Certbot Renewal Failed

Let's Encrypt could not reach the HTTP-01 challenge on port 80, or the DNS for the name no longer points at this server. Check the site below to confirm what is wrong.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

SSL Certificate Checker

The error, and the fix

Error CodesChallenge failed · Timeout during connect
Usual CauseLet's Encrypt could not reach the HTTP-01 challenge on port 80, or the DNS for the name no longer points at this server
Check From a Terminalopenssl s_client -connect example.com:443 -servername example.com

Let's Encrypt could not reach the HTTP-01 challenge on port 80, or the DNS for the name no longer points at this server.

How to fix it: Keep port 80 open, check the A/AAAA records point here (including IPv6), and run certbot renew --dry-run to test.

Questions

What does "certbot renewal failed" mean?
Let's Encrypt could not reach the HTTP-01 challenge on port 80, or the DNS for the name no longer points at this server.
How do I fix it?
Keep port 80 open, check the A/AAAA records point here (including IPv6), and run certbot renew --dry-run to test.
Is it safe to click through the warning?
Not on a site where you enter passwords or payment details: the connection may not be private. Fix the certificate instead.

Stop abuse leaving your servers

Frabs watches every VM's outbound traffic and stops spam, scans and floods before the abuse report arrives.