Let's Encrypt Cert could not be issued

Discussion in 'ISPConfig 3 Priority Support' started by aldo, Oct 5, 2016.

  1. aldo

    aldo Member HowtoForge Supporter

    I have upgraded ISPConfig 3.0.5.4p9 on Debian 7 to version 3.1 and installed certbot as described in the manual.
    When I check "Let's Encrypt SSL" checkbox, SSL tab does not become hidden as described in the manual, but pressing "Save" ISPConfig tries to get the certificate without success.
    There are no subdomains/aliasdomains other than mydomain.tld and www.mydomain.tld and both are reachable.

    Code:
    2016-10-05 15:00    my.server.name    Warning    Let's Encrypt SSL Cert for: mydomain.tld could not be issued.    
    2016-10-05 15:00    my.server.name    Debug    Let's Encrypt SSL Cert domains: mydomain.tld --domains www.mydomain.tld    
    2016-10-05 15:00    my.server.name    Debug    Create Let's Encrypt SSL Cert for: mydomain.tld
    What other tests could I do?
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    Please update do ispconfig 3.1dev by running:

    ispconfig_update.sh

    and chse "git-stable" as update source. There is a missing whiteline in the vhost template for apache 2.2. Then change a settings in the website, e.g. enable cgi, press save to force an update of the vhost config, then go back to the website settings and enable letsencrypt again (and undo the change that you did before).
     
  3. aldo

    aldo Member HowtoForge Supporter

    That not solved.
    I notice that after saving (2nd time with letsencrypt set) both SSL and SSL Encrypt flags result unchecked.
    In SSL tab, SSL key is present but SSL Request and SSL Certificate aren't.
    Should Locality, State, Org, Org unit and Country be left empty during letsencrypt creation?
     
  4. till

    till Super Moderator Staff Member ISPConfig Developer

    This means that letsencrypt could not issue a cert for your domain.

    Yes. do not do anything on the ssl tab as this will cause letsencrypt to fail.
     
  5. aldo

    aldo Member HowtoForge Supporter

    Sorry, I tried with an untouched SSL tab, but I got the same result.
     
  6. till

    till Super Moderator Staff Member ISPConfig Developer

    check the debug log and you can also check the letsencrypt log to see why letsencrypt refused to issue the ssl cert.
     
  7. aldo

    aldo Member HowtoForge Supporter

    Is debug log different from ISPConfig -> Monitor -> Show System-Log after setting log level to "debug"?
    Where is letsencrypt log?
     
  8. till

    till Super Moderator Staff Member ISPConfig Developer

  9. aldo

    aldo Member HowtoForge Supporter

    I've read the FAQ, but have not been useful.
    The /var/log/letsencrypt log does not exist.
     
  10. till

    till Super Moderator Staff Member ISPConfig Developer

Share This Page