MOON
Server: Apache
System: Linux vps.espica.me 5.14.0-611.54.3.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Thu May 7 16:31:24 EDT 2026 x86_64
User: golnoorlig (1005)
PHP: 8.2.32
Disabled: exec,passthru,shell_exec,system
Upload Files
File: //proc/thread-self/root/var/log/letsencrypt/letsencrypt.log
2026-07-19 00:59:08,404:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-19 00:59:08,404:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-19 00:59:08,404:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-19 00:59:08,405:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-19 00:59:08,416:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-19 00:59:08,418:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-19 00:59:08,419:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-19 00:59:08,439:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-19 00:59:08,441:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-19 00:59:08,441:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-19 00:59:08,441:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-19 00:59:08,442:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f2c5fc1da00>
Prep: True
2026-07-19 00:59:08,442:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f2c5fc1da00> and installer None
2026-07-19 00:59:08,442:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-19 00:59:08,488:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-19 00:59:08,489:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-19 00:59:08,490:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-19 00:59:08,922:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-19 00:59:08,922:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 04:59:08 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "jtMV4Ut1V0I": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-19 00:59:08,924:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-19 00:59:08,925:DEBUG:acme.client:Requesting fresh nonce
2026-07-19 00:59:08,925:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-19 00:59:09,063:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-19 00:59:09,063:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 04:59:08 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2npVIsb_J7JTGH29gkp6-qTlmU0aNMV-6DyJi3Tl1w88
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-19 00:59:09,063:DEBUG:acme.client:Storing nonce: YUeQbvp2npVIsb_J7JTGH29gkp6-qTlmU0aNMV-6DyJi3Tl1w88
2026-07-19 00:59:09,064:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-19 00:59:09,065:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMm5wVklzYl9KN0pUR0gyOWdrcDYtcVRsbVUwYU5NVi02RHlKaTNUbDF3ODgiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "AVIEFDkpOTOMzlQzyRUFiCVLRQ_cxrcNFLmjp4Mxr6TeCl-lLdIXl0YODxJAPTNdruidctixWGV3p4OjyffgMTUk91F-_nZM6EQaZStVJMmUI3rPmHfOdkLk-JXgezqX6tXpakKhntQnPj6HhVV24eCGWtyhROi9NYzcTeUPQowALKoufk0hVORoDB9zKBak-7jW-zZeDW0or0IWV6JwsM6ohg_Xdafg0Rx3CXde1DDkWfCVF0nwE90zSo9XBroBVEnTUNM0mznqwg4xCHHpcSJBmLf6JqbEx9JnYHF5doIy3zXP4TIvKYKB_zUqOxeLCO8Kr8kNS4Fl8bN1teG2SQ",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-19 00:59:09,234:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-19 00:59:09,235:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Sun, 19 Jul 2026 04:59:09 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/533992090665
Replay-Nonce: YUeQbvp2Mt7kJOxkuDwyFyhK5vWGBXZo-ylMJB2FBFr4wveDphI
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-26T04:59:09Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742126683785"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/533992090665"
}
2026-07-19 00:59:09,235:DEBUG:acme.client:Storing nonce: YUeQbvp2Mt7kJOxkuDwyFyhK5vWGBXZo-ylMJB2FBFr4wveDphI
2026-07-19 00:59:09,235:DEBUG:acme.client:JWS payload:
b''
2026-07-19 00:59:09,236:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742126683785:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMk10N2tKT3hrdUR3eUZ5aEs1dldHQlhaby15bE1KQjJGQkZyNHd2ZURwaEkiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQyMTI2NjgzNzg1In0",
  "signature": "nsmEqdb9qwf2Xc9T0uaxDCVV-u5u4i2b3zLsC8z_GordaVivZN2Z8HrvI_6FETf6UlJ00buYQhQNUt9ewZNgh-OEimrwZvU8cqNsuX-3E6LEzeAnabJck_FCQxo6Uqx9foUNMvqLoIU03WEsclJPIs4KEltqb6jb2b6B9EKM_-EBgJEFfKoEDu8NVjulXRO6wQO16MDHNAkr5EZrKPYtXc5yrX0KGCctZkIs_fgWueISWmn_vFDQLqoM6sNfUqmalgnShx1nSpaj9zXClrPW7Vk-UntPUV5uUH7aDgC241fVMwny8hwnPRHP8gvQke_U5zTkAY8fy_K3z9x8BmJhzQ",
  "payload": ""
}
2026-07-19 00:59:09,376:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/742126683785 HTTP/1.1" 200 822
2026-07-19 00:59:09,376:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 04:59:09 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2YZ6sIyR_5bM7mIDWlZA5QSIjB2ULTFN84ugTVTEYj8o
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-26T04:59:09Z",
  "challenges": [
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/CfXi9w",
      "status": "pending",
      "token": "sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/-PaUgA",
      "status": "pending",
      "token": "sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/Y_1iUA",
