Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:21:59 [emerg] 1725639#1725639: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed
How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Nginx Web Server plugin (nginx) [Misconfigured]
2: Runs an HTTP server locally which serves the necessary validation files under
the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP
server already running. HTTP challenge only (wildcards not supported).
(standalone)
3: Saves the necessary validation files to a .well-known/acme-challenge/
directory within the nominated webroot path. A separate HTTP server must be
running and serving files from the webroot path. HTTP challenge only (wildcards
not supported). (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-3] then [enter] (press 'c' to cancel):
https://matrix.to/#/!sNARMdEsFZERaQAJzl:matrix.org/$1oLeNI80LdVcZmNW6mIRwHd0BaeHaIeLN0SBV4E8omY:
```bash
certbot --nginx-ctl /usr/sbin/nginx --force-renew renew
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com-0001.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for v.lemnoslife.com and 6 more domains
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: etesync.lemnoslife.com
Type: unauthorized
Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/KKRD0BhRJNu4YQb0NJwfxTxwkGaJqm_mWcuWgIOxWXU: 404
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
Failed to renew certificate gitea.lemnoslife.com-0001 with error: Some challenges have failed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for crawler.yt.lemnoslife.com and 5 more domains
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: crawler.yt.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain
Domain: private.yt.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
Failed to renew certificate gitea.lemnoslife.com with error: Some challenges have failed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitlab.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for private.yt.lemnoslife.com and 9 more domains
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: crawler.yt.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain
Domain: private.yt.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain
Domain: yt4.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain
Domain: etesync.lemnoslife.com
Type: unauthorized
Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/_68c-vc8JjgY7iJdEmNdJHZKiv02knPESeQEWqi_gQw: 404
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
Failed to renew certificate gitlab.lemnoslife.com with error: Some challenges have failed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for overleaf.lemnoslife.com
Reloading nginx server after certificate renewal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/pim.etesync.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for pim.etesync.lemnoslife.com
Reloading nginx server after certificate renewal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/private.yt.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for private.yt.lemnoslife.com and yt4.lemnoslife.com
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: private.yt.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain
Domain: yt4.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
Failed to renew certificate private.yt.lemnoslife.com with error: Some challenges have failed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/server0.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for server0.lemnoslife.com
Reloading nginx server after certificate renewal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/v.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for v.lemnoslife.com
Reloading nginx server after certificate renewal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/videos.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for videos.lemnoslife.com
Reloading nginx server after certificate renewal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The following renewals succeeded:
/etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem (success)
/etc/letsencrypt/live/pim.etesync.lemnoslife.com/fullchain.pem (success)
/etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem (success)
/etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem (success)
/etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem (success)
The following renewals failed:
/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem (failure)
/etc/letsencrypt/live/gitea.lemnoslife.com/fullchain.pem (failure)
/etc/letsencrypt/live/gitlab.lemnoslife.com/fullchain.pem (failure)
/etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem (failure)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 renew failure(s), 0 parse failure(s)
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
On Debian 13 OverClock3000:
```bash
grep -rw gitea /etc/nginx/sites-enabled/
```
<details>
<summary>Output:</summary>
```
/etc/nginx/sites-enabled/server0: ssl_certificate /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem; # managed by Certbot
/etc/nginx/sites-enabled/server0: ssl_certificate_key /etc/letsencrypt/live/gitea.lemnoslife.com-0001/privkey.pem; # managed by Certbot
/etc/nginx/sites-enabled/.git/logs/HEAD:0000000000000000000000000000000000000000 9319f715812032b9d42d25b6463fd8cb6331116d Benjamin Loison <serveur@lemnoslife.com> 1790810365 +0200 commit (initial): Add `gitea`
/etc/nginx/sites-enabled/.git/logs/refs/heads/master:0000000000000000000000000000000000000000 9319f715812032b9d42d25b6463fd8cb6331116d Benjamin Loison <serveur@lemnoslife.com> 1790810365 +0200 commit (initial): Add `gitea`
grep: /etc/nginx/sites-enabled/.git/index: binary file matches
/etc/nginx/sites-enabled/.git/COMMIT_EDITMSG:Add `gitea`
/etc/nginx/sites-enabled/youtube_operational_api:# [Benjamin_Loison/nginx/issues/4](https://gitea.lemnoslife.com/Benjamin_Loison/nginx/issues/4)
/etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf: ssl_certificate /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem; # managed by Certbot
/etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf: ssl_certificate_key /etc/letsencrypt/live/gitea.lemnoslife.com-0001/privkey.pem; # managed by Certbot
```
</details>
It was unclear to me where `etesync.lemnoslife.com` is involved.
