<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Let&amp;#39;s Encrypt renewal problem</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/113867/let-s-encrypt-renewal-problem</link><description>Hello, 
 Anyone having issue with Let&amp;#39;s Encrypt unable to both auto and manual renewal with latest version 9.603-1? Let&amp;#39;s Encrypt log shows 
 
 Haven&amp;#39;t made any or FW changes prior. Thanks for any feedback</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408290?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 18:06:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d68976f1-2f1c-49da-a634-07d9639fbb09</guid><dc:creator>PatrickLee</dc:creator><description>&lt;p&gt;Hi Briain,&lt;/p&gt;
&lt;p&gt;My issue is now resolved.&amp;nbsp; My cert was using an old Interface.&amp;nbsp; Deleted my cert and re-create and point to the new Interface and it works.&amp;nbsp; Thanks for all your feedback and hope you have a pleasant dinner.&amp;nbsp; Looking forward to the fireworks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408289?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 17:50:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:650f6786-65b2-4622-b221-1717d138f726</guid><dc:creator>Briain</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Yes, sorry but it was just rather a wild &amp;#39;stab in the dark&amp;#39; and I realise that most USA ISP&amp;#39;s issue modems (whereas in the UK, it&amp;#39;s almost always routers; the only way we can avoid double NAT is to use a Draytek V130).&lt;/p&gt;
&lt;p&gt;I&amp;#39;m struggling to think what else could be blocking it, but over here, it&amp;#39;s time to make dinner, so I&amp;#39;ll ponder it all further over a glass of red wine (though at the moment, I cannot think of anything else that caught me out when initially doing all this).&lt;/p&gt;
&lt;p&gt;Bri&lt;/p&gt;
&lt;p&gt;PS Enjoy the 4th July celebrations over there; I hope one already has one&amp;#39;s has a BBQ lit and that the beers are well chilled (we don&amp;#39;t get many chances to do BBQs in Scotland; typically, all the food - and the BBQ fuel - almost immediately get blown away in the &amp;gt;70 MPH westerly &amp;#39;breezes&amp;#39;)! :-)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408287?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 17:29:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:414d9293-c7ad-4cb3-aa36-775004b67d44</guid><dc:creator>PatrickLee</dc:creator><description>&lt;p&gt;Hi Briain,&lt;/p&gt;
&lt;p&gt;I&amp;#39;m not using double-NAT.&amp;nbsp; Just your typical setup modem in front of the UTM.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408286?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 17:07:18 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4074ac58-fb54-42c1-8982-4e1552984975</guid><dc:creator>Briain</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve just had a looked at my archive logs to see what was shown for the auto-renew failure:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;2019:06:23-02:38:01 hadrian letsencrypt[8147]: I Check renewal: renew REF_CaCsrLetsencryp (domains: --------.ddns.net): certificate valid until Jul 22 12:44:18 2019 GMT (less than 30 days)
2019:06:23-02:39:03 hadrian letsencrypt[8492]: I Renew certificate: handling CSR REF_CaCsrLetsencryp for domain set [--------.ddns.net]
2019:06:23-02:39:03 hadrian letsencrypt[8492]: I Renew certificate: running command: /var/storage/chroot-reverseproxy/usr/dehydrated/bin/dehydrated -x -f /var/storage/chroot-reverseproxy/usr/dehydrated/conf/config -c --accept-terms --domain --------.ddns.net
2019:06:23-02:39:24 hadrian letsencrypt[8492]: I Renew certificate: command completed with exit code 256
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED: ERROR: Challenge is invalid! (returned: invalid) (result: {
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   &amp;quot;type&amp;quot;: &amp;quot;http-01&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COradsMMAND_FAILED:   &amp;quot;status&amp;quot;: &amp;quot;invalid&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   &amp;quot;error&amp;quot;: {
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:     &amp;quot;type&amp;quot;: &amp;quot;urn:acme:error:connection&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:     &amp;quot;detail&amp;quot;: &amp;quot;Fetching &lt;a href="http://--------.ddns.net/.well-known/acme-challenge/ly2GTBx4zNk_rhT9_5VzdXMo1Cv7cL3OzJfIfnMPWJY:"&gt;--------.ddns.net/.../ly2GTBx4zNk_rhT9_5VzdXMo1Cv7cL3OzJfIfnMPWJY:&lt;/a&gt; Timeout during connect (likely firewall problem)&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:     &amp;quot;status&amp;quot;: 400
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   },
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   &amp;quot;uri&amp;quot;: &amp;quot;&lt;a href="https://acme-v01.api.letsencrypt.org/acme/challenge/qtsI8fLjPR5Y3w_oMo-lqtLiGjVSIBC63sN3qpcOweo/17402800189"&gt;acme-v01.api.letsencrypt.org/.../17402800189&amp;quot;&lt;/a&gt;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   &amp;quot;token&amp;quot;: &amp;quot;ly2GTBx4zNk_rhT9_5VzdXMo1Cv7cL3OzJfIfnMPWJY&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   &amp;quot;validationRecord&amp;quot;: [
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:     {
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:       &amp;quot;url&amp;quot;: &amp;quot;&lt;a href="http://--------.ddns.net/.well-known/acme-challenge/ly2GTBx4zNk_rhT9_5VzdXMo1Cv7cL3OzJfIfnMPWJY"&gt;--------.ddns.net/.../ly2GTBx4zNk_rhT9_5VzdXMo1Cv7cL3OzJfIfnMPWJY&amp;quot;&lt;/a&gt;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:       &amp;quot;hostname&amp;quot;: &amp;quot;--------.ddns.net&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:       &amp;quot;port&amp;quot;: &amp;quot;80&amp;quot;,