      "status": "pending",
      "token": "sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo"
    }
  ]
}
2026-07-19 00:59:09,377:DEBUG:acme.client:Storing nonce: YUeQbvp2YZ6sIyR_5bM7mIDWlZA5QSIjB2ULTFN84ugTVTEYj8o
2026-07-19 00:59:09,377:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-19 00:59:09,377:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-19 00:59:09,377:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-19 00:59:09,377:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-19 00:59:09,379:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo
2026-07-19 00:59:09,380:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-19 00:59:09,381:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/-PaUgA:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMllaNnNJeVJfNWJNN21JRFdsWkE1UVNJakIyVUxURk44NHVnVFZURVlqOG8iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQyMTI2NjgzNzg1Ly1QYVVnQSJ9",
  "signature": "I0Ie2bXJ_Eres4HJadOYna_bHsREDqZcGmMgv0XqNuUOtPin7Hx5Fsq8yWiSix0yz-r3ZF3-7qYve74vH3L7wR2CuX1eacfxHDSkAK8w3OVEbQTrpNgOQ1nypBiTVFn0AWNLlVaGD2g_Y7waNK0pgxrj0xAT2XQfUpi_PBh6f7_Z1zbSByfbTga9cvfWAebr5kRD1eKeLRWdDhDfrkHKtNy8BasrB9CQrRxiSnsp_0L088A5HcOZ3jVPITvvPxAAeJ_8yS_z-2Z5YKw_FFha6qSdbH5nsXWoQ883XnaWiPjhBbeK23ET1C_IJf9qH0qpjMkHrx-E0iTx8hS4RSPQRQ",
  "payload": "e30"
}
2026-07-19 00:59:09,531:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/742126683785/-PaUgA HTTP/1.1" 200 195
2026-07-19 00:59:09,531:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 04:59:09 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742126683785>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/-PaUgA
Replay-Nonce: DeP8OpbNeUD5ugOXsDpDiNOJ3Ac1ruU7qlDUb_Y1EgmkEPc3mgo
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/-PaUgA",
  "status": "pending",
  "token": "sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo"
}
2026-07-19 00:59:09,531:DEBUG:acme.client:Storing nonce: DeP8OpbNeUD5ugOXsDpDiNOJ3Ac1ruU7qlDUb_Y1EgmkEPc3mgo
2026-07-19 00:59:09,532:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-19 00:59:10,532:DEBUG:acme.client:JWS payload:
b''
2026-07-19 00:59:10,534:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742126683785:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTmVVRDV1Z09Yc0RwRGlOT0ozQWMxcnVVN3FsRFViX1kxRWdta0VQYzNtZ28iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQyMTI2NjgzNzg1In0",
  "signature": "gh7BXeU8FLoGE0Zw6g0d3QG7RsMnosdiTKS6DfoR4BOFKKL97nwM_InPB6LfK_ZiuMJPoVN9sYL4dNpWQm6MWMbolytC8XCsL9I2n-8wp1WgACqRAo4it9pwV2C1Zj_TmV9djQcsS2FEvEubo6vDCwNonCtuUZJ5LI5UVQewrrIRmK_fU68tK4oDO-eFcMIPkE3jgD1Mw5GRU6pc-ByuZbAMwUMFQH7_JQKu8wEzyyQ5dUuod1g1KVbY7XGU6Na-g-vN22NGWMvWzJJfMuj7Rxw99qSBQNvFC6AHgHHQ4wqQhWxHqVYDXePVpmANiFs4BEpY2Si8b5Wepb_eUqZeAw",
  "payload": ""
}
2026-07-19 00:59:10,671:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/742126683785 HTTP/1.1" 200 1032
2026-07-19 00:59:10,672:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 04:59:10 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNh3lbPyI1ArDlfuRH3MfLMXM_g6YIVz7ValispgMrgDw
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-26T04:59:09Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742126683785/-PaUgA",
      "status": "invalid",
      "validated": "2026-07-19T04:59:09Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo: 404",
        "status": 403
      },
      "token": "sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-19 00:59:10,672:DEBUG:acme.client:Storing nonce: DeP8OpbNh3lbPyI1ArDlfuRH3MfLMXM_g6YIVz7ValispgMrgDw
2026-07-19 00:59:10,672:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-19 00:59:10,672:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-19 00:59:10,672:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-19 00:59:10,673:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-19 00:59:10,673:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-19 00:59:10,673:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-19 00:59:10,673:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/sahpQR8BqmH0RDz4Wwwv7n2vEyH7OSf1nOxSSZuZbAo
2026-07-19 00:59:10,674:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-19 00:59:10,674:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-19 00:59:10,676:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-19 00:59:10,677:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-19 00:59:10,678:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-19 00:59:10,678:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-19 00:59:10,678:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-19 00:59:10,678:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-19 00:59:10,678:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-19 14:44:06,636:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-19 14:44:06,636:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-19 14:44:06,636:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-19 14:44:06,637:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-19 14:44:06,658:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-19 14:44:06,660:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-19 14:44:06,662:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-19 14:44:06,680:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-19 14:44:06,682:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-19 14:44:06,682:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-19 14:44:06,682:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-19 14:44:06,682:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f8075d87a00>
