Questions tagged [lets-encrypt]
Let's Encrypt is a certificate authority that provides free X.509 certificates for TLS encryption.
870 questions
-2 votes
0 answers
140 views
Docker acme-companion can't connect to get certificate
I have reverse proxy with acme-companion on my docker stack - all behind ufw. I was using different solution before - but similar, and it worked. I had to change it since old solution were not updated ...
1 vote
1 answer
123 views
Is it correct to add Thawte certificate manually?
I have Ubuntu Server, Apache2 and certbot installed. I downloaded ThawtePCA.crt.pem from https://knowledge.digicert.com/general-information/digicert-trusted-root-authority-certificates set chown to ...
2 votes
0 answers
308 views
Apache 2.4.25 stopped working from one day to another on debian9 [closed]
I am running 2 forums and since the forum software does not support any current PHP and MySsql/Mariadb versions from Debian 10 forward, I am forced to stay on Debian 9. Either that or no forums ...
4 votes
2 answers
629 views
Why Apache Alias directive doesn't have precedence to Rewrite?
I need to have a rewrite of http to https with Apache and I also need to handle let's encrypt challenge for renewal, then I wrote this configuration, with Alias for Let's Encrypt and Rewrite for http-&...
0 votes
0 answers
81 views
Apache mod_md: can I renew a Let's Encrypt certificate with the same public key?
When using mod_md, is there a way to renew a Let's Encrypt certificate with the same public key (an equivalent to certbot renew --reuse-key)? I'd like to avoid having to change DNS DANE TLSA records ...
0 votes
0 answers
95 views
How can I configure Mosquitto on kubernetes to auto-restart when cert-manager obtains a new Let's encrypt certificate automatically?
Is there an example configuration of eclipse-mosquitto 2.x (docker container) on Kubernetes to restart automatically the pod when cert-manager obtains a new Let's encrypt certificate automatically (...
1 vote
0 answers
57 views
Centos 7, Postfix - Outbound (smtp) Untrusted TLS connection [closed]
I have a Centos 7 server that I'm having trouble clearing the smtp warning for outbound mail. I get: Untrusted TLS connection established to... [any domain] I am using letsencrypt. I have searched ...
0 votes
0 answers
66 views
Cyrus imapd / Let's Encrypt: SSL hiccups when attempting to load the live certs, but works fine from the archive
I'm currently setting up Cyrus IMAPd on my server in conjunction with certificates from Let's Encrypt to enable imaps, however, while doing s I have run into a problem: Attempting to load the ...
0 votes
0 answers
236 views
Let's Encrypt is Ending OCSP Support in 2025
From the official statement located at https://letsencrypt.org/2024/12/05/ending-ocsp/ August 6, 2025 On this date we will turn off our OCSP responders. I would like to know, if in Apache2 on Debian ...
2 votes
2 answers
1k views
Certbot, run a script after create a certificate
I have a new server with Rocky Linux 9.5. I have Apache installed and am creating the certificates I need with Certbot. When I run: certbot --apache -d mydomain after getting the certificate, and ...
0 votes
1 answer
150 views
Let's Encrypt TLS Certificate Expiration Plans
CA/B is decreasing certificate duration in stages culminating in 47 days on March 15, 2029. Currently Let's Encrypt hands out 90-day certificates. Does Let's Encrypt have their own roadmap of when/how ...
-1 votes
1 answer
128 views
allowing SSL certificate on multiple port on nginx
hello I have a website with SSL certificate called englishsociety.net if you open it on tab you can find the lock is working but I am facing an issue with different port let's say this port for ...
0 votes
1 answer
314 views
FreeIPA broke after Let’s Encrypt [closed]
I found another server fault question that seemed similar, but none of the answers helped. # ipa-pkinit-manage status PKINIT is enabled The ipa-pkinit-manage command was successful # ipa -v ping ipa: ...
0 votes
0 answers
173 views
Error code: SSL_ERROR_UNRECOGNIZED_NAME_ALERT
After updating the certificate on a microk8s cluster, the following error occurred: SSL_ERROR_UNRECOGNIZED_NAME_ALERT Is Let's Encrypt not working? Previously the domain could be accessed but now it ...
1 vote
1 answer
501 views
Nginx and acne.sh LE certs: Verify error: Invalid response from .well-known/acme-challenge
I'm using acme.sh to create a certificate for an older server, which I need to run for various reasons. However, I'm missing something wrt the .well-known/acme-challenge part. When I run the script: ...
1 vote
1 answer
409 views
Certbot renew SSL certificate behind a NGINX Gateway fails to authenticate on secondary validation
I have a docker container running a NGINX website behind a docker container running a NGINX Gateway. Both on the same host. Using URL 'my-site.com'. The webroot files are in a folder on host that are ...
