When I click the “Provision” button on the TLS Certificates page I get a very unhelpful “Something went wrong. Sorry” error!
The overnight automatic attempts are sending me emails showing a failure of LetsEncrypt to download the challenge files. My domains serve their content from the correct paths (as far as I know). Could it be a permissions issue? What should the default permissions be?
I needed to change the permissions on the folders for my domains in order to FTP the files into them for the websites.
I’ve tried changing them back as follows but I suspect this isn’t correct.
sudo chown -R user-data /home/user-data/www/default
sudo chown -R user-data /home/user-data/www/gideon-it.co.uk
sudo chown -R user-data /home/user-data/www/philipalantyler.co.uk
sudo chown -R user-data /home/user-data/www/gideon-it.com
The emailed error message is shown below for the gideon-it.com domain.
Provisioning TLS certificates for gideon-it.com, autoconfig.gideon-it.com, autodiscover.gideon-it.com, mta-sts.gideon-it.com, www.gideon-it.com.
Provisioning TLS certificates for philipalantyler.co.uk, autoconfig.philipalantyler.co.uk, autodiscover.philipalantyler.co.uk, mta-sts.philipalantyler.co.uk, www.philipalantyler.co.uk.
error: gideon-it.com, autoconfig.gideon-it.com, autodiscover.gideon-it.com, mta-sts.gideon-it.com, www.gideon-it.com:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gideon-it.com and 4 more domains
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
Domain: autodiscover.gideon-it.com
Type: connection
Detail: 81.174.152.174: Fetching http://autodiscover.gideon-it.com/.well-known/acme-challenge/yWGA3xoJeMbxz8NBVyDfeHFtIJc28MR3D4Qbr1OMQ0Q: Timeout during connect (likely firewall problem)
Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
The System software is up to date.|
Mail-in-a-Box is up to date. You are running version v68