No repair ability #14

Open
opened 2026-10-01 01:48:41 +02:00 by Benjamin_Loison · 34 comments
Owner

https://matrix.to/#/!sNARMdEsFZERaQAJzl:matrix.org/$1oLeNI80LdVcZmNW6mIRwHd0BaeHaIeLN0SBV4E8omY:

certbot --nginx-ctl /usr/sbin/nginx --force-renew renew
Output:

Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com-0001.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for v.lemnoslife.com and 6 more domains

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
  Domain: etesync.lemnoslife.com
  Type:   unauthorized
  Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/KKRD0BhRJNu4YQb0NJwfxTxwkGaJqm_mWcuWgIOxWXU: 404

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Failed to renew certificate gitea.lemnoslife.com-0001 with error: Some challenges have failed.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for crawler.yt.lemnoslife.com and 5 more domains

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
  Domain: crawler.yt.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain

  Domain: private.yt.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Failed to renew certificate gitea.lemnoslife.com with error: Some challenges have failed.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitlab.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for private.yt.lemnoslife.com and 9 more domains

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
  Domain: crawler.yt.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain

  Domain: private.yt.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain

  Domain: yt4.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain

  Domain: etesync.lemnoslife.com
  Type:   unauthorized
  Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/_68c-vc8JjgY7iJdEmNdJHZKiv02knPESeQEWqi_gQw: 404

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Failed to renew certificate gitlab.lemnoslife.com with error: Some challenges have failed.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for overleaf.lemnoslife.com
Reloading nginx server after certificate renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/pim.etesync.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for pim.etesync.lemnoslife.com
Reloading nginx server after certificate renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/private.yt.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for private.yt.lemnoslife.com and yt4.lemnoslife.com

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
  Domain: private.yt.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain

  Domain: yt4.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Failed to renew certificate private.yt.lemnoslife.com with error: Some challenges have failed.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/server0.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for server0.lemnoslife.com
Reloading nginx server after certificate renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/v.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for v.lemnoslife.com
Reloading nginx server after certificate renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/videos.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for videos.lemnoslife.com
Reloading nginx server after certificate renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The following renewals succeeded:
  /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem (success)
  /etc/letsencrypt/live/pim.etesync.lemnoslife.com/fullchain.pem (success)
  /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem (success)
  /etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem (success)
  /etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem (success)

The following renewals failed:
  /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem (failure)
  /etc/letsencrypt/live/gitea.lemnoslife.com/fullchain.pem (failure)
  /etc/letsencrypt/live/gitlab.lemnoslife.com/fullchain.pem (failure)
  /etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem (failure)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 renew failure(s), 0 parse failure(s)
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

On Debian 13 OverClock3000:

grep -rw gitea /etc/nginx/sites-enabled/
Output:
/etc/nginx/sites-enabled/server0:    ssl_certificate /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem; # managed by Certbot
/etc/nginx/sites-enabled/server0:    ssl_certificate_key /etc/letsencrypt/live/gitea.lemnoslife.com-0001/privkey.pem; # managed by Certbot
/etc/nginx/sites-enabled/.git/logs/HEAD:0000000000000000000000000000000000000000 9319f715812032b9d42d25b6463fd8cb6331116d Benjamin Loison <serveur@lemnoslife.com> 1790810365 +0200	commit (initial): Add `gitea`
/etc/nginx/sites-enabled/.git/logs/refs/heads/master:0000000000000000000000000000000000000000 9319f715812032b9d42d25b6463fd8cb6331116d Benjamin Loison <serveur@lemnoslife.com> 1790810365 +0200	commit (initial): Add `gitea`
grep: /etc/nginx/sites-enabled/.git/index: binary file matches
/etc/nginx/sites-enabled/.git/COMMIT_EDITMSG:Add `gitea`
/etc/nginx/sites-enabled/youtube_operational_api:# [Benjamin_Loison/nginx/issues/4](https://gitea.lemnoslife.com/Benjamin_Loison/nginx/issues/4)
/etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:    ssl_certificate /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem; # managed by Certbot
/etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:    ssl_certificate_key /etc/letsencrypt/live/gitea.lemnoslife.com-0001/privkey.pem; # managed by Certbot

It was unclear to me where etesync.lemnoslife.com is involved.

The Stack Overflow answer 78483090 seems to have involved more troubles than help in my case.

In /etc/nginx/sites-enabled/:

ls
gitea  gitlab-omnibus-ssl-nginx.conf  overleaf	peertube  server0  youtube_operational_api
certbot --nginx-ctl /usr/sbin/nginx certonly -d gitea.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t.

2026/10/01 01:21:59 [emerg] 1725639#1725639: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed


