• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsesne Let’s Encrypt error issuing Certificate

ACME
2
5
1.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sshami
    last edited by sshami Jun 7, 2021, 12:19 PM Jun 7, 2021, 12:15 PM

    Hi, I am getting problem while issuing lets encrypt certificate.
    Using Domain SAN list - Standalone HTTP server.
    name.domainname/:Verify error:Invalid response from http://name.domainname/.well-known/acme-challenge/C27R5jTknkrfD3-7gMfiISsDIG3qtluDM_JcI8CEUHI [xxx.xx.xx.xx]: 503
    Note: Above domain name is changed just for example.
    If i go to/tmp/acme/acme_issuecert.log
    “type”: “urn:ietf:params:acme:error:malformed”,
    “detail”: “Unable to update challenge :: authorization must be pending”,
    “status”: 400
    If i hit : http://name.domainname/.well-known/acme-challenge/C27R5jTknkrfD3-7gMfiISsDIG3qtluDM_JcI8CEUHI
    503 Service Unavailable
    No server is available to handle this request.

    My steup is 2 Pfsese with HA with CARP virtual IP.

    G 1 Reply Last reply Jun 7, 2021, 12:23 PM Reply Quote 0
    • G
      Gertjan @sshami
      last edited by Jun 7, 2021, 12:23 PM

      @sshami said in Pfsesne Let’s Encrypt error issuing Certificate:

      If i hit : http://name.domainname/.....
      then
      503 Service Unavailable

      which means that, when LE contacted on port 80 TCP (a classic http request) the "name.domainname" web server, there was no answer = no web server present ?
      "name.domainname" points to a web server ?

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      S 1 Reply Last reply Jun 7, 2021, 12:27 PM Reply Quote 0
      • S
        sshami @Gertjan
        last edited by sshami Jun 7, 2021, 12:29 PM Jun 7, 2021, 12:27 PM

        @gertjan
        Thanks !
        First of all i a unable to create certificate via LE giving error 503.
        What would be posible cause and where i have to check. Even i can dns lookup my entry and it resolved correct IP.
        Could i try to use DNS-Amazon Route53 API method instead of standalone HTTP server.

        G 1 Reply Last reply Jun 7, 2021, 12:36 PM Reply Quote 0
        • G
          Gertjan @sshami
          last edited by Jun 7, 2021, 12:36 PM

          @sshami

          @sshami said in Pfsesne Let’s Encrypt error issuing Certificate:

          What would be posible cause

          You have to own = rent "name.domainname".
          You have a A record setup that point to an IP.
          On this IP you should have a web server, that should answer, at least, '80' (http).

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          S 1 Reply Last reply Jun 7, 2021, 12:50 PM Reply Quote 0
          • S
            sshami @Gertjan
            last edited by sshami Jun 7, 2021, 12:54 PM Jun 7, 2021, 12:50 PM

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            4 out of 5
            • First post
              4/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.