Prep: True
2026-07-19 14:44:06,683:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f8075d87a00> and installer None
2026-07-19 14:44:06,683:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-19 14:44:06,723:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-19 14:44:06,723:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-19 14:44:06,726:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-19 14:44:07,156:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-19 14:44:07,156:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "UGCy4RorLLs": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-19 14:44:07,159:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-19 14:44:07,160:DEBUG:acme.client:Requesting fresh nonce
2026-07-19 14:44:07,161:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-19 14:44:07,294:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-19 14:44:07,295:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 18:44:07 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNjTTJ2VnqxvuBgnGugmMDKsUnb9Lpgq39NSxjrqlLpbY
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-19 14:44:07,295:DEBUG:acme.client:Storing nonce: DeP8OpbNjTTJ2VnqxvuBgnGugmMDKsUnb9Lpgq39NSxjrqlLpbY
2026-07-19 14:44:07,295:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-19 14:44:07,297:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTmpUVEoyVm5xeHZ1QmduR3VnbU1ES3NVbmI5THBncTM5TlN4anJxbExwYlkiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "ocIrGcqvJf-v4kVckq3UiH2SCE4tNSS0qxSx4RUNTStcmPfr7sJMZ3Vwv0gbNudu4EwNK3kcb1Ci3gK2-XnbjZSU8qLuwnwEfRrsVwOMXaf8DQsJEWDYvqitF49w7g703s616tttOrSHFem_06AZM_9VnJV41Q0gk1pSE2skmiKDNcxgoG02RzA-bZBLyytvvM9MzyTS9rXz9-NLAvjNJMEIJgpUvevEPzhQ9peFh7KXPeuLmxj6qIRZ_o_-cHdBPVbJ7pixeM8kpfUBwNi7tpSkPjYotEqgYsxLDMH1SBcLS8ZPcqu8vNguZipHKUjSI5FD6wNdWoPAxI8JFoRVqA",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-19 14:44:07,467:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-19 14:44:07,468:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Sun, 19 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/534212243725
Replay-Nonce: YUeQbvp2wT2Mo3O4H6Srd0wxtoa4bLCFIDPNaEfiGCXVGmIo2S8
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-26T18:44:07Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742476665175"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/534212243725"
}
2026-07-19 14:44:07,468:DEBUG:acme.client:Storing nonce: YUeQbvp2wT2Mo3O4H6Srd0wxtoa4bLCFIDPNaEfiGCXVGmIo2S8
2026-07-19 14:44:07,468:DEBUG:acme.client:JWS payload:
b''
2026-07-19 14:44:07,470:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742476665175:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMndUMk1vM080SDZTcmQwd3h0b2E0YkxDRklEUE5hRWZpR0NYVkdtSW8yUzgiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQyNDc2NjY1MTc1In0",
  "signature": "ccPR-GQu6_vcuRqXE0Grk7mMIJlw4Ihqmr6iiDiVvt9WP3pGXcaRnndJka4Ia5d4ihs-h4jsAu5yySNVww4tQM_z4rKG9rmWLJ11pNnTT6o3iYNjD-w80OoypdY117ItuHWRW6MxKEFjx5K0xHHizOwnO55eIPBabBn8L9_egxiP0uizE6Mug6LUs8696oQrwL7kJfDpIle0ZYl76HFtCpOrJrnTJ_YXIzFV9JZ8fv5eDxPNyNGI5oDc9rgz859Xi7hGA0YBxG1RQIxR025ZRbtaMKvG6BWYdsGh75DW-omMCJ1B0JgiaK2Q8vb7wru3SS3p3rgyARrOHyhtBfig5w",
  "payload": ""
}
2026-07-19 14:44:07,622:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/742476665175 HTTP/1.1" 200 822
2026-07-19 14:44:07,623:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2VHQFp7UfDsyK1iof9yfoNToJFReRCHNwFe1rLQpdLng
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-26T18:44:07Z",
  "challenges": [
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/tWn_bA",
      "status": "pending",
      "token": "ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/OuCyeA",
      "status": "pending",
      "token": "ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/R4TayA",
      "status": "pending",
      "token": "ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28"
    }
  ]
}
2026-07-19 14:44:07,624:DEBUG:acme.client:Storing nonce: YUeQbvp2VHQFp7UfDsyK1iof9yfoNToJFReRCHNwFe1rLQpdLng
2026-07-19 14:44:07,624:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-19 14:44:07,624:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-19 14:44:07,624:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-19 14:44:07,624:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-19 14:44:07,626:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28
2026-07-19 14:44:07,626:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-19 14:44:07,627:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/R4TayA:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMlZIUUZwN1VmRHN5SzFpb2Y5eWZvTlRvSkZSZVJDSE53RmUxckxRcGRMbmciLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQyNDc2NjY1MTc1L1I0VGF5QSJ9",