How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Nginx Web Server plugin (nginx) [Misconfigured]
2: Runs an HTTP server locally which serves the necessary validation files under
the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP
server already running. HTTP challenge only (wildcards not supported).
(standalone)
3: Saves the necessary validation files to a .well-known/acme-challenge/
directory within the nominated webroot path. A separate HTTP server must be
running and serving files from the webroot path. HTTP challenge only (wildcards
not supported). (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-3] then [enter] (press 'c' to cancel): 
https://matrix.to/#/!sNARMdEsFZERaQAJzl:matrix.org/$1oLeNI80LdVcZmNW6mIRwHd0BaeHaIeLN0SBV4E8omY: ```bash certbot --nginx-ctl /usr/sbin/nginx --force-renew renew ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com-0001.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for v.lemnoslife.com and 6 more domains Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: etesync.lemnoslife.com Type: unauthorized Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/KKRD0BhRJNu4YQb0NJwfxTxwkGaJqm_mWcuWgIOxWXU: 404 Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. Failed to renew certificate gitea.lemnoslife.com-0001 with error: Some challenges have failed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for crawler.yt.lemnoslife.com and 5 more domains Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: crawler.yt.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain Domain: private.yt.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. Failed to renew certificate gitea.lemnoslife.com with error: Some challenges have failed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/gitlab.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for private.yt.lemnoslife.com and 9 more domains Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: crawler.yt.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for crawler.yt.lemnoslife.com - check that a DNS record exists for this domain Domain: private.yt.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain Domain: yt4.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain Domain: etesync.lemnoslife.com Type: unauthorized Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/_68c-vc8JjgY7iJdEmNdJHZKiv02knPESeQEWqi_gQw: 404 Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. Failed to renew certificate gitlab.lemnoslife.com with error: Some challenges have failed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for overleaf.lemnoslife.com Reloading nginx server after certificate renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/pim.etesync.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for pim.etesync.lemnoslife.com Reloading nginx server after certificate renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/private.yt.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for private.yt.lemnoslife.com and yt4.lemnoslife.com Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: private.yt.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain Domain: yt4.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. Failed to renew certificate private.yt.lemnoslife.com with error: Some challenges have failed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/server0.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for server0.lemnoslife.com Reloading nginx server after certificate renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/v.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for v.lemnoslife.com Reloading nginx server after certificate renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/videos.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for videos.lemnoslife.com Reloading nginx server after certificate renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - The following renewals succeeded: /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem (success) /etc/letsencrypt/live/pim.etesync.lemnoslife.com/fullchain.pem (success) /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem (success) /etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem (success) /etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem (success) The following renewals failed: /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem (failure) /etc/letsencrypt/live/gitea.lemnoslife.com/fullchain.pem (failure) /etc/letsencrypt/live/gitlab.lemnoslife.com/fullchain.pem (failure) /etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem (failure) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 4 renew failure(s), 0 parse failure(s) Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details> On Debian 13 OverClock3000: ```bash grep -rw gitea /etc/nginx/sites-enabled/ ``` <details> <summary>Output:</summary> ``` /etc/nginx/sites-enabled/server0: ssl_certificate /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem; # managed by Certbot /etc/nginx/sites-enabled/server0: ssl_certificate_key /etc/letsencrypt/live/gitea.lemnoslife.com-0001/privkey.pem; # managed by Certbot /etc/nginx/sites-enabled/.git/logs/HEAD:0000000000000000000000000000000000000000 9319f715812032b9d42d25b6463fd8cb6331116d Benjamin Loison <serveur@lemnoslife.com> 1790810365 +0200 commit (initial): Add `gitea` /etc/nginx/sites-enabled/.git/logs/refs/heads/master:0000000000000000000000000000000000000000 9319f715812032b9d42d25b6463fd8cb6331116d Benjamin Loison <serveur@lemnoslife.com> 1790810365 +0200 commit (initial): Add `gitea` grep: /etc/nginx/sites-enabled/.git/index: binary file matches /etc/nginx/sites-enabled/.git/COMMIT_EDITMSG:Add `gitea` /etc/nginx/sites-enabled/youtube_operational_api:# [Benjamin_Loison/nginx/issues/4](https://gitea.lemnoslife.com/Benjamin_Loison/nginx/issues/4) /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf: ssl_certificate /etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem; # managed by Certbot /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf: ssl_certificate_key /etc/letsencrypt/live/gitea.lemnoslife.com-0001/privkey.pem; # managed by Certbot ``` </details> It was unclear to me where `etesync.lemnoslife.com` is involved. [The Stack Overflow answer 78483090](https://stackoverflow.com/a/78483090) seems to have involved more troubles than help in my case. In `/etc/nginx/sites-enabled/`: ```bash ls ``` ``` gitea gitlab-omnibus-ssl-nginx.conf overleaf peertube server0 youtube_operational_api ``` ```bash certbot --nginx-ctl /usr/sbin/nginx certonly -d gitea.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t. 2026/10/01 01:21:59 [emerg] 1725639#1725639: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file) nginx: configuration file /etc/nginx/nginx.conf test failed How would you like to authenticate with the ACME CA? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: Nginx Web Server plugin (nginx) [Misconfigured] 2: Runs an HTTP server locally which serves the necessary validation files under the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP server already running. HTTP challenge only (wildcards not supported). (standalone) 3: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported). (webroot) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-3] then [enter] (press 'c' to cancel): ``` </details>
Author
Owner
nginx -c /etc/nginx/nginx.conf -t
Output:
2026/10/01 01:22:11 [emerg] 1725667#1725667: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed
```bash nginx -c /etc/nginx/nginx.conf -t ``` <details> <summary>Output:</summary> ``` 2026/10/01 01:22:11 [emerg] 1725667#1725667: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file) nginx: configuration file /etc/nginx/nginx.conf test failed ``` </details>
Author
Owner

image.png

SSL_ERROR_RX_RECORD_TOO_LONG

![image.png](attachments/28234617-77c6-44c1-975f-1af09fd3900b) > SSL_ERROR_RX_RECORD_TOO_LONG
197 KiB
Author
Owner

DuckDuckGo search "SSL_ERROR_RX_RECORD_TOO_LONG" "certbot".

The Server Fault answer 1113578:

It seems that indeed I forgot to add ssl to listen.

DuckDuckGo search `"SSL_ERROR_RX_RECORD_TOO_LONG" "certbot"`. [The Server Fault answer 1113578](https://serverfault.com/a/1113578): It seems that indeed I forgot to add `ssl` to `listen`.
Author
Owner
sudo service nginx status
Output:
× nginx.service - A high performance web server and a reverse proxy server
     Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
     Active: failed (Result: exit-code) since Thu 2026-10-01 01:22:25 CEST; 5s ago
   Duration: 2d 8h 17min 43.911s
 Invocation: 3456f273bd374118965bf9f8678f0b06
       Docs: man:nginx(8)
    Process: 1725679 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=1/FAILURE)
   Mem peak: 2.7M
        CPU: 16ms

Oct 01 01:22:25 overclock3000 systemd[1]: Starting nginx.service - A high performance web server and a reverse proxy server...
Oct 01 01:22:25 overclock3000 nginx[1725679]: 2026/10/01 01:22:25 [emerg] 1725679#1725679: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
Oct 01 01:22:25 overclock3000 nginx[1725679]: nginx: configuration file /etc/nginx/nginx.conf test failed
Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'.
Oct 01 01:22:25 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server.
```bash sudo service nginx status ``` <details> <summary>Output:</summary> ``` × nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled) Active: failed (Result: exit-code) since Thu 2026-10-01 01:22:25 CEST; 5s ago Duration: 2d 8h 17min 43.911s Invocation: 3456f273bd374118965bf9f8678f0b06 Docs: man:nginx(8) Process: 1725679 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=1/FAILURE) Mem peak: 2.7M CPU: 16ms Oct 01 01:22:25 overclock3000 systemd[1]: Starting nginx.service - A high performance web server and a reverse proxy server... Oct 01 01:22:25 overclock3000 nginx[1725679]: 2026/10/01 01:22:25 [emerg] 1725679#1725679: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file) Oct 01 01:22:25 overclock3000 nginx[1725679]: nginx: configuration file /etc/nginx/nginx.conf test failed Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE Oct 01 01:22:25 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'. Oct 01 01:22:25 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server. ``` </details>
Author
Owner
certbot --nginx-ctl /usr/sbin/nginx certonly -d gitea.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t.