[The Stack Overflow answer 78483090](https://stackoverflow.com/a/78483090) seems to have involved more troubles than help in my case.
In `/etc/nginx/sites-enabled/`:
```bash
ls
```
```
gitea gitlab-omnibus-ssl-nginx.conf overleaf peertube server0 youtube_operational_api
```
```bash
certbot --nginx-ctl /usr/sbin/nginx certonly -d gitea.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:21:59 [emerg] 1725639#1725639: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed
How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Nginx Web Server plugin (nginx) [Misconfigured]
2: Runs an HTTP server locally which serves the necessary validation files under
the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP
server already running. HTTP challenge only (wildcards not supported).
(standalone)
3: Saves the necessary validation files to a .well-known/acme-challenge/
directory within the nominated webroot path. A separate HTTP server must be
running and serving files from the webroot path. HTTP challenge only (wildcards
not supported). (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-3] then [enter] (press 'c' to cancel):
```
</details>
It seems that indeed I forgot to add ssl to listen.
DuckDuckGo search `"SSL_ERROR_RX_RECORD_TOO_LONG" "certbot"`.
[The Server Fault answer 1113578](https://serverfault.com/a/1113578):
It seems that indeed I forgot to add `ssl` to `listen`.
× nginx.service - A high performance web server and a reverse proxy server
Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
Active: failed (Result: exit-code) since Thu 2026-10-01 01:22:25 CEST; 5s ago
Duration: 2d 8h 17min 43.911s
Invocation: 3456f273bd374118965bf9f8678f0b06
Docs: man:nginx(8)
Process: 1725679 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=1/FAILURE)
Mem peak: 2.7M
CPU: 16ms
Oct 01 01:22:25 overclock3000 systemd[1]: Starting nginx.service - A high performance web server and a reverse proxy server...
Oct 01 01:22:25 overclock3000 nginx[1725679]: 2026/10/01 01:22:25 [emerg] 1725679#1725679: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
Oct 01 01:22:25 overclock3000 nginx[1725679]: nginx: configuration file /etc/nginx/nginx.conf test failed
Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'.
Oct 01 01:22:25 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server.
```bash
sudo service nginx status
```
<details>
<summary>Output:</summary>
```
× nginx.service - A high performance web server and a reverse proxy server
Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
Active: failed (Result: exit-code) since Thu 2026-10-01 01:22:25 CEST; 5s ago
Duration: 2d 8h 17min 43.911s
Invocation: 3456f273bd374118965bf9f8678f0b06
Docs: man:nginx(8)
Process: 1725679 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=1/FAILURE)
Mem peak: 2.7M
CPU: 16ms
Oct 01 01:22:25 overclock3000 systemd[1]: Starting nginx.service - A high performance web server and a reverse proxy server...
Oct 01 01:22:25 overclock3000 nginx[1725679]: 2026/10/01 01:22:25 [emerg] 1725679#1725679: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
Oct 01 01:22:25 overclock3000 nginx[1725679]: nginx: configuration file /etc/nginx/nginx.conf test failed
Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'.
Oct 01 01:22:25 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server.
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:23:58 [emerg] 1725789#1725789: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Nginx Web Server plugin (nginx) [Misconfigured]
2: Runs an HTTP server locally which serves the necessary validation files under
the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP
server already running. HTTP challenge only (wildcards not supported).
(standalone)
3: Saves the necessary validation files to a .well-known/acme-challenge/
directory within the nominated webroot path. A separate HTTP server must be
running and serving files from the webroot path. HTTP challenge only (wildcards
not supported). (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-3] then [enter] (press 'c' to cancel):
```bash
certbot --nginx-ctl /usr/sbin/nginx certonly -d gitea.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:23:58 [emerg] 1725789#1725789: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Nginx Web Server plugin (nginx) [Misconfigured]
2: Runs an HTTP server locally which serves the necessary validation files under
the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP
server already running. HTTP challenge only (wildcards not supported).