  "signature": "k1s6xgod2I_E_v3qQNnEVovZbiR3nH2m8e-7uRLxJCSgJISl9ca-38ynjBptwN-d1wHCBXpgOAcGj66E8XtmK-BlF82kNpr1zoky82JkdgvAnqNiFLEVGi_0W90HHfRuGvJr_MYx2jbuRrJaO9LJElOTqFoXWry4F2VxjjFAtN7dE9wDXaZJ5nQj2fTk4F6n5LuZP9Wt3OXpullQxIHKCSUUogXPMirlZ-Of6e5mdfO3shuAjCKktpPTRBH_tSlnUskCs-VD4ys1gHBGazZJe57IgRd5rB1fTbIPjDLB_ZTlGPD8c8OtvCHGBNwNcOZEV3d_ZJq8Yc51h257DXj8JA",
  "payload": "e30"
}
2026-07-19 14:44:07,783:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/742476665175/R4TayA HTTP/1.1" 200 195
2026-07-19 14:44:07,784:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742476665175>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/R4TayA
Replay-Nonce: YUeQbvp275GtszmfPyLx_CuG8QloX6iL_8F0qQz7kCFbKkZH2mg
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/R4TayA",
  "status": "pending",
  "token": "ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28"
}
2026-07-19 14:44:07,784:DEBUG:acme.client:Storing nonce: YUeQbvp275GtszmfPyLx_CuG8QloX6iL_8F0qQz7kCFbKkZH2mg
2026-07-19 14:44:07,785:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-19 14:44:08,786:DEBUG:acme.client:JWS payload:
b''
2026-07-19 14:44:08,787:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742476665175:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMjc1R3Rzem1mUHlMeF9DdUc4UWxvWDZpTF84RjBxUXo3a0NGYktrWkgybWciLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQyNDc2NjY1MTc1In0",
  "signature": "JOScs9nIVyDAWLVM7ju7GGnPQA7IVSZoxPBCiPJEQhO0f_lzt9tZCeKuMJuTjM7w8ctmOelWYq7eDYN0M2WTEhjfxrgBIkDc5gpXDzCTLRsGwVacliZ4kmBASol03PV0ZvU6AzOkGnTqMxZ5aRWx-DPn-tdAZmPqydnoTD_Kg0A01alnJY1uYbpopwysMUXw3LMH5AwDlPWuC7QzzniOW82m7b2J5FRo-FT50NG5LxOtVGL6CnDneSuJFeDNY-S6zjDZn8ocFzVxea0OLS60Sjv3tXpcVQjrDUAOAqoIGMW57Zs_f6xdYka-NtZEHD9pF0bAwr7dBmV83Ei7swkKtQ",
  "payload": ""
}
2026-07-19 14:44:08,927:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/742476665175 HTTP/1.1" 200 1032
2026-07-19 14:44:08,928:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sun, 19 Jul 2026 18:44:08 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2ibD8aFBdWsXOfu0VRpCOhnpqyvFG52gzmxe7MXeRvng
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-26T18:44:07Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742476665175/R4TayA",
      "status": "invalid",
      "validated": "2026-07-19T18:44:07Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28: 404",
        "status": 403
      },
      "token": "ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-19 14:44:08,928:DEBUG:acme.client:Storing nonce: YUeQbvp2ibD8aFBdWsXOfu0VRpCOhnpqyvFG52gzmxe7MXeRvng
2026-07-19 14:44:08,928:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-19 14:44:08,929:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-19 14:44:08,929:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-19 14:44:08,930:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-19 14:44:08,930:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-19 14:44:08,930:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-19 14:44:08,930:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/ig3smWrPQqmGQK5oBDwL43I8qAh1LB8Ttvn8lxtAy28
2026-07-19 14:44:08,931:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-19 14:44:08,931:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-19 14:44:08,934:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-19 14:44:08,935:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-19 14:44:08,935:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-19 14:44:08,935:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-19 14:44:08,936:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-19 14:44:08,936:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-19 14:44:08,936:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-20 01:56:03,745:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-20 01:56:03,745:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-20 01:56:03,745:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-20 01:56:03,747:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-20 01:56:03,762:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-20 01:56:03,764:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-20 01:56:03,766:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-20 01:56:03,790:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-20 01:56:03,793:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-20 01:56:03,793:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-20 01:56:03,793:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-20 01:56:03,793:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7fd12d1f7a00>
Prep: True
2026-07-20 01:56:03,794:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7fd12d1f7a00> and installer None
