.

Your mail.ntispl.com domain is not responding to HTTP requests on port 80. This is required to satisfy the HTTP Challenge you used previously to get the cert. It must have worked when you got the cert originally and any renewals. But, is no longer working.

The Let's Encrypt server reported this as "Error getting validation data". I saw connection problems from every testing tool I tried so it is not unique to Let's Encrypt.

I can reach that domain using HTTPS on port 443. Just not HTTP and port 80. Interestingly, the cert used for connections to the mail subdomain use a wildcard cert for *.ntispl.com

For example, see: Check website performance and response : Check host - online website monitoring

3 Likes

letsencrypt.txt (1.9 MB)
Dear Sir,
please check the logs. It's happening after iredadmin-pro upgradation

1 Like

Dear Team,
Issue is resolved
Thanks

1 Like

MikeMcQ April 18, 2026, 12:55pm 5

Would you please explain what you did to resolve this? It might help us instruct someone else in the future if this happens again. Thanks

1 Like