Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Acme/letsencrypt error creating directory…

    Scheduled Pinned Locked Moved ACME
    12 Posts 3 Posters 9.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      @hvisage:

      Where can I see the directory it tried to create that failed?

      Erm… that'd be the one you configured (if you are talking about the local webroot method). If you did not configure any, no wonder it doesn't work.

      1 Reply Last reply Reply Quote 0
      • R
        roadfox
        last edited by

        a hint where this is configured would be much appreciated

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          In the same place where you select the method.

          1 Reply Last reply Reply Quote 0
          • R
            roadfox
            last edited by

            There's no field to configure a directory in pf version 2.3.2_1 and acme package 0.1.9

            Also i don't think that configuring webroot is enough, from what i saw so far LE tryes to access a document over http, but there is no webserver listening on port 80 nor is there a firewall rule allowing access from LE to 80 over WAN.
            would be great if the cert issue process ensures that LE is trying to access the document over 443 (if webif is on 443) and that there is a rule or even better open a temporary one if this is possible

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              @roadfox:

              There's no field to configure a directory in pf version 2.3.2_1 and acme package 0.1.9

              What ???

              (And yeah you need to have a webserver running there, completely OT for this thread. See this.)

              Screenshot_webroot_folder.png_thumb
              Screenshot_webroot_folder.png

              1 Reply Last reply Reply Quote 0
              • R
                roadfox
                last edited by

                See attachement on how it looks on my pfsense

                Do i use a broken template i'm not aware that i changed it, but i'm absolutely not sure
                In the other thread you write "If someone really insists on using  a local webroot."
                I'm absolutely not insisting on it, but which is the prefered method to use?

                And many thank for helping and replying so quick!

                ![Bild 5.png](/public/imported_attachments/1/Bild 5.png)
                ![Bild 5.png_thumb](/public/imported_attachments/1/Bild 5.png_thumb)

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  Click the + there.

                  1 Reply Last reply Reply Quote 0
                  • R
                    roadfox
                    last edited by

                    oh boy, ok got it, many thanks

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      https://redmine.pfsense.org/issues/7237

                      1 Reply Last reply Reply Quote 0
                      • H
                        hvisage
                        last edited by

                        doktornotor pointed to the method how to set it up with HAproxy whenthereisn'tawebserveronport80*

                        HOWEVER: The default nginx Webconfigurator, will also listen on port 80 when the "WebGUI redirect" is unchecked (System -> Advanced -> Admin Access)

                        Then, under the certificate under the Services -> ACME, select/edit/create the certificate, you select the webroot local, and then use /usr/local/www/.well-known/acme-challenge/
                        (See attachment)

                        I suspect when I check that WebGUI redirect disable, then you could use the "standalone HTTP server" option…

                        ![Screenshot 2017-02-13 18.39.46.png](/public/imported_attachments/1/Screenshot 2017-02-13 18.39.46.png)
                        ![Screenshot 2017-02-13 18.39.46.png_thumb](/public/imported_attachments/1/Screenshot 2017-02-13 18.39.46.png_thumb)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.