2026-07-20 01:56:03,794:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-20 01:56:03,837:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-20 01:56:03,838:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-20 01:56:03,840:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-20 01:56:04,270:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-20 01:56:04,270:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 05:56:04 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "GEOq8vuC_qQ": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-20 01:56:04,272:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-20 01:56:04,275:DEBUG:acme.client:Requesting fresh nonce
2026-07-20 01:56:04,275:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-20 01:56:04,410:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-20 01:56:04,410:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 05:56:04 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2r7S05tQoyJnA7LmBpWW4abeV9cPF0sVN0bw1RTzkL3E
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-20 01:56:04,411:DEBUG:acme.client:Storing nonce: YUeQbvp2r7S05tQoyJnA7LmBpWW4abeV9cPF0sVN0bw1RTzkL3E
2026-07-20 01:56:04,411:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-20 01:56:04,413:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMnI3UzA1dFFveUpuQTdMbUJwV1c0YWJlVjljUEYwc1ZOMGJ3MVJUemtMM0UiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "USHt6K4_OQ390aQRQrJcYCRNJFiT4gbLSVAIYvfZ3azXsOSLLz2sTVX_P7wYr7L-eXmWhTEfF5JcwrIXax7l2g1XjI6CXSbLRAa2M_4KmmcK5jLY0UeGgAl93qA-PdaU4OXRgfbDMo7ZCyhV1zjIdfJupdPiSpOD7z9HeKCQ6JZOadn-SIM-0q01uXZTZnUqusRg2uZnTpx9AmD_0ME6SjdN_H-rCKOAUGO-TwJArjanSiytF2Tsdqrg81DeGzWaDOAGq-sVnv9BnY5TiF-4b8oEzsNb6umgUxhIinssvJaDKm9DgODrqB7MHMA7012EC5tv8FNPBhQETdloUv2ksw",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-20 01:56:04,582:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-20 01:56:04,582:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Mon, 20 Jul 2026 05:56:04 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/534400036675
Replay-Nonce: DeP8OpbNPN_pHj_z1A6wn3V3P5xWQC4Ye4SzsFxYhQKwy2nC0Js
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-27T05:56:04Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742773597685"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/534400036675"
}
2026-07-20 01:56:04,583:DEBUG:acme.client:Storing nonce: DeP8OpbNPN_pHj_z1A6wn3V3P5xWQC4Ye4SzsFxYhQKwy2nC0Js
2026-07-20 01:56:04,583:DEBUG:acme.client:JWS payload:
b''
2026-07-20 01:56:04,584:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742773597685:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTlBOX3BIal96MUE2d24zVjNQNXhXUUM0WWU0U3pzRnhZaFFLd3kybkMwSnMiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQyNzczNTk3Njg1In0",
  "signature": "WvMK8eDryWthq5AOmkcd0BHibWdrV-k3iwmF9NOUGsyAXJBiP71cAm8rop1I7bG8cr5-NFWbHMAWfS9AKfiVhdgOgnztI3iIfre5yrNsZ_oBuFCxmRnNTPPRT9hgogV7xRgUerxi6gP204uNsb46Xux5I0-ASHyeqMNFkfeYO4V6iOr8vrNDV_BL5yLX_JCo1mNYoS7IPWRm2Ouv6Yrf2rQrW_LPToUkFmVw_RRHW_nl0NyPYG_Elx4KqrUtm38S84LpARMv5oJHMHZkpFqJRRel-n03mb3DHEkXv82orBKcAnkVaoxkBakKzb_OsynzuMDCBoCwp1oTXMZHzLBisw",
  "payload": ""
}
2026-07-20 01:56:04,730:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/742773597685 HTTP/1.1" 200 822
2026-07-20 01:56:04,731:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 05:56:04 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2-ha_FOdFN8H-89L-UcEJFCVBiAnFkR2UOvO9k0XS6jA
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-27T05:56:04Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/2xBTPQ",
      "status": "pending",
      "token": "jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/lXKDkA",
      "status": "pending",
      "token": "jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/H363hQ",
      "status": "pending",
      "token": "jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA"
    }
  ]
}
2026-07-20 01:56:04,731:DEBUG:acme.client:Storing nonce: YUeQbvp2-ha_FOdFN8H-89L-UcEJFCVBiAnFkR2UOvO9k0XS6jA
2026-07-20 01:56:04,732:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-20 01:56:04,732:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-20 01:56:04,733:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-20 01:56:04,733:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-20 01:56:04,736:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA
2026-07-20 01:56:04,738:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-20 01:56:04,740:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/2xBTPQ:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMi1oYV9GT2RGTjhILTg5TC1VY0VKRkNWQmlBbkZrUjJVT3ZPOWswWFM2akEiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQyNzczNTk3Njg1LzJ4QlRQUSJ9",
  "signature": "GDaRjMBGBXxWymFcZhZ8Jta5vP7vTyZfBl3b0g5JmqG_Qk_mg7CCa7MLk1YKWiI_MHMP3aRp9Cx1sdwvG7OYSj9STo0_5mPtB82AWgAXP8QBFMkd3gRdCHBzak1jExabPnhitS1GZj1qahcXPx7CTCtHSTSPy8vJ2WNxcsfGYEB4j1CB1d78gh4Hy1qtyG_3nU_TLAuCfLckFCXDbG4fF4TMiJ9b8ZCoNWvDgIXmGBLp_f4lk5jdvAzbYXr68fO_yjnohbUxJ-oesaa_l_3Wxc04J6QbcOIXbJtYFRibZ-GpqY2TYn8jWmS9sQqIrgV1u_uinqvBHwQbQy_hDftbHQ",
  "payload": "e30"
}
2026-07-20 01:56:04,913:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/742773597685/2xBTPQ HTTP/1.1" 200 195
2026-07-20 01:56:04,913:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 05:56:04 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742773597685>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/2xBTPQ