2026/10/01 01:23:58 [emerg] 1725789#1725789: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed


How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Nginx Web Server plugin (nginx) [Misconfigured]
2: Runs an HTTP server locally which serves the necessary validation files under
the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP
server already running. HTTP challenge only (wildcards not supported).
(standalone)
3: Saves the necessary validation files to a .well-known/acme-challenge/
directory within the nominated webroot path. A separate HTTP server must be
running and serving files from the webroot path. HTTP challenge only (wildcards
not supported). (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-3] then [enter] (press 'c' to cancel): 
```bash certbot --nginx-ctl /usr/sbin/nginx certonly -d gitea.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Error while running /usr/sbin/nginx -c /etc/nginx/nginx.conf -t. 2026/10/01 01:23:58 [emerg] 1725789#1725789: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53 nginx: configuration file /etc/nginx/nginx.conf test failed How would you like to authenticate with the ACME CA? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: Nginx Web Server plugin (nginx) [Misconfigured] 2: Runs an HTTP server locally which serves the necessary validation files under the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP server already running. HTTP challenge only (wildcards not supported). (standalone) 3: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported). (webroot) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-3] then [enter] (press 'c' to cancel): ``` </details>
Author
Owner
nginx -c /etc/nginx/nginx.conf -t
Output:
2026/10/01 01:23:49 [emerg] 1725786#1725786: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed
```bash nginx -c /etc/nginx/nginx.conf -t ``` <details> <summary>Output:</summary> ``` 2026/10/01 01:23:49 [emerg] 1725786#1725786: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53 nginx: configuration file /etc/nginx/nginx.conf test failed ``` </details>
Author
Owner
certbot help
Output:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...

Certbot can obtain and install HTTPS/TLS/SSL certificates.  By default,
it will attempt to use a webserver both for obtaining and installing the
certificate. The most common SUBCOMMANDS and flags are:

obtain, install, and renew certificates:
    (default) run   Obtain & install a certificate in your current webserver
    certonly        Obtain or renew a certificate, but do not install it
    renew           Renew all previously obtained certificates that are near
expiry
    enhance         Add security enhancements to your existing configuration
   -d DOMAINS       Comma-separated list of domains to obtain a certificate for

  (the certbot apache plugin is not installed)
  --standalone      Run a standalone webserver for authentication
  --nginx           Use the Nginx plugin for authentication & installation
  --webroot         Place files in a server's webroot folder for authentication
  --manual          Obtain certificates interactively, or using shell script
hooks

   -n               Run non-interactively
  --test-cert       Obtain a test certificate from a staging server
  --dry-run         Test "renew" or "certonly" without saving any certificates
to disk

manage certificates:
    certificates    Display information about certificates you have from Certbot
    revoke          Revoke a certificate (supply --cert-name or --cert-path)
    delete          Delete a certificate (supply --cert-name)
    reconfigure     Update a certificate's configuration (supply --cert-name)

manage your account:
    register        Create an ACME account
    unregister      Deactivate an ACME account
    update_account  Update an ACME account
    show_account    Display account details
  --agree-tos       Agree to the ACME server's Subscriber Agreement
   -m EMAIL         Email address for important account notifications

More detailed help:

  -h, --help [TOPIC]    print this message, or detailed help on a topic;
                        the available TOPICS are:

   all, automation, commands, paths, security, testing, or any of the
   subcommands or plugins (certonly, renew, install, register, nginx,
   apache, standalone, webroot, etc.)
  -h all                print a detailed help page including all topics
  --version             print the version number
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
```bash certbot help ``` <details> <summary>Output:</summary> ``` - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ... Certbot can obtain and install HTTPS/TLS/SSL certificates. By default, it will attempt to use a webserver both for obtaining and installing the certificate. The most common SUBCOMMANDS and flags are: obtain, install, and renew certificates: (default) run Obtain & install a certificate in your current webserver certonly Obtain or renew a certificate, but do not install it renew Renew all previously obtained certificates that are near expiry enhance Add security enhancements to your existing configuration -d DOMAINS Comma-separated list of domains to obtain a certificate for (the certbot apache plugin is not installed) --standalone Run a standalone webserver for authentication --nginx Use the Nginx plugin for authentication & installation --webroot Place files in a server's webroot folder for authentication --manual Obtain certificates interactively, or using shell script hooks -n Run non-interactively --test-cert Obtain a test certificate from a staging server --dry-run Test "renew" or "certonly" without saving any certificates to disk manage certificates: certificates Display information about certificates you have from Certbot revoke Revoke a certificate (supply --cert-name or --cert-path) delete Delete a certificate (supply --cert-name) reconfigure Update a certificate's configuration (supply --cert-name) manage your account: register Create an ACME account unregister Deactivate an ACME account update_account Update an ACME account show_account Display account details --agree-tos Agree to the ACME server's Subscriber Agreement -m EMAIL Email address for important account notifications More detailed help: -h, --help [TOPIC] print this message, or detailed help on a topic; the available TOPICS are: all, automation, commands, paths, security, testing, or any of the subcommands or plugins (certonly, renew, install, register, nginx, apache, standalone, webroot, etc.) -h all print a detailed help page including all topics --version print the version number - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ``` </details>
Author
Owner
certbot run
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running nginx -c /etc/nginx/nginx.conf -t.

2026/10/01 01:24:37 [emerg] 1725834#1725834: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53
nginx: configuration file /etc/nginx/nginx.conf test failed

Certbot doesn't know how to automatically configure the web server on this system. However, it can still get a certificate for you. Please run "certbot certonly" to do so. You'll need to manually configure your web server to use the resulting certificate.
```bash certbot run ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Error while running nginx -c /etc/nginx/nginx.conf -t. 2026/10/01 01:24:37 [emerg] 1725834#1725834: no "ssl_certificate" is defined for the "listen ... ssl" directive in /etc/nginx/sites-enabled/gitlab-omnibus-ssl-nginx.conf:53 nginx: configuration file /etc/nginx/nginx.conf test failed Certbot doesn't know how to automatically configure the web server on this system. However, it can still get a certificate for you. Please run "certbot certonly" to do so. You'll need to manually configure your web server to use the resulting certificate. ``` </details>
Author
Owner
ls -lh
Output:
total 16K
lrwxrwxrwx 1 root root   32 Apr 10  2024 gitea -> /etc/nginx/sites-available/gitea
-rw-r--r-- 1 root root 5.0K Oct  1 01:21 gitlab-omnibus-ssl-nginx.conf
lrwxrwxrwx 1 root root   35 Apr 10  2024 overleaf -> /etc/nginx/sites-available/overleaf
lrwxrwxrwx 1 root root   35 Mar 25  2024 peertube -> /etc/nginx/sites-available/peertube
-rw-r--r-- 1 root root 1.5K Oct  1 01:21 server0
-rw-r--r-- 1 root root 1.5K Aug 14  2025 youtube_operational_api
```bash ls -lh ``` <details> <summary>Output:</summary> ``` total 16K lrwxrwxrwx 1 root root 32 Apr 10 2024 gitea -> /etc/nginx/sites-available/gitea -rw-r--r-- 1 root root 5.0K Oct 1 01:21 gitlab-omnibus-ssl-nginx.conf lrwxrwxrwx 1 root root 35 Apr 10 2024 overleaf -> /etc/nginx/sites-available/overleaf lrwxrwxrwx 1 root root 35 Mar 25 2024 peertube -> /etc/nginx/sites-available/peertube -rw-r--r-- 1 root root 1.5K Oct 1 01:21 server0 -rw-r--r-- 1 root root 1.5K Aug 14 2025 youtube_operational_api ``` </details>
Author
Owner
ls -lh
Output:
total 16K
lrwxrwxrwx 1 root root   32 Apr 10  2024 gitea -> /etc/nginx/sites-available/gitea
-rw-r--r-- 1 root root 5.0K Oct  1 01:21 gitlab-omnibus-ssl-nginx.conf
lrwxrwxrwx 1 root root   35 Apr 10  2024 overleaf -> /etc/nginx/sites-available/overleaf
lrwxrwxrwx 1 root root   35 Mar 25  2024 peertube -> /etc/nginx/sites-available/peertube
-rw-r--r-- 1 root root 1.5K Oct  1 01:21 server0
-rw-r--r-- 1 root root 1.5K Aug 14  2025 youtube_operational_api
ls /etc/letsencrypt/
accounts  archive  archive_old	cli.ini  csr  keys  live  live_old  options-ssl-apache.conf  options-ssl-nginx.conf  renewal  renewal-hooks  ssl-dhparams.pem
```bash ls -lh ``` <details> <summary>Output:</summary> ``` total 16K lrwxrwxrwx 1 root root 32 Apr 10 2024 gitea -> /etc/nginx/sites-available/gitea -rw-r--r-- 1 root root 5.0K Oct 1 01:21 gitlab-omnibus-ssl-nginx.conf lrwxrwxrwx 1 root root 35 Apr 10 2024 overleaf -> /etc/nginx/sites-available/overleaf lrwxrwxrwx 1 root root 35 Mar 25 2024 peertube -> /etc/nginx/sites-available/peertube -rw-r--r-- 1 root root 1.5K Oct 1 01:21 server0 -rw-r--r-- 1 root root 1.5K Aug 14 2025 youtube_operational_api ``` </details> ```bash ls /etc/letsencrypt/ ``` ``` accounts archive archive_old cli.ini csr keys live live_old options-ssl-apache.conf options-ssl-nginx.conf renewal renewal-hooks ssl-dhparams.pem ```
Author
Owner
nginx -c /etc/nginx/nginx.conf -t
Output:
2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem"
2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem"
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
```bash nginx -c /etc/nginx/nginx.conf -t ``` <details> <summary>Output:</summary> ``` 2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem" 2026/10/01 01:27:52 [warn] 1726046#1726046: "ssl_stapling" ignored, no OCSP responder URL in the certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem" nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` </details>
Author
Owner
certbot install
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Which certificate would you like to install?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: overleaf.lemnoslife.com
2: private.yt.lemnoslife.com
3: server0.lemnoslife.com
4: v.lemnoslife.com
5: videos.lemnoslife.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-5] then [enter] (press 'c' to cancel): 
```bash certbot install ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Which certificate would you like to install? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: overleaf.lemnoslife.com 2: private.yt.lemnoslife.com 3: server0.lemnoslife.com 4: v.lemnoslife.com 5: videos.lemnoslife.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-5] then [enter] (press 'c' to cancel): ``` </details>
