<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Can&#x27;t renew SSL certificate]]></title><description><![CDATA[<p dir="auto">When trying to renew Let's Encrypt certificates via Cloudron's Domains page, I press Renew All Certs, and no error message is printed in the the browser when the process seems complete, but when checking logs it seems the update has failed.</p>
<pre><code>Sep 22 16:17:59 box:shell startMail (stderr):
Sep 22 16:17:59 box:reverseproxy ensureCertificate: renewal of my.arj.rocks failed. using fallback certificates for arj.rocks
Sep 22 16:17:59 box:tasks 791: {"percent":34,"message":"Renewing certs of nextcloud.arj.rocks"}
Sep 22 16:17:59 box:reverseproxy ensureCertificate: nextcloud.arj.rocks certificate already exists at /home/yellowtent/boxdata/certs/_.arj.rocks.key
Sep 22 16:17:59 box:reverseproxy isExpiringSync: /home/yellowtent/boxdata/certs/_.arj.rocks.cert Certificate will expire 1
Sep 22 16:17:59 box:reverseproxy ensureCertificate: nextcloud.arj.rocks cert require renewal
Sep 22 16:17:59 box:reverseproxy ensureCertificate: getting certificate for nextcloud.arj.rocks with options {"prod":true,"performHttpAuthorization":false,"wildcard":true,"email":"[redacted]@gmail.com"}
Sep 22 16:17:59 box:cert/acme2 getCertificate: attempt 1
Sep 22 16:17:59 box:cert/acme2 getCertificate: start acme flow for nextcloud.arj.rocks from https://acme-v02.api.letsencrypt.org/directory
Sep 22 16:17:59 box:cert/acme2 getCertificate: will get wildcard cert for *.arj.rocks
Sep 22 16:17:59 box:cert/acme2 getCertificate: attempt 2
Sep 22 16:17:59 box:cert/acme2 getCertificate: start acme flow for nextcloud.arj.rocks from https://acme-v02.api.letsencrypt.org/directory
Sep 22 16:17:59 box:cert/acme2 getCertificate: will get wildcard cert for *.arj.rocks
Sep 22 16:17:59 box:cert/acme2 getCertificate: attempt 3
Sep 22 16:17:59 box:cert/acme2 getCertificate: start acme flow for nextcloud.arj.rocks from https://acme-v02.api.letsencrypt.org/directory
Sep 22 16:17:59 box:cert/acme2 getCertificate: will get wildcard cert for *.arj.rocks
Sep 22 16:17:59 box:reverseproxy ensureCertificate: error: Network error getting directory: getaddrinfo EAI_AGAIN acme-v02.api.letsencrypt.org acme-v02.api.letsencrypt.org:443 cert: null
</code></pre>
<p dir="auto">I've checked my firewall settings and ports 443 and 80 are open. I also tried again after disabling the firewall, the error is replicated.</p>
<p dir="auto">Any ideas what I need to do to renew certs?</p>
<p dir="auto">Many thanks</p>
]]></description><link>https://forum.cloudron.io/topic/3197/can-t-renew-ssl-certificate</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 20:21:29 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/3197.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 22 Sep 2020 15:25:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Can&#x27;t renew SSL certificate on Wed, 23 Sep 2020 16:26:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/andrewj720" aria-label="Profile: andrewj720">@<bdi>andrewj720</bdi></a> Looks like DNS is not working on your server. You can also try <code>host cloudron.io</code> etc, I guess none of it working?</p>
<p dir="auto">Can you check if your cloud firewall allows outbound port 53 UDP ? I think there was a post on this forum some time ago that someone had it blocked in AWS security group by mistake, for example.</p>
]]></description><link>https://forum.cloudron.io/post/13580</link><guid isPermaLink="true">https://forum.cloudron.io/post/13580</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 23 Sep 2020 16:26:10 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t renew SSL certificate on Wed, 23 Sep 2020 11:31:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> No success unfortunately. I get:</p>
<pre><code>root@cloudron:~# host acme-v02.api.letsencrypt.org 127.0.0.1
;; connection timed out; no servers could be reached

</code></pre>
<p dir="auto">And the same after running</p>
<pre><code>sudo systemctl restart unbound
</code></pre>
]]></description><link>https://forum.cloudron.io/post/13556</link><guid isPermaLink="true">https://forum.cloudron.io/post/13556</guid><dc:creator><![CDATA[andrewj720]]></dc:creator><pubDate>Wed, 23 Sep 2020 11:31:30 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t renew SSL certificate on Tue, 22 Sep 2020 16:07:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/andrewj720" aria-label="Profile: andrewj720">@<bdi>andrewj720</bdi></a> said in <a href="/post/13500">Can't renew SSL certificate</a>:</p>
<blockquote>
<p dir="auto">Sep 22 16:17:59 box:reverseproxy ensureCertificate: error: Network error getting directory: getaddrinfo EAI_AGAIN <a href="http://acme-v02.api.letsencrypt.org" target="_blank" rel="noopener noreferrer nofollow ugc">acme-v02.api.letsencrypt.org</a> <a href="http://acme-v02.api.letsencrypt.org:443" target="_blank" rel="noopener noreferrer nofollow ugc">acme-v02.api.letsencrypt.org:443</a> cert: null</p>
</blockquote>
<p dir="auto">It seems there is some DNS error. Do you have any special DNS setup? Does the following command work on your server?</p>
<pre><code>host acme-v02.api.letsencrypt.org 127.0.0.1
</code></pre>
<p dir="auto">If not, you can try restarting unbound using <code>sudo systemctl restart unbound</code> and try the command again.</p>
]]></description><link>https://forum.cloudron.io/post/13502</link><guid isPermaLink="true">https://forum.cloudron.io/post/13502</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Tue, 22 Sep 2020 16:07:11 GMT</pubDate></item></channel></rss>