(standalone)
3: Saves the necessary validation files to a .well-known/acme-challenge/
directory within the nominated webroot path. A separate HTTP server must be
running and serving files from the webroot path. HTTP challenge only (wildcards
not supported). (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-3] then [enter] (press 'c' to cancel):
```
</details>
2026/10/01 01:23:49 [emerg] 1725786#1725786: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
```bash
nginx -c /etc/nginx/nginx.conf -t
```
<details>
<summary>Output:</summary>
```
2026/10/01 01:23:49 [emerg] 1725786#1725786: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
```
</details>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...
Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,
it will attempt to use a webserver both for obtaining and installing the
certificate. The most common SUBCOMMANDS and flags are:
obtain, install, and renew certificates:
(default) run Obtain & install a certificate in your current webserver
certonly Obtain or renew a certificate, but do not install it
renew Renew all previously obtained certificates that are near
expiry
enhance Add security enhancements to your existing configuration
-d DOMAINS Comma-separated list of domains to obtain a certificate for
(the certbot apache plugin is not installed)
--standalone Run a standalone webserver for authentication
--nginx Use the Nginx plugin for authentication & installation
--webroot Place files in a server's webroot folder for authentication
--manual Obtain certificates interactively, or using shell script
hooks
-n Run non-interactively
--test-cert Obtain a test certificate from a staging server
--dry-run Test "renew" or "certonly" without saving any certificates
to disk
manage certificates:
certificates Display information about certificates you have from Certbot
revoke Revoke a certificate (supply --cert-name or --cert-path)
delete Delete a certificate (supply --cert-name)
reconfigure Update a certificate's configuration (supply --cert-name)
manage your account:
register Create an ACME account
unregister Deactivate an ACME account
update_account Update an ACME account
show_account Display account details
--agree-tos Agree to the ACME server's Subscriber Agreement
-m EMAIL Email address for important account notifications
More detailed help:
-h, --help [TOPIC] print this message, or detailed help on a topic;
the available TOPICS are:
all, automation, commands, paths, security, testing, or any of the
subcommands or plugins (certonly, renew, install, register, nginx,
apache, standalone, webroot, etc.)
-h all print a detailed help page including all topics
--version print the version number
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
```bash
certbot help
```
<details>
<summary>Output:</summary>
```
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...
Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,
it will attempt to use a webserver both for obtaining and installing the
certificate. The most common SUBCOMMANDS and flags are:
obtain, install, and renew certificates:
(default) run Obtain & install a certificate in your current webserver
certonly Obtain or renew a certificate, but do not install it
renew Renew all previously obtained certificates that are near
expiry
enhance Add security enhancements to your existing configuration
-d DOMAINS Comma-separated list of domains to obtain a certificate for
(the certbot apache plugin is not installed)
--standalone Run a standalone webserver for authentication
--nginx Use the Nginx plugin for authentication & installation
--webroot Place files in a server's webroot folder for authentication
--manual Obtain certificates interactively, or using shell script
hooks
-n Run non-interactively
--test-cert Obtain a test certificate from a staging server
--dry-run Test "renew" or "certonly" without saving any certificates
to disk
manage certificates:
certificates Display information about certificates you have from Certbot
revoke Revoke a certificate (supply --cert-name or --cert-path)
delete Delete a certificate (supply --cert-name)
reconfigure Update a certificate's configuration (supply --cert-name)
manage your account:
register Create an ACME account
unregister Deactivate an ACME account
update_account Update an ACME account
show_account Display account details
--agree-tos Agree to the ACME server's Subscriber Agreement
-m EMAIL Email address for important account notifications
More detailed help:
-h, --help [TOPIC] print this message, or detailed help on a topic;
the available TOPICS are:
all, automation, commands, paths, security, testing, or any of the
subcommands or plugins (certonly, renew, install, register, nginx,
apache, standalone, webroot, etc.)
-h all print a detailed help page including all topics
--version print the version number
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:24:37 [emerg] 1725834#1725834: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
Certbot doesn't know how to automatically configure the web server on this system. However, it can still get a certificate for you. Please run "certbot certonly" to do so. You'll need to manually configure your web server to use the resulting certificate.
```bash
certbot run
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:24:37 [emerg] 1725834#1725834: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
Certbot doesn't know how to automatically configure the web server on this system. However, it can still get a certificate for you. Please run "certbot certonly" to do so. You'll need to manually configure your web server to use the resulting certificate.