Author
Owner
certbot install -d gitea.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Which certificate would you like to install?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: overleaf.lemnoslife.com
2: private.yt.lemnoslife.com
3: server0.lemnoslife.com
4: v.lemnoslife.com
5: videos.lemnoslife.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-5] then [enter] (press 'c' to cancel): 
```bash certbot install -d gitea.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Which certificate would you like to install? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: overleaf.lemnoslife.com 2: private.yt.lemnoslife.com 3: server0.lemnoslife.com 4: v.lemnoslife.com 5: videos.lemnoslife.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-5] then [enter] (press 'c' to cancel): ``` </details>
Author
Owner
certbot renew
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate not yet due for renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/private.yt.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for private.yt.lemnoslife.com and yt4.lemnoslife.com

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
  Domain: private.yt.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain

  Domain: yt4.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Failed to renew certificate private.yt.lemnoslife.com with error: Some challenges have failed.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/server0.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate not yet due for renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/v.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate not yet due for renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/videos.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate not yet due for renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The following certificates are not due for renewal yet:
  /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped)
  /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped)
  /etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped)
  /etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped)
All renewals failed. The following certificates could not be renewed:
  /etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem (failure)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1 renew failure(s), 0 parse failure(s)
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot renew ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/private.yt.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for private.yt.lemnoslife.com and yt4.lemnoslife.com Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: private.yt.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for private.yt.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for private.yt.lemnoslife.com - check that a DNS record exists for this domain Domain: yt4.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for yt4.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for yt4.lemnoslife.com - check that a DNS record exists for this domain Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. Failed to renew certificate private.yt.lemnoslife.com with error: Some challenges have failed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/server0.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/v.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/videos.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - The following certificates are not due for renewal yet: /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped) /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped) /etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped) /etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped) All renewals failed. The following certificates could not be renewed: /etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem (failure) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1 renew failure(s), 0 parse failure(s) Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner

The Super User answer 1432542:

sudo certbot certificates
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Found the following certs:
  Certificate Name: overleaf.lemnoslife.com
    Serial Number: 500a167fc0988edc6ff5fea97edd5079dc8
    Key Type: ECDSA
    Domains: v.lemnoslife.com gitea.lemnoslife.com overleaf.lemnoslife.com server0.lemnoslife.com videos.lemnoslife.com
    Expiry Date: 2026-12-29 22:12:45+00:00 (VALID: 89 days)
    Certificate Path: /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/overleaf.lemnoslife.com/privkey.pem
  Certificate Name: private.yt.lemnoslife.com
    Serial Number: 404ff5a4140f1353148b03619761ec44b6c
    Key Type: ECDSA
    Domains: private.yt.lemnoslife.com yt4.lemnoslife.com
    Expiry Date: 2024-12-27 01:22:07+00:00 (INVALID: EXPIRED)
    Certificate Path: /etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/private.yt.lemnoslife.com/privkey.pem
  Certificate Name: server0.lemnoslife.com
    Serial Number: 6af1566df3baf57524d2f29f99bbcf6e8f9
    Key Type: ECDSA
    Domains: server0.lemnoslife.com
    Expiry Date: 2026-12-29 21:50:55+00:00 (VALID: 89 days)
    Certificate Path: /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/server0.lemnoslife.com/privkey.pem
  Certificate Name: v.lemnoslife.com
    Serial Number: 6209775b16f2366b277c57b45b5d2002be2
    Key Type: ECDSA
    Domains: v.lemnoslife.com
    Expiry Date: 2026-12-29 21:51:04+00:00 (VALID: 89 days)
    Certificate Path: /etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/v.lemnoslife.com/privkey.pem
  Certificate Name: videos.lemnoslife.com
    Serial Number: 5d01bf81fd1df7f369d01002cb62fe63e97
    Key Type: ECDSA
    Domains: videos.lemnoslife.com
    Expiry Date: 2026-12-29 21:51:10+00:00 (VALID: 89 days)
    Certificate Path: /etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/videos.lemnoslife.com/privkey.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
[The Super User answer 1432542](https://superuser.com/a/1432542): ```bash sudo certbot certificates ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Found the following certs: Certificate Name: overleaf.lemnoslife.com Serial Number: 500a167fc0988edc6ff5fea97edd5079dc8 Key Type: ECDSA Domains: v.lemnoslife.com gitea.lemnoslife.com overleaf.lemnoslife.com server0.lemnoslife.com videos.lemnoslife.com Expiry Date: 2026-12-29 22:12:45+00:00 (VALID: 89 days) Certificate Path: /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem Private Key Path: /etc/letsencrypt/live/overleaf.lemnoslife.com/privkey.pem Certificate Name: private.yt.lemnoslife.com Serial Number: 404ff5a4140f1353148b03619761ec44b6c Key Type: ECDSA Domains: private.yt.lemnoslife.com yt4.lemnoslife.com Expiry Date: 2024-12-27 01:22:07+00:00 (INVALID: EXPIRED) Certificate Path: /etc/letsencrypt/live/private.yt.lemnoslife.com/fullchain.pem Private Key Path: /etc/letsencrypt/live/private.yt.lemnoslife.com/privkey.pem Certificate Name: server0.lemnoslife.com Serial Number: 6af1566df3baf57524d2f29f99bbcf6e8f9 Key Type: ECDSA Domains: server0.lemnoslife.com Expiry Date: 2026-12-29 21:50:55+00:00 (VALID: 89 days) Certificate Path: /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem Private Key Path: /etc/letsencrypt/live/server0.lemnoslife.com/privkey.pem Certificate Name: v.lemnoslife.com Serial Number: 6209775b16f2366b277c57b45b5d2002be2 Key Type: ECDSA Domains: v.lemnoslife.com Expiry Date: 2026-12-29 21:51:04+00:00 (VALID: 89 days) Certificate Path: /etc/letsencrypt/live/v.lemnoslife.com/fullchain.pem Private Key Path: /etc/letsencrypt/live/v.lemnoslife.com/privkey.pem Certificate Name: videos.lemnoslife.com Serial Number: 5d01bf81fd1df7f369d01002cb62fe63e97 Key Type: ECDSA Domains: videos.lemnoslife.com Expiry Date: 2026-12-29 21:51:10+00:00 (VALID: 89 days) Certificate Path: /etc/letsencrypt/live/videos.lemnoslife.com/fullchain.pem Private Key Path: /etc/letsencrypt/live/videos.lemnoslife.com/privkey.pem - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ``` </details>
