SSL and Let’s Encrypt

A certificate that expired, or a renewal that cannot see the site.

Certbot or the panel’s client. The failure is usually DNS, a redirect, or Cloudflare in front of an origin with no certificate of its own.

Why renewal fails

Let’s Encrypt has to reach the host. Something is in the way.

HTTP-01 blocked

A redirect to HTTPS that loops, a firewall on port 80, or the panel looking at the wrong web root. The error names the check that failed.

DNS wrong

The name points at an old IP, or only at Cloudflare. Issuing on the origin needs the name to reach the server, or a DNS-01 challenge if the proxy must stay on.

Cloudflare Full

Full (strict) with no origin certificate is a browser error, not an expired Let’s Encrypt on the edge. The origin needs its own cert. Flexible is not the fix we leave in place.

Panels

Hestia, DirectAdmin and cPanel issue the cert. They also hide the failure.

The panel log is a summary. Certbot’s output is the reason. We renew in the tool the panel expects, so the next automatic run does not overwrite a hand-installed file.

Cloudflare and DNS → · Control panels →

Price

€55 an hour. A warning in the browser is not an emergency by itself.

Minimum 1 hour. If the certificate has expired and checkout is down, say so. That can be priority at €75 in business hours. A wildcard is DNS-01 and needs access to the zone, not only to the server.

Pricing →

Certificate expired, or the renewal mail has been ignored?

Tell us the domain and whether Cloudflare is in front. No panel password in the first message.

Request Support → Contact Us