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:       &amp;quot;addressesResolved&amp;quot;: [
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:         &amp;quot;---.---.---.132&amp;quot;
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:       ],
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:       &amp;quot;addressUsed&amp;quot;: &amp;quot;---.---.---.132&amp;quot;
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:     }
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED:   ]
2019:06:23-02:39:24 hadrian letsencrypt[8492]: E Renew certificate: COMMAND_FAILED: })
2019:06:23-02:39:25 hadrian letsencrypt[8492]: I Renew certificate: sending notification WARN-603
2019:06:23-02:39:25 hadrian letsencrypt[8492]: [WARN-603] Let&amp;#39;s Encrypt certificate renewal failed accessing Let&amp;#39;s Encrypt service
2019:06:23-02:39:25 hadrian letsencrypt[8492]: I Renew certificate: execution completed (CSRs renewed: 0, failed: 1)&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;
&lt;p&gt;&lt;br /&gt;So your log shows similar to the failure to the one that I&amp;#39;d had (before then letting the USA through) and thus that the response from LE is being blocked somewhere.&lt;br /&gt;&lt;br /&gt;Sorry to ask a such a silly question (though this one did initially catch me out) but are you using a double NAT scheme (e.g. an ISP router in front of UTM) and thus could it just be that for some odd reason, port 80 is no longer open [to the UTM WAN address] in the ISP router?&lt;/p&gt;
&lt;p&gt;Bri&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408283?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 16:49:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f3d1c172-898d-434c-a612-e7bfbde63e5f</guid><dc:creator>Briain</dc:creator><description>&lt;p&gt;Ah, well your location rather rules out my country blocking issue! :-)&lt;/p&gt;
&lt;p&gt;Anyhow, with me living in Scotland, with the USA permitted through country blocking and after a manual renew, it did actually work, so that implies 9.603-1 is capable of successfully refreshing an LE certificate. &lt;/p&gt;
&lt;p&gt;Bri&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408281?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 16:37:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b08c34df-4e45-4906-a6b7-0e76b5fceefb</guid><dc:creator>PatrickLee</dc:creator><description>&lt;p&gt;Hi Briain,&lt;/p&gt;
&lt;p&gt;Thanks for replying.&amp;nbsp; I live in the US, so USA blocking doesn&amp;#39;t apply.&amp;nbsp; Although acme-v01.x.x.x domain shows in the log, I went ahead and make an exception and do a manual renewal and my LE still failed.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/57/8360.Clipboard02.jpg"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/57/8360.Clipboard02.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;BTW, I&amp;#39;m also aware of the 5 days limitation on the manual renewal&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Let's Encrypt renewal problem</title><link>https://community.sophos.com/thread/408280?ContentTypeID=1</link><pubDate>Thu, 04 Jul 2019 15:56:36 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f85cd4ef-5d1e-4907-a4f1-e8364fcf0604</guid><dc:creator>Briain</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Yes, a few days ago I had a failure to auto-renew.&lt;/p&gt;
&lt;p&gt;When I first tried obtaining a LE certificate a few times (a couple of months back) I failed miserably, then I spotted a post suggesting that country blocking could prevent the process (which makes sense as I had USA set to block &amp;#39;From&amp;#39;; again, oops) so after letting the USA back through, I requested my certificate again and this time, it worked.&lt;/p&gt;
&lt;p&gt;Folloing the successful installation of the certificate, I then set the USA back to &amp;#39;From&amp;#39; and instead created a country blocking exception for acme-v01.api.letsencrypt.org and once again, I hit the &amp;#39;Renew&amp;#39; button in the Certificate Management section, and that also worked; my certificate was successfully updated. I waited a while and tried again, and once again the renewal process worked, so I was pretty confident that I&amp;#39;d found the solution.*&lt;/p&gt;
&lt;p&gt;That all said, another poster then tried that same trick and for some odd reason, they were unsuccessful.&lt;/p&gt;
&lt;p&gt;Move forward to last week (and with me now running 9.603-1) and I received an email from UTM stating that the automatic certificate renewal process had failed, so I again tried the manual renew process and that also failed. I wondered if the LE domain had been changed, but looking at the logs showed that it was still acme-v01.api.letsencrypt.org (implying that it hadn&amp;#39;t changed) so this time I had to let the USA back through country blocking (and then after hitting the manual refresh button, this time it worked) so in my case, it certainly &lt;em&gt;looks&lt;/em&gt; like something associated with the 9.603-1 update is perhaps now preventing my country blocking exception for&amp;nbsp;acme-v01.api.letsencrypt.org from working.&lt;/p&gt;
&lt;p&gt;Anyhow, it&amp;#39;s no big deal for me as I can simply let the USA back through after receiving my next failure e-mail (assuming it does fail, that is) and then manually hit the &amp;#39;refresh&amp;#39; button.&lt;/p&gt;
&lt;p&gt;Bri&lt;/p&gt;
&lt;p&gt;*Incidentally, after re-testing that country blocking exception yet one more time - just to prove it was 100% reliable - it failed to renew the certificate. I looked at the LE logs and at the LE site, discovering that you can only apply 5 times (in any 5 day rolling period) then you get biffed off the LE server for 5 days; oops! Of course, it wasn&amp;#39;t an issue as my existing certificate still had 90 days of life left in it.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>