Author
Owner
certbot renew overleaf.lemnoslife.com
Output:
usage: 
  certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...

Certbot can obtain and install HTTPS/TLS/SSL certificates.  By default,
it will attempt to use a webserver both for obtaining and installing the
certificate. 
certbot: error: unrecognized arguments: overleaf.lemnoslife.com
```bash certbot renew overleaf.lemnoslife.com ``` <details> <summary>Output:</summary> ``` usage: certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ... Certbot can obtain and install HTTPS/TLS/SSL certificates. By default, it will attempt to use a webserver both for obtaining and installing the certificate. certbot: error: unrecognized arguments: overleaf.lemnoslife.com ``` </details>
Author
Owner
certbot renew -d overleaf.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Currently, the renew verb is capable of either renewing all installed certificates that are due to be renewed or renewing a single certificate specified by its name. If you would like to renew specific certificates by their domains, use the certonly command instead. The renew verb may provide other options for selecting certificates to renew in the future.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot renew -d overleaf.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Currently, the renew verb is capable of either renewing all installed certificates that are due to be renewed or renewing a single certificate specified by its name. If you would like to renew specific certificates by their domains, use the certonly command instead. The renew verb may provide other options for selecting certificates to renew in the future. Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
certbot renew --cert-name overleaf.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Certificate not yet due for renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The following certificates are not due for renewal yet:
  /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped)
No renewals were attempted.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
```bash certbot renew --cert-name overleaf.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - The following certificates are not due for renewal yet: /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem expires on 2026-12-29 (skipped) No renewals were attempted. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ``` </details>
Author
Owner
certbot renew --force-renew --cert-name overleaf.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for v.lemnoslife.com and 4 more domains
Reloading nginx server after certificate renewal

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations, all renewals succeeded: 
  /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem (success)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
```bash certbot renew --force-renew --cert-name overleaf.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /etc/letsencrypt/renewal/overleaf.lemnoslife.com.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Renewing an existing certificate for v.lemnoslife.com and 4 more domains Reloading nginx server after certificate renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Congratulations, all renewals succeeded: /etc/letsencrypt/live/overleaf.lemnoslife.com/fullchain.pem (success) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ``` </details>
Author
Owner
certbot --nginx
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Which names would you like to activate HTTPS for?
We recommend selecting either all domains, or all domains in a VirtualHost/server block.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: gitea.lemnoslife.com
2: gitlab.lemnoslife.com
3: overleaf.lemnoslife.com
4: server0.lemnoslife.com
5: v.lemnoslife.com
6: videos.lemnoslife.com
7: private.yt.lemnoslife.com
8: youtube.local
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Requesting a certificate for gitea.lemnoslife.com
archive directory exists for gitea.lemnoslife.com
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot --nginx ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Which names would you like to activate HTTPS for? We recommend selecting either all domains, or all domains in a VirtualHost/server block. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: gitea.lemnoslife.com 2: gitlab.lemnoslife.com 3: overleaf.lemnoslife.com 4: server0.lemnoslife.com 5: v.lemnoslife.com 6: videos.lemnoslife.com 7: private.yt.lemnoslife.com 8: youtube.local - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate numbers separated by commas and/or spaces, or leave input blank to select all options shown (Enter 'c' to cancel): 1 Requesting a certificate for gitea.lemnoslife.com archive directory exists for gitea.lemnoslife.com Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
mv /etc/letsencrypt/{archive/,}gitea.lemnoslife.com
certbot --nginx
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Which names would you like to activate HTTPS for?
We recommend selecting either all domains, or all domains in a VirtualHost/server block.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: gitea.lemnoslife.com
2: gitlab.lemnoslife.com
3: overleaf.lemnoslife.com
4: server0.lemnoslife.com
5: v.lemnoslife.com
6: videos.lemnoslife.com
7: private.yt.lemnoslife.com
8: youtube.local
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Requesting a certificate for gitea.lemnoslife.com
archive directory exists for gitea.lemnoslife.com-0001
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash mv /etc/letsencrypt/{archive/,}gitea.lemnoslife.com certbot --nginx ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Which names would you like to activate HTTPS for? We recommend selecting either all domains, or all domains in a VirtualHost/server block. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: gitea.lemnoslife.com 2: gitlab.lemnoslife.com 3: overleaf.lemnoslife.com 4: server0.lemnoslife.com 5: v.lemnoslife.com 6: videos.lemnoslife.com 7: private.yt.lemnoslife.com 8: youtube.local - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate numbers separated by commas and/or spaces, or leave input blank to select all options shown (Enter 'c' to cancel): 1 Requesting a certificate for gitea.lemnoslife.com archive directory exists for gitea.lemnoslife.com-0001 Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
mv /etc/letsencrypt/{archive/,}gitea.lemnoslife.com-0001
certbot --nginx
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Error while running nginx -c /etc/nginx/nginx.conf -t.

