Hallo,
ich habe, wie in Docker KISS + linuxmuster-mrbs beschrieben einen mrbs-Server aufgesetzt.
Heute habe ich gemerkt, dass das letsencrypt-Zertifikat abgelaufen ist.
Ein dehydrated -c
hat folgende Ausgabe ergeben:
root@docker:~# dehydrated -c
# INFO: Using main config file /etc/dehydrated/config
Processing docker.staufer-gymnasium.de
+ Checking domain name(s) of existing cert... unchanged.
+ Checking expire date of existing cert...
+ Valid till Mar 7 11:34:45 2020 GMT Certificate will not expire
(Longer than 30 days). Skipping renew!
Processing mrbs.staufer-gymnasium.de
+ Checking domain name(s) of existing cert... unchanged.
+ Checking expire date of existing cert...
+ Valid till Dec 7 07:30:14 2019 GMT Certificate will expire
(Less than 30 days). Renewing!
+ Signing domains...
+ Generating private key...
+ Generating signing request...
Can't load /root/.rnd into RNG
140189093441984:error:2406F079:random number generator:RAND_load_file:Cannot open file:../crypto/rand/randfile.c:88:Filename=/root/.rnd
+ Requesting new certificate order from CA...
+ Received 1 authorizations URLs from the CA
+ Handling authorization for mrbs.staufer-gymnasium.de
+ 1 pending challenge(s)
+ Deploying challenge tokens...
+ Responding to challenge for mrbs.staufer-gymnasium.de authorization...
+ Cleaning challenge tokens...
+ Challenge validation has failed :(
ERROR: Challenge is invalid! (returned: invalid) (result: {
"type": "http-01",
"status": "invalid",
"error": {
"type": "urn:ietf:params:acme:error:unauthorized",
"detail": "Invalid response from https://mrbs.staufer-gymnasium.de/.well-known/acme-challenge/bKfeB489HMvbl-8zUarpbAl1PA90p7VdnpCXysUvzvk [141.10.70.29]: \"\u003c!DOCTYPE HTML PUBLIC \\\"-//IETF//DTD HTML 2.0//EN\\\"\u003e\\n\u003chtml\u003e\u003chead\u003e\\n\u003ctitle\u003e404 Not Found\u003c/title\u003e\\n\u003c/head\u003e\u003cbody\u003e\\n\u003ch1\u003eNot Found\u003c/h1\u003e\\n\u003cp\"",
"status": 403
},
"url": "https://acme-v02.api.letsencrypt.org/acme/chall-v3/1621199621/6YND2A",
"token": "bKfeB489HMvbl-8zUarpbAl1PA90p7VdnpCXysUvzvk",
"validationRecord": [
{
"url": "http://mrbs.staufer-gymnasium.de/.well-known/acme-challenge/bKfeB489HMvbl-8zUarpbAl1PA90p7VdnpCXysUvzvk",
"hostname": "mrbs.staufer-gymnasium.de",
"port": "80",
"addressesResolved": [
"141.10.70.29"
],
"addressUsed": "141.10.70.29"
},
{
"url": "https://mrbs.staufer-gymnasium.de/.well-known/acme-challenge/bKfeB489HMvbl-8zUarpbAl1PA90p7VdnpCXysUvzvk",
"hostname": "mrbs.staufer-gymnasium.de",
"port": "443",
"addressesResolved": [
"141.10.70.29"
],
"addressUsed": "141.10.70.29"
}
]
})
root@docker:~#
Kann mir jemand einen Tipp geben?
Vielen Dank schon mal für’s mitdenken,
Mathias