• Plesk Uservoice will be deprecated by October. Moving forward, all product feature requests and improvement suggestions will be managed through our new platform Plesk Productboard.
    To continue sharing your ideas and feedback, please visit features.plesk.com

Resolved Let's Encrypt unclear renewal failure

Bitpalast

Plesk addicted!
Plesk Guru
Onyx 17.0, CentOS 7.3, 64-Bit

Error message on certificate renewal of an add-on domain with web space:
Code:
[2017-04-28 15:30:06] ERR [extension/letsencrypt] Cannot renew certificate on domain DOMAIN-1.TLD with error: Challenge marked as invalid. Details: Could not connect to www.DOMAIN-2.TLD.well-known

Subscription is on domain "DOMAIN-1.TLD", an add-on domain is "DOMAIN-2.TLD". The "www" checkbox was set in Let's Encrypt, a valid, working certfificate exists for DOMAIN-2.TLD. The file permissions for subscription and add-on domain are the Plesk default permissions, the website is accessible. It is a Wordpress installation from the applications repository. The website is in "maintenance" mode.

Why is the renewal failing?
 
This issue was resolved. The customer has created a 301 redirect in her .htaccess file. The Let's Encrypt verification followed that redirect and failed to verify the domain. The certificate on that domain has been removed by us, because it makes no sense to have a cert on a redirect.
 
Back
Top