2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)
nginx: configuration file /etc/nginx/nginx.conf test failed

The nginx plugin is not working; there may be problems with your existing configuration.
The error was: MisconfigurationError('Error while running nginx -c /etc/nginx/nginx.conf -t.\n\n2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)\nnginx: configuration file /etc/nginx/nginx.conf test failed\n')
```bash mv /etc/letsencrypt/{archive/,}gitea.lemnoslife.com-0001 certbot --nginx ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Error while running nginx -c /etc/nginx/nginx.conf -t. 2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file) nginx: configuration file /etc/nginx/nginx.conf test failed The nginx plugin is not working; there may be problems with your existing configuration. The error was: MisconfigurationError('Error while running nginx -c /etc/nginx/nginx.conf -t.\n\n2026/10/01 01:35:09 [emerg] 1728871#1728871: cannot load certificate "/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem": BIO_new_file() failed (SSL: error:80000002:system library::No such file or directory:calling fopen(/etc/letsencrypt/live/gitea.lemnoslife.com-0001/fullchain.pem, r) error:10000080:BIO routines::no such file)\nnginx: configuration file /etc/nginx/nginx.conf test failed\n') ``` </details>
Author
Owner
nginx -c /etc/nginx/nginx.conf -t
Output:
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
```bash nginx -c /etc/nginx/nginx.conf -t ``` <details> <summary>Output:</summary> ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` </details>
Author
Owner
certbot --nginx
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Which names would you like to activate HTTPS for?
We recommend selecting either all domains, or all domains in a VirtualHost/server block.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: gitea.lemnoslife.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Requesting a certificate for gitea.lemnoslife.com
An unexpected error occurred:
too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:23:31 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot --nginx ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Which names would you like to activate HTTPS for? We recommend selecting either all domains, or all domains in a VirtualHost/server block. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: gitea.lemnoslife.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate numbers separated by commas and/or spaces, or leave input blank to select all options shown (Enter 'c' to cancel): 1 Requesting a certificate for gitea.lemnoslife.com An unexpected error occurred: too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:23:31 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
certbot --nginx -d gitea.lemnoslife.com -d blog.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gitea.lemnoslife.com and blog.lemnoslife.com

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
  Domain: blog.lemnoslife.com
  Type:   dns
  Detail: DNS problem: NXDOMAIN looking up A for blog.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for blog.lemnoslife.com - check that a DNS record exists for this domain

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot --nginx -d gitea.lemnoslife.com -d blog.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Requesting a certificate for gitea.lemnoslife.com and blog.lemnoslife.com Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems: Domain: blog.lemnoslife.com Type: dns Detail: DNS problem: NXDOMAIN looking up A for blog.lemnoslife.com - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for blog.lemnoslife.com - check that a DNS record exists for this domain Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet. Some challenges have failed. Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
certbot --nginx -d gitea.lemnoslife.com -d gitea.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for gitea.lemnoslife.com
An unexpected error occurred:
too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:30:10 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot --nginx -d gitea.lemnoslife.com -d gitea.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Requesting a certificate for gitea.lemnoslife.com An unexpected error occurred: too many certificates (5) already issued for this exact set of identifiers in the last 168h0m0s, retry after 2026-10-02 09:30:10 UTC: see https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
certbot --nginx -d gitea.lemnoslife.com -d server0.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
You have an existing certificate that contains a portion of the domains you
requested (ref: /etc/letsencrypt/renewal/server0.lemnoslife.com.conf)

It contains these names: server0.lemnoslife.com

You requested these names for the new certificate: gitea.lemnoslife.com,
server0.lemnoslife.com.

Do you want to expand and replace this existing certificate with the new
certificate?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(E)xpand/(C)ancel: E
Renewing an existing certificate for gitea.lemnoslife.com and server0.lemnoslife.com

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/server0.lemnoslife.com/privkey.pem
This certificate expires on 2026-12-29.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.