```
</details>
2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem"
2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem"
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
```bash
nginx -c /etc/nginx/nginx.conf -t
```
<details>
<summary>Output:</summary>
```
2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem"
2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem"
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
```
</details>
usage:
certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...
Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,
it will attempt to use a webserver both for obtaining and installing the
certificate.
certbot: error: unrecognized arguments: overleaf.lemnoslife.com
```bash
certbot renew overleaf.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
usage:
certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...
Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,
it will attempt to use a webserver both for obtaining and installing the
certificate.
certbot: error: unrecognized arguments: overleaf.lemnoslife.com
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Currently, the renew verb is capable of either renewing all installed certificates that are due to be renewed or renewing a single certificate specified by its name. If you would like to renew specific certificates by their domains, use the certonly command instead. The renew verb may provide other options for selecting certificates to renew in the future.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash
certbot renew -d overleaf.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Currently, the renew verb is capable of either renewing all installed certificates that are due to be renewed or renewing a single certificate specified by its name. If you would like to renew specific certificates by their domains, use the certonly command instead. The renew verb may provide other options for selecting certificates to renew in the future.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed
The nginx plugin is not working; there may be problems with your existing configuration.
The error was: MisconfigurationError('Error while running nginx -c /etc/nginx/nginx.conf -t.\n\n2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)\nnginx: configuration file /etc/nginx/nginx.conf test failed\n')
```bash
mv /etc/letsencrypt/{archive/,}gitea.lemnoslife.com-0001
certbot --nginx
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running nginx -c /etc/nginx/nginx.conf -t.
2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed
The nginx plugin is not working; there may be problems with your existing configuration.
The error was: MisconfigurationError('Error while running nginx -c /etc/nginx/nginx.conf -t.\n\n2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)\nnginx: configuration file /etc/nginx/nginx.conf test failed\n')
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Which names would you like to activate HTTPS for?
We recommend selecting either all domains, or all domains in a VirtualHost/server block.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: gitea.lemnoslife.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Requesting a certificate for gitea.lemnoslife.com
An unexpected error occurred:
too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:23:31 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash
certbot --nginx
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Which names would you like to activate HTTPS for?
We recommend selecting either all domains, or all domains in a VirtualHost/server block.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: gitea.lemnoslife.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Requesting a certificate for gitea.lemnoslife.com
An unexpected error occurred:
too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:23:31 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gitea.lemnoslife.com and blog.lemnoslife.com
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: blog.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for blog.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for blog.lemnoslife.com - check that a DNS record exists for this domain
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash
certbot --nginx -d gitea.lemnoslife.com -d blog.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gitea.lemnoslife.com and blog.lemnoslife.com
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: blog.lemnoslife.com
Type: dns
Detail: DNS problem: NXDOMAIN looking up A for blog.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for blog.lemnoslife.com - check that a DNS record exists for this domain
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gitea.lemnoslife.com
An unexpected error occurred:
too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:30:10 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash
certbot --nginx -d gitea.lemnoslife.com -d gitea.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gitea.lemnoslife.com
An unexpected error occurred:
too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:30:10 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
You have an existing certificate that contains a portion of the domains you
requested (ref: /etc/letsencrypt/renewal/server0.lemnoslife.com.conf)
It contains these names: server0.lemnoslife.com
You requested these names for the new certificate: gitea.lemnoslife.com,
server0.lemnoslife.com.
Do you want to expand and replace this existing certificate with the new
certificate?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(E)xpand/(C)ancel: E
Renewing an existing certificate for gitea.lemnoslife.com and server0.lemnoslife.com
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/privkey.pem
This certificate expires on 2026-12-29.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.
Deploying certificate
Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea
Could not install certificate
NEXT STEPS:
- The certificate was saved, but could not be installed (installer: nginx). After fixing the error shown below, try installing it again by running:
certbot install --cert-name server0.lemnoslife.com
Could not automatically find a matching server block for server0.lemnoslife.com. Set the `server_name` directive to use the Nginx installer.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash
certbot --nginx -d gitea.lemnoslife.com -d server0.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
You have an existing certificate that contains a portion of the domains you
requested (ref: /etc/letsencrypt/renewal/server0.lemnoslife.com.conf)
It contains these names: server0.lemnoslife.com
You requested these names for the new certificate: gitea.lemnoslife.com,
server0.lemnoslife.com.