Replay-Nonce: YUeQbvp2_d1GGpu9PHEBh1gpG9Cg9m2qd6gUFoFw8tUuTFFpG9U
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/2xBTPQ",
  "status": "pending",
  "token": "jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA"
}
2026-07-20 01:56:04,914:DEBUG:acme.client:Storing nonce: YUeQbvp2_d1GGpu9PHEBh1gpG9Cg9m2qd6gUFoFw8tUuTFFpG9U
2026-07-20 01:56:04,914:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-20 01:56:05,915:DEBUG:acme.client:JWS payload:
b''
2026-07-20 01:56:05,917:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/742773597685:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMl9kMUdHcHU5UEhFQmgxZ3BHOUNnOW0ycWQ2Z1VGb0Z3OHRVdVRGRnBHOVUiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQyNzczNTk3Njg1In0",
  "signature": "StkLKAZNgmtr1RlpDiCi6m8oeJKMgmOtxjHQz-uqjx0oC-ICD1fSP8QILwoN9kIbn4PcIRiYJjW9ImWs4a-l0tuOIYlw03YnNJgm2d8HDtO6IMU68Tfyhcgl3TV9MxAsg7bEYmDEj72XnqQJVTmWpe5BnAQZru4mGoAdvoyGq6g_mJVYRkVUGUjkWipZ7n-EBj3mGNKMJqzKgFP3kR_TABbEG12kzTwt8-dEb7fL8N2klIB0WA0ZlkEL8svPkbErLHHvp8dd7RbjwnBaoZCtDduJbkxTcFDcDZAkNMuWnLVHPcazPp23eqnuvHKsO9biykQbj69DhjOrCvyqyyaZXA",
  "payload": ""
}
2026-07-20 01:56:06,077:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/742773597685 HTTP/1.1" 200 1032
2026-07-20 01:56:06,078:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 05:56:06 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNvW5A0rDEuTB5vA9iyO1oFN8Koj3esbH_e-p3Ky6g764
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-27T05:56:04Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/742773597685/2xBTPQ",
      "status": "invalid",
      "validated": "2026-07-20T05:56:04Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA: 404",
        "status": 403
      },
      "token": "jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-20 01:56:06,078:DEBUG:acme.client:Storing nonce: DeP8OpbNvW5A0rDEuTB5vA9iyO1oFN8Koj3esbH_e-p3Ky6g764
2026-07-20 01:56:06,079:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-20 01:56:06,079:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-20 01:56:06,079:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-20 01:56:06,080:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-20 01:56:06,080:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-20 01:56:06,080:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-20 01:56:06,080:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/jBJqux_IxszwMunburLQ6y--TB4xaZ9NiBIvzbeAKJA
2026-07-20 01:56:06,081:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-20 01:56:06,081:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-20 01:56:06,083:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-20 01:56:06,083:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-20 01:56:06,084:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-20 01:56:06,084:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-20 01:56:06,084:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-20 01:56:06,084:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-20 01:56:06,085:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-20 14:25:59,965:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-20 14:25:59,965:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-20 14:25:59,965:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-20 14:25:59,966:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-20 14:25:59,978:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-20 14:25:59,981:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-20 14:25:59,983:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-20 14:26:00,050:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-20 14:26:00,053:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-20 14:26:00,053:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-20 14:26:00,053:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-20 14:26:00,053:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7fcc1120fa00>
Prep: True
2026-07-20 14:26:00,054:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7fcc1120fa00> and installer None
2026-07-20 14:26:00,054:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-20 14:26:00,098:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-20 14:26:00,099:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-20 14:26:00,102:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-20 14:26:00,528:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-20 14:26:00,528:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 18:26:00 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert",
  "ytQ8p4hjtMc": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417"
}
2026-07-20 14:26:00,530:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-20 14:26:00,533:DEBUG:acme.client:Requesting fresh nonce
2026-07-20 14:26:00,533:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-20 14:26:00,671:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-20 14:26:00,672:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 18:26:00 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2xCJoOBNvH4-5oSLTN3OzQWsV-4ftYCtqDmAbkzJxCPA