Deploying certificate
Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea
Could not install certificate

NEXT STEPS:
- The certificate was saved, but could not be installed (installer: nginx). After fixing the error shown below, try installing it again by running:
  certbot install --cert-name server0.lemnoslife.com

Could not automatically find a matching server block for server0.lemnoslife.com. Set the `server_name` directive to use the Nginx installer.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash certbot --nginx -d gitea.lemnoslife.com -d server0.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - You have an existing certificate that contains a portion of the domains you requested (ref: /etc/letsencrypt/renewal/server0.lemnoslife.com.conf) It contains these names: server0.lemnoslife.com You requested these names for the new certificate: gitea.lemnoslife.com, server0.lemnoslife.com. Do you want to expand and replace this existing certificate with the new certificate? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (E)xpand/(C)ancel: E Renewing an existing certificate for gitea.lemnoslife.com and server0.lemnoslife.com Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/fullchain.pem Key is saved at: /etc/letsencrypt/live/server0.lemnoslife.com/privkey.pem This certificate expires on 2026-12-29. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background. Deploying certificate Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea Could not install certificate NEXT STEPS: - The certificate was saved, but could not be installed (installer: nginx). After fixing the error shown below, try installing it again by running: certbot install --cert-name server0.lemnoslife.com Could not automatically find a matching server block for server0.lemnoslife.com. Set the `server_name` directive to use the Nginx installer. Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
ln -s /etc/nginx/sites-available/server0 server0

does not return anything.

certbot install --cert-name server0.lemnoslife.com
Output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Deploying certificate
Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea
Successfully deployed certificate for server0.lemnoslife.com to /etc/nginx/sites-enabled/server0
We were unable to install your certificate, however, we successfully restored your server to its prior configuration.
nginx restart failed:
2026/10/01 01:43:17 [emerg] 1729439#1729439: a duplicate listen 0.0.0.0:443 in /etc/nginx/sites-enabled/gitea:29

Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
```bash ln -s /etc/nginx/sites-available/server0 server0 ``` does not return anything. ```bash certbot install --cert-name server0.lemnoslife.com ``` <details> <summary>Output:</summary> ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Deploying certificate Successfully deployed certificate for gitea.lemnoslife.com to /etc/nginx/sites-enabled/gitea Successfully deployed certificate for server0.lemnoslife.com to /etc/nginx/sites-enabled/server0 We were unable to install your certificate, however, we successfully restored your server to its prior configuration. nginx restart failed: 2026/10/01 01:43:17 [emerg] 1729439#1729439: a duplicate listen 0.0.0.0:443 in /etc/nginx/sites-enabled/gitea:29 Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. ``` </details>
Author
Owner
service nginx restart
Output:
Job for nginx.service failed because the control process exited with error code.
See "systemctl status nginx.service" and "journalctl -xeu nginx.service" for details.
root@overclock3000:/etc/nginx/sites-enabled# service nginx status | cat
× nginx.service - A high performance web server and a reverse proxy server
     Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
     Active: failed (Result: exit-code) since Thu 2026-10-01 01:43:52 CEST; 3s ago
   Duration: 2d 8h 17min 43.911s
 Invocation: c50448b06181489ab7c52034778a2128
       Docs: man:nginx(8)
    Process: 1729479 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS)
    Process: 1729480 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=1/FAILURE)
   Mem peak: 2.1M
        CPU: 50ms

Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use)
Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use)
Oct 01 01:43:52 overclock3000 nginx[1729480]: nginx: [emerg] still could not bind()
Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'.
Oct 01 01:43:52 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server.
```bash service nginx restart ``` <details> <summary>Output:</summary> ``` Job for nginx.service failed because the control process exited with error code. See "systemctl status nginx.service" and "journalctl -xeu nginx.service" for details. root@overclock3000:/etc/nginx/sites-enabled# service nginx status | cat × nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled) Active: failed (Result: exit-code) since Thu 2026-10-01 01:43:52 CEST; 3s ago Duration: 2d 8h 17min 43.911s Invocation: c50448b06181489ab7c52034778a2128 Docs: man:nginx(8) Process: 1729479 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS) Process: 1729480 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=1/FAILURE) Mem peak: 2.1M CPU: 50ms Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use) Oct 01 01:43:50 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use) Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use) Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use) Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address already in use) Oct 01 01:43:51 overclock3000 nginx[1729480]: nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address already in use) Oct 01 01:43:52 overclock3000 nginx[1729480]: nginx: [emerg] still could not bind() Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE Oct 01 01:43:52 overclock3000 systemd[1]: nginx.service: Failed with result 'exit-code'. Oct 01 01:43:52 overclock3000 systemd[1]: Failed to start nginx.service - A high performance web server and a reverse proxy server. ``` </details>
Author
Owner
netstat -tulpn | grep 80
Output:
tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      1726097/nginx: mast 
udp6       0      0 fe80::XXXX:XXXX:XXX:XX6 :::*                                1633/NetworkManager 
udp6       0      0 fe80::YYYY:YYYY:YYY:YY3 :::*                                1728/ntpd
```bash netstat -tulpn | grep 80 ``` <details> <summary>Output:</summary> ``` tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 1726097/nginx: mast udp6 0 0 fe80::XXXX:XXXX:XXX:XX6 :::* 1633/NetworkManager udp6 0 0 fe80::YYYY:YYYY:YYY:YY3 :::* 1728/ntpd ``` </details>
Author
Owner
killall nginx
netstat -tulpn | grep 80
Output:
udp6       0      0 fe80::XXXX:XXXX:XXX:XX6 :::*                                1633/NetworkManager 
udp6       0      0 fe80::YYYY:YYYY:YYY:YY3 :::*                                1728/ntpd
```bash killall nginx netstat -tulpn | grep 80 ``` <details> <summary>Output:</summary> ``` udp6 0 0 fe80::XXXX:XXXX:XXX:XX6 :::* 1633/NetworkManager udp6 0 0 fe80::YYYY:YYYY:YYY:YY3 :::* 1728/ntpd ``` </details>
Author
Owner
service nginx restart

does not return anything.

```bash service nginx restart ``` does not return anything.
Author
Owner

Above are the big steps as far as I remember, now I solved the issue.

Above are the big steps as far as I remember, now I solved the issue.
Author
Owner

Could restore gitlab-omnibus-ssl-nginx.conf overleaf peertube youtube_operational_api server0.

Could restore `gitlab-omnibus-ssl-nginx.conf overleaf peertube youtube_operational_api server0`.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Benjamin_Loison/certbot#14