0 votes
1 answer
93 views
Dovecot and SSL certificate caching
I have dovecot setup to use the letsencrypt certificates I use for my website. The certificates are updated automatically every 90 days (I think), I check for updates every week. The website (httpd) ...
0 votes
0 answers
85 views
How did someone get a Let's Encrypt cert for my domain?
Have ancient domain. Registrar NameCheap, nameservers point to linode, no server running. If I do a dig +trace, returns no DNS records, which is what I expect. However, the domain shows up on ...
0 votes
1 answer
203 views
Virtualmin: How to get the TXT record values for _acme-challenge? [closed]
The following Virtualmin dialog supposedly allows creating/renewing Lets Encrypt SSL certs in Virtualmin, however, the process fails because of 2 errors. The first error is a strange mkdir error about ...
0 votes
1 answer
53 views
Error validating http-01 SSL challenge (Let's Encryp, BuyPass Go SSL etc.)
I'm trying to somehow generate some SSL certificates using Certify The Web / IIS but every time (and with every certificate authority) I just get a timeout: Timeout during connect (likely firewall ...
1 vote
0 answers
165 views
NGINX SSL configurations sometimes point to the wrong domain with multiple virtual hosts
Question: I am running an NGINX server with approximately 150 virtual host configurations. Occasionally, clients report that their SSL certificate is incorrect, and their domain points to another ...
0 votes
1 answer
304 views
Need Advice on Using Certbot with Nginx for SSL Certificates
I need some advice on how to properly use Certbot to obtain SSL certificates from Let's Encrypt. For context, I am doing this in a script, so I need it to be non-interactive. I have a basic ...
0 votes
1 answer
127 views
cert-manager letsencrypt certificate give cert-manager.local on browser
After getting certificate from issuer apiVersion: cert-manager.io/v1 kind: Issuer metadata: name: letsencrypt-staging spec: acme: # The ACME server URL server: https://acme-staging-v02.api....
2 votes
0 answers
498 views
Apache2.4, How to disable OCSP?
Am running Apache 2.4 on Windows, with Let's Encrypt certification. Now, in July this year, Let's Encrypt announced intention to remove OCSP Service. Am using mod_md and hppt-01 challenge for ...
0 votes
1 answer
1k views
Certificate Authority (CA) is expiring on pfSense router
We are getting notifications of two CA's expiring in pfSense - shown below in a yellow colour: These are: Acmecert: O=(STAGING) Internet Security Research Group, CN=(STAGING) Pretend Pear X1, C=US ...
0 votes
0 answers
112 views
Nginx reverse Proxy randomly throws error for "Already listening to port 80 & 443"
I have set up nginx as a reverse proxy for my app with LetsEncrypt as SSL. All goes smoothly, but sometimes all of a sudden nginx goes down with an error message: Already bind with port 80/443 and a ...
1 vote
1 answer
280 views
How to debug certmanager's complaint about receiving the wrong HTTP response
I've got a small k3s cluster in my home hosting a few websites and local applications. For the most part, I've been able to wrangle it to host a variety of services, but the LetsEncrypt functionality ...
0 votes
1 answer
343 views
Issues enabling HTTPS on Nginx with Let's Encrypt for a Strapi API and React app
I'm trying to enable HTTPS on my Nginx server for two applications: a Strapi API and a React client application. React running from /home/rocky/231009twins/front/dist on port 50001 with pm2. Served on ...
1 vote
1 answer
134 views
Least risky server migration
I'm a iOS/Android developer and I'm not too expert with servers so I don't know how to make a server migration in the least risky way. This is my current scenario (this has been working for a long ...
1 vote
1 answer
781 views
let's encrypt certificate permission issue with postgres
I'm using certbot, on Ubuntu 22, to generare ssl certificate. All works fine but all certificate is generated in the following folder /etc/letsencrypt/live/domain/cert.pem The problem is that user and ...
1 vote
2 answers
3k views
Renew FreeIPA certs when existing cert already expired
I have FreeIPA on Rocky 8. I installed custom certs from LetsEncrypt using the command ipa-cacert-manage -p DM_PASSWORD -n NICKNAME -t C,, install ca.crt ipa-certupdate ipa-server-certinstall -w -d /...
2 votes
1 answer
6k views
Certbot failing on nginx reverse proxy: 404
I am trying to setup a Mastodon instance on Ubuntu 22.04. I have setup Nginx as a reverse proxy and now I am trying to generate an SSL certificate with Let's Encrypt. When I run certbot --nginx -d ...
0 votes
1 answer
122 views
CRON bash script certbot renew hangs
I have this script in /home/user/renew.sh ( cd /home/user/website/ && docker compose run --rm certbot renew --dry-run && docker compose kill -s SIGHUP webserver ) sudo crontab -e */5 *...