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-20 14:26:00,672:DEBUG:acme.client:Storing nonce: YUeQbvp2xCJoOBNvH4-5oSLTN3OzQWsV-4ftYCtqDmAbkzJxCPA
2026-07-20 14:26:00,672:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-20 14:26:00,675:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMnhDSm9PQk52SDQtNW9TTFROM096UVdzVi00ZnRZQ3RxRG1BYmt6SnhDUEEiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "GHBoSa8Q1dCR2JnxYNJC2caBVjhoVG_5ncwzWr2MGk5eNbzrxP2Do4V2nnt1aCS4vPQ9sqTdFVxVud3UIS89pLjdQ8MZnVXTj1pQUzmklsXBe4-ldIV9dIM0YPRDSpc3JZHyxUFmA18XwULdeRGacidKQTuIl9CaryrvMIlv6y35q1zJ4igQXUUa16uFv-8rpEIazcB86qSEepFdf_1C2Ms6AyZ1roSncDgiW8fgcz2Oqkt62yyzfAq7kroUS62j9gjZm3L7GuQrTuP2MylCHvpKwzcNZmpZxRGsOKsv2WOhpO31rTEQ3OrUW7Mpsgv1Kh5l1Gjxvw524it9sacviw",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-20 14:26:00,844:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-20 14:26:00,845:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Mon, 20 Jul 2026 18:26:00 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/534608933225
Replay-Nonce: YUeQbvp2oGzu8KF3Ho_ovnrHfOGKTlEF-tjGwMSY9G2HbkD1gP0
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-27T18:26:00Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743100506645"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/534608933225"
}
2026-07-20 14:26:00,845:DEBUG:acme.client:Storing nonce: YUeQbvp2oGzu8KF3Ho_ovnrHfOGKTlEF-tjGwMSY9G2HbkD1gP0
2026-07-20 14:26:00,846:DEBUG:acme.client:JWS payload:
b''
2026-07-20 14:26:00,848:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743100506645:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMm9HenU4S0YzSG9fb3ZuckhmT0dLVGxFRi10akd3TVNZOUcySGJrRDFnUDAiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQzMTAwNTA2NjQ1In0",
  "signature": "CgBjp4H6geHzQLVpyTPk1lLeZGLp64zr-wmyD-liE8lHCh3NzSGtJ11fH6ZMkaMYhZdvEP6kYePx7mfMQ20JWcosnFoTKnS-9AVJa_7tQ13xrCBhgdNqCOcSX991aMy17HnInXBcPlAOaQFrAm8A4-nUBOj9XYhJRtumQWWRUCY9e3HyqiAxdsRLEPP13BjE_OUSqEbpr74wnnMnGJyFa-7vfr26cN2qR7gBp9npYiPDtccGcP6nq2N0AYtfnEdewIXqYMwYFz6cngqXXmE2PNIKexsPfjQTKdbbqtSuZYI7OBB8hwwjnx8x_xrGg9aL4sQnbrX9q5_ab1buKL3IZg",
  "payload": ""
}
2026-07-20 14:26:00,988:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/743100506645 HTTP/1.1" 200 822
2026-07-20 14:26:00,988:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 18:26:00 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNvb4REiB5wL4lBekIACh1gUHUdYeqZD3VekbcXDKidnY
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-27T18:26:00Z",
  "challenges": [
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/jvFwnw",
      "status": "pending",
      "token": "ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/BtKhng",
      "status": "pending",
      "token": "ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/SSHp4g",
      "status": "pending",
      "token": "ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek"
    }
  ]
}
2026-07-20 14:26:00,989:DEBUG:acme.client:Storing nonce: DeP8OpbNvb4REiB5wL4lBekIACh1gUHUdYeqZD3VekbcXDKidnY
2026-07-20 14:26:00,989:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-20 14:26:00,989:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-20 14:26:00,989:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-20 14:26:00,990:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-20 14:26:00,992:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek
2026-07-20 14:26:00,994:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-20 14:26:00,996:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/SSHp4g:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTnZiNFJFaUI1d0w0bEJla0lBQ2gxZ1VIVWRZZXFaRDNWZWtiY1hES2lkblkiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQzMTAwNTA2NjQ1L1NTSHA0ZyJ9",
  "signature": "WCSXLBUlWl_xtM7hfaIxxJpvHzVbNAzkKiiRQfoyHubRDDg1gGXVAEP__cJMzIFIWgDJn_qunqSkj8IghTgpaxjKLmuyWj4voIQuKNi5JZ3J7HZdun1SKdpm7gv8L2Oa39oh5Kx2qV-qYuT0E_az_O1oHDqkMiMrP1dZAao0KyhJQCcvzRJ-5Ost3-W0II2DkVJFOxEELwV5NhTkMC3y0hO8InjwXqvN7ivm6evBLcYXIDlenycFl4-0plt5hBDGvzixQmEzUWcLtBqJ40y13NZfClkfaXe0rLw1oh7sEyh5NP4IRSP6jz7xyPSM0YLcHvu1q4YisYzuuPrNSRuUPw",
  "payload": "e30"
}
2026-07-20 14:26:01,149:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/743100506645/SSHp4g HTTP/1.1" 200 195
2026-07-20 14:26:01,149:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 18:26:01 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743100506645>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/SSHp4g
Replay-Nonce: YUeQbvp2Z4ZzVeumlcx0LuFz4OOoTsCCHRobxkqQXbPtd-3Y8ss
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/SSHp4g",
  "status": "pending",
  "token": "ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek"
}
2026-07-20 14:26:01,150:DEBUG:acme.client:Storing nonce: YUeQbvp2Z4ZzVeumlcx0LuFz4OOoTsCCHRobxkqQXbPtd-3Y8ss
2026-07-20 14:26:01,150:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-20 14:26:02,151:DEBUG:acme.client:JWS payload:
b''
2026-07-20 14:26:02,152:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743100506645:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMlo0WnpWZXVtbGN4MEx1Rno0T09vVHNDQ0hSb2J4a3FRWGJQdGQtM1k4c3MiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQzMTAwNTA2NjQ1In0",
  "signature": "jV7QdiVZRRFc5OK-D8hBKenOArClZg9pYVAoCiyahNSB-iuMHHvTSWD3GGB1VpC0ngm4p91dtS7HLh5Qt3x5MQfdM_E0HOKmCahGx23ksHMA75U5NGB8V1slBRVj3FvKjT1wlw_QJj_6t9rmSFehJxQFjkwF83ok0srFwM2b6YYTJpY-K-bFbFofb3Io-SlrvFQDmxaws1zTwHyVHyzQ21SKAJtK1HJ6HUkbSsIHbnzoRyyIflMXJ_pSCwdVj14ypbcOvaAOVtKD5BLD5dSw31nBUjuygGOZvTw8Jyt89vMpJKg9QBTQpNHx3SdyVxqW8dLugxEbYto5qZJMxQLdKg",
  "payload": ""
}
2026-07-20 14:26:02,291:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/743100506645 HTTP/1.1" 200 1032
2026-07-20 14:26:02,291:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Mon, 20 Jul 2026 18:26:02 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNJvlQRIoNkI0t85GQa5288_oPUK_IrZPPIOu84aLnpGU
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-27T18:26:00Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743100506645/SSHp4g",
      "status": "invalid",
      "validated": "2026-07-20T18:26:01Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek: 404",
        "status": 403
      },
      "token": "ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-20 14:26:02,292:DEBUG:acme.client:Storing nonce: DeP8OpbNJvlQRIoNkI0t85GQa5288_oPUK_IrZPPIOu84aLnpGU
2026-07-20 14:26:02,292:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-20 14:26:02,292:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-20 14:26:02,292:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-20 14:26:02,293:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-20 14:26:02,293:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-20 14:26:02,293:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-20 14:26:02,293:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/ogFhRJh6b9wVjUMW9g9Cb1xoyFU2L_t5N9PeBMgIVek
2026-07-20 14:26:02,294:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-20 14:26:02,294:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-20 14:26:02,296:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-20 14:26:02,297:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-20 14:26:02,297:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-20 14:26:02,298:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-20 14:26:02,298:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-20 14:26:02,298:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-20 14:26:02,298:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-21 02:56:03,423:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-21 02:56:03,423:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-21 02:56:03,423:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-21 02:56:03,424:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-21 02:56:03,435:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-21 02:56:03,437:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-21 02:56:03,438:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-21 02:56:03,462:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-21 02:56:03,464:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-21 02:56:03,464:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-21 02:56:03,465:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-21 02:56:03,465:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7fda6ef14a00>
Prep: True
2026-07-21 02:56:03,465:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7fda6ef14a00> and installer None
2026-07-21 02:56:03,465:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-21 02:56:03,532:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-21 02:56:03,533:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-21 02:56:03,535:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-21 02:56:03,963:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-21 02:56:03,963:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 06:56:03 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "4O4r5gSppuc": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-21 02:56:03,964:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-21 02:56:03,966:DEBUG:acme.client:Requesting fresh nonce
2026-07-21 02:56:03,967:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-21 02:56:04,101:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-21 02:56:04,101:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 06:56:04 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbN1uybJSw1VUASM8Qk9ONXG-VpLJUT9IL2OuEsTvQEoZA
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-21 02:56:04,102:DEBUG:acme.client:Storing nonce: DeP8OpbN1uybJSw1VUASM8Qk9ONXG-VpLJUT9IL2OuEsTvQEoZA
2026-07-21 02:56:04,102:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-21 02:56:04,103:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTjF1eWJKU3cxVlVBU004UWs5T05YRy1WcExKVVQ5SUwyT3VFc1R2UUVvWkEiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "SzOfRjg7HfrdbkBG9jK5ZqsXXclR3q8BjPluy5X4Yh3qofR3c2OckRvX76E4mJ8eYwPorAd6kz1Ugl-IHx2Z3zUel6jWFcpuGaZFdnY5lumAY1FXyeMpQt-x0eUA2_upX-ybdBJxCe9q6uDc1BCaRgDkV6xkTmBVW1vcV_QX0NJmuiFnFQFgzt-