Do you want to expand and replace this existing certificate with the new
certificate?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(E)xpand/(C)ancel: E
Renewing an existing certificate for gitea.lemnoslife.com and server0.lemnoslife.com
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/privkey.pem
This certificate expires on 2026-12-29.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.
Deploying certificate
Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea
Could not install certificate
NEXT STEPS:
- The certificate was saved, but could not be installed (installer: nginx). After fixing the error shown below, try installing it again by running:
certbot install --cert-name server0.lemnoslife.com
Could not automatically find a matching server block for server0.lemnoslife.com. Set the `server_name` directive to use the Nginx installer.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Deploying certificate
Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea
Successfully deployed certificate for server0.lemnoslife.com to /etc/nginx/sites-enabled/server0
We were unable to install your certificate, however, we successfully restored your server to its prior configuration.
nginx restart failed:
2026/10/01 01:43:17 [emerg] 1729439#1729439: a duplicate listen 0.0.0.0:443 in /etc/nginx/sites-enabled/gitea:29
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash
ln -s /etc/nginx/sites-available/server0 server0
```
does not return anything.
```bash
certbot install --cert-name server0.lemnoslife.com
```
<details>
<summary>Output:</summary>
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Deploying certificate
Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea
Successfully deployed certificate for server0.lemnoslife.com to /etc/nginx/sites-enabled/server0
We were unable to install your certificate, however, we successfully restored your server to its prior configuration.
nginx restart failed:
2026/10/01 01:43:17 [emerg] 1729439#1729439: a duplicate listen 0.0.0.0:443 in /etc/nginx/sites-enabled/gitea:29
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```
</details>
Job for nginx.service failed because the control process exited with error code.
See "systemctl status nginx.service" and "journalctl -xeu nginx.service" for details.
root@overclock3000:/etc/nginx/sites-enabled# service nginx status | cat
× nginx.service - A high performance web server and a reverse proxy server
Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
Active: failed (Result: exit-code) since Thu 2026-10-01 01:43:52 CEST; 3s ago
Duration: 2d 8h 17min 43.911s
Invocation: c50448b06181489ab7c52034778a2128
Docs: man:nginx(8)
Process: 1729479 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS)
Process: 1729480 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=1/FAILURE)
Mem peak: 2.1M
CPU: 50ms
Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:52 overclock3000 nginx[1729480]: nginx: [emerg] still could not bind()
Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'.
Oct 01 01:43:52 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server.
```bash
service nginx restart
```
<details>
<summary>Output:</summary>
```
Job for nginx.service failed because the control process exited with error code.
See "systemctl status nginx.service" and "journalctl -xeu nginx.service" for details.
root@overclock3000:/etc/nginx/sites-enabled# service nginx status | cat
× nginx.service - A high performance web server and a reverse proxy server
Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
Active: failed (Result: exit-code) since Thu 2026-10-01 01:43:52 CEST; 3s ago
Duration: 2d 8h 17min 43.911s
Invocation: c50448b06181489ab7c52034778a2128
Docs: man:nginx(8)
Process: 1729479 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS)
Process: 1729480 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=1/FAILURE)
Mem peak: 2.1M
CPU: 50ms
Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:52 overclock3000 nginx[1729480]: nginx: [emerg] still could not bind()
Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'.
Oct 01 01:43:52 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server.
```
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
https://matrix.to/#/!sNARMdEsFZERaQAJzl:matrix.org/$1oLeNI80LdVcZmNW6mIRwHd0BaeHaIeLN0SBV4E8omY:
Output:
On Debian 13 OverClock3000:
Output:
It was unclear to me where
etesync.lemnoslife.comis involved.The Stack Overflow answer 78483090 seems to have involved more troubles than help in my case.
In
/etc/nginx/sites-enabled/:Output:
Output:
DuckDuckGo search
"SSL_ERROR_RX_RECORD_TOO_LONG" "certbot".The Server Fault answer 1113578:
It seems that indeed I forgot to add
ssltolisten.Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
The Super User answer 1432542:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
Output:
does not return anything.
Output:
Output:
Output:
Output:
does not return anything.
Above are the big steps as far as I remember, now I solved the issue.
Could restore
gitlab-omnibus-ssl-nginx.conf overleaf peertube youtube_operational_api server0.