0 votes
0 answers
829 views
Mailu email server: Let’s Encrypt does not request new certificate automatically
Using Mailu docker image, I built an email server on Debian 12. Whenever the certificate expires, I use docker compose down and docker compose up command so certificate will be renewed. What I ...
0 votes
1 answer
3k views
How to find the root cause of "TLS library ..., wrong version number" for Postfix?
While trying to perform telnet on port 587 when I enter "AUTH LOGIN" the connection is closed ("Connection closed by foreign host.") and I have the following logs in my postfix ...
1 vote
2 answers
947 views
LetsEncrypt SSL with HAProxy Renew Not Working
I am trying to give SSL on HAProxy using certbot with LetsEncrypt. I am creating SSL with command: sudo certbot certonly --standalone -d test.example.com \ --non-interactive --agree-tos --email ...
4 votes
1 answer
2k views
Postfix not updating Let's Encrypt certificate
Whenever I update the SSL cert on the server (Alma Linux) I restart Postfix. I usually do this a few days or a week before the certificate runs out. However mail connections always fail on the day the ...
0 votes
0 answers
487 views
How to use multiple ports on the same server for a single domain using nginx and SSL
I am using Godaddy as my domain registrar and created a <subdomain_name> which is linked to my servers IP address on Digital Ocean. I am also using Let's encrypt to get SSL certificates and ...
0 votes
0 answers
35 views
Debian firewall allowing connections on port 3000 [duplicate]
I have a Debian server running Rocket Chat. The web interface is on port 3000 and works. I am trying to configure LetsEncrypt and checking the firewall it appears only port 22 is permitted. How can I ...
0 votes
0 answers
744 views
MongoDB issue with TLS
I am trying to set up TLS certificates for my standalone MongoDB instance on a cloud compute instance. I got the certificates from certbot using the command sudo certbot certonly --standalone -d. i ...
0 votes
2 answers
2k views
How do I properly issue Let's Encrypt certificate for my mail server?
How do I properly issue Let's Encrypt certificate for my Postfix mail server? Right now I have a self-signed certificate and I get these messages it cannot be trusted. I did certbot --nginx certonly -...
1 vote
1 answer
161 views
IP redirect Lets encrypt
Here is Lets encrypt documentation regarding http validation: "Our implementation of the HTTP-01 challenge follows redirects, up to 10 redirects deep. It only accepts redirects to “http:” or “...
0 votes
0 answers
426 views
MariaDB Crashes on Startup with Let's Encrypt Certificates
It seems I'm encountering an issue while setting up secure connections for my clients to connect to my database server on Debian 12. Every time I attempt to start MariaDB, it crashes with a Private ...
0 votes
1 answer
2k views
Mikrotik: Creating Letsencrypt cert fails on RouterOS v7
From RouterOS's webfig CLI I attempted to create a LetsEncrypt cert: certificate/enable-ssl-certificate dns-name=my.domain.com But it returned the error: progress: [error] http challenge validation ...
0 votes
2 answers
624 views
Postfix TLS with Letsencrypt configuration
I am running Postfix inside a docker container. Certificate are generated with certbot. With the following configuration: smtpd_tls_cert_file=/var/keys/fullchain.pem smtpd_tls_key_file=/var/keys/...
0 votes
0 answers
607 views
StrongSwan IPSec VPN - IKEv2 - LetsEncrypt Certificate Issue (building CRED_PRIVATE_KEY - RSA failed, tried 10 builders)
I followed the link below for setup IKEv2 VPN Using Strongswan and Let's encrypt on CentOS 7. How to Setup IKEv2 VPN Using Strongswan and Let's encrypt on CentOS 7 But info on that link has been ...
2 votes
1 answer
5k views
How to get both ECC & RSA certificates from Let's Encrypt for Postfix?
Let's Encrypt has started issuing ECC certificates by default since Certbot 2.0. This is not a problem for modern web browsers, but Let's Encrypt certificates can be used for other purposes than HTTPS,...
1 vote
1 answer
908 views
How to modify the command line used to renew a certificate using WACS
I have been using Let's Encrypt certificates for some of my domains/servers for a while, using the win-acme client for Windows for the generation and renewal. My problem is: every renewal I have to ...
0 votes
1 answer
123 views
How to add trusted SSL certificate to LinuxForHealth FHIR Server
I'm currently facing an issue with my LinuxForHealth FHIR Server setup and SSL certificates. I have the FHIR server running as a Docker container on my server, using a self-signed certificate and ...
0 votes
2 answers
234 views
In Postfix, Should SSL FQDN Matches with myhostname or mydomain field in /etc/postfix/main.cf?
Quoted from the documentation: myhostname The internet hostname of this mail system. The default is to use the fully-qualified domain name (FQDN) from gethostname(), or to use the non-FQDN result ...