• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Resolved Let's Encrypt unclear renewal failure

Bitpalast

Plesk addicted!
Plesk Guru
Onyx 17.0, CentOS 7.3, 64-Bit

Error message on certificate renewal of an add-on domain with web space:
Code:
[2017-04-28 15:30:06] ERR [extension/letsencrypt] Cannot renew certificate on domain DOMAIN-1.TLD with error: Challenge marked as invalid. Details: Could not connect to www.DOMAIN-2.TLD.well-known

Subscription is on domain "DOMAIN-1.TLD", an add-on domain is "DOMAIN-2.TLD". The "www" checkbox was set in Let's Encrypt, a valid, working certfificate exists for DOMAIN-2.TLD. The file permissions for subscription and add-on domain are the Plesk default permissions, the website is accessible. It is a Wordpress installation from the applications repository. The website is in "maintenance" mode.

Why is the renewal failing?
 
This issue was resolved. The customer has created a 301 redirect in her .htaccess file. The Let's Encrypt verification followed that redirect and failed to verify the domain. The certificate on that domain has been removed by us, because it makes no sense to have a cert on a redirect.
 
Back
Top