Skip to content
View in the app

A better way to browse. Learn more.

Unraid

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Nginx Proxy Manager doesn't let create a new cert

Featured Replies

NPM does not allow you to create a new certificate by issuing an Internal Error. Moreover, I previously used NPM, completely deleted it, still gives an error. The ports on the router are redirected correctly. When creating a certificate in the "SSL Certificates" menu, it gives the following:


Error: Command failed: certbot certonly --config "/etc/letsencrypt.ini" --cert-name "npm-13" --agree-tos --authenticator webroot --email "[email protected]" --preferred-challenges "dns,http" --domains "jelly.DOMAIN.DOMAIN"
Saving debug log to /var/log/letsencrypt/letsencrypt.log
An unexpected error occurred:
Error creating new order :: too many failed authorizations recently: see https://letsencrypt.org/docs/failed-validation-limit/
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

    at ChildProcess.exithandler (node:child_process:399:12)
    at ChildProcess.emit (node:events:526:28)
    at maybeClose (node:internal/child_process:1092:16)
    at Process.ChildProcess._handle.onexit (node:internal/child_process:302:5)


Please help, I have already searched through all kinds of resources, I can't find a solution in any way. Previously, everything was created calmly, but now it is not being created at all, even though I did not touch anything.

I apologize for possible mistakes, because I used a translator to write the text.

изображение.png

изображение.png

изображение.png

изображение.png

Solved by MAM59

  • Community Expert
  • Solution

yeah, this happens if you play around with letsencrypt too much and too often.

 

The good thing: there is nothing wrong with NPM, UNRAID or the container.

 

You need to do 2 things to get it done:

 

1) be patient, you are blocked for at least 1hr, no way to speed it up

2) get your "jelly..." domain properly announced in the external DNS servers. You cannot get any cert for internal only domains. Go to you DNS provider, add a CNAME for jelly... to your current external ip address (or add an A or AAAA record if you are using static addresses in the real world)

 

check with "nslookup jelly.... 8.8.8.8" before you do your next try and make letsencrypt become mad for you again.

The nslookup should be able to get an address record that points to your box. If not, FIX IT!!!

(repeat until it works)

 

Edited by MAM59

  • Author
56 minutes ago, MAM59 said:

yeah, this happens if you play around with letsencrypt too much and too often.

 

The good thing: there is nothing wrong with NPM, UNRAID or the container.

 

You need to do 2 things to get it done:

 

1) be patient, you are blocked for at least 1hr, no way to speed it up

2) get your "jelly..." domain properly announced in the external DNS servers. You cannot get any cert for internal only domains. Go to you DNS provider, add a CNAME for jelly... to your current external ip address (or add an A or AAAA record if you are using static addresses in the real world)

 

check with "nslookup jelly.... 8.8.8.8" before you do your next try and make letsencrypt become mad for you again.

The nslookup should be able to get an address record that points to your box. If not, FIX IT!!!

(repeat until it works)

 

big thanks!! It's very stupid mistake. I forgot about CNAME in domain registrar. But it's strange, that NPM shows that it's just "internal error"

Edited by StrongDan

  • Community Expert
1 minute ago, StrongDan said:

But it's strange, that NPM doesn't show that it's just "internal error"

not really.

NPM assumes, that you use a different DNS service internally, so it does not trust the query results.

 

It should check the domain against google or somebody else before it bothers letsencrypt with a non-deligated domain, but it does not (ask the container creator why not).

 

On the other hand, there is a big warning below the domain field, people should read an believe it 😘

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.