1

Topic: Can't ssl Letsencrypt

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.4.0 MARIADB edition
- Deployed with iRedMail Easy or the downloadable installer? With the downloadable installer.
- Linux/BSD distribution name and version: Debian 10
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
I have my iredmail behind a proxy server with apache but when i try to certbot it sends an error

Failed authorization procedure. mail.example.com(http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from https://mail.example.com/.well-known/acme-challenge/gDbPtBN7reOxDzBUvME8wAam4xoqTSG74i4HO06oZKY [XX.X.X.XX]: "<html>\r\n<head><title>404 Not Found</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>404 Not Found</h1></center>\r\n<hr><center>"

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: mail.example.com
   Type:   unauthorized
   Detail: Invalid response from
   https://mail.example.com/.well-known/acme-challenge/gDbPtBN7reOxDzBUvME8wAam4xoqTSG74i4HO06oZKY
   [XX.X.X.XX]: "<html>\r\n<head><title>404 Not
   Found</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>404
   Not Found</h1></center>\r\n<hr><center>"

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address.

Someone can help me?

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2 (edited by Cthulhu 2021-12-22 00:04:54)

Re: Can't ssl Letsencrypt

well, the file was not found, either it does not exist, or the filename was wrong, but i aswell dont think that you own mail.example.com

better change to DNS verification then

3

Re: Can't ssl Letsencrypt

I have it configured into Cloudflare, obviously don't example.com, is just that, an example. By the way i could certificate that. Now i am able to login with thunderbird and all of that. The only thing that i note is that when i connect can't use the port 993 for imaps, it must be 143 or it's impossible to connect.

4

Re: Can't ssl Letsencrypt

starttls is always better than SSL