• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved Let's Encrypt unclear renewal failure

Bitpalast

Plesk addicted!
Plesk Guru
Onyx 17.0, CentOS 7.3, 64-Bit

Error message on certificate renewal of an add-on domain with web space:
Code:
[2017-04-28 15:30:06] ERR [extension/letsencrypt] Cannot renew certificate on domain DOMAIN-1.TLD with error: Challenge marked as invalid. Details: Could not connect to www.DOMAIN-2.TLD.well-known

Subscription is on domain "DOMAIN-1.TLD", an add-on domain is "DOMAIN-2.TLD". The "www" checkbox was set in Let's Encrypt, a valid, working certfificate exists for DOMAIN-2.TLD. The file permissions for subscription and add-on domain are the Plesk default permissions, the website is accessible. It is a Wordpress installation from the applications repository. The website is in "maintenance" mode.

Why is the renewal failing?
 
This issue was resolved. The customer has created a 301 redirect in her .htaccess file. The Let's Encrypt verification followed that redirect and failed to verify the domain. The certificate on that domain has been removed by us, because it makes no sense to have a cert on a redirect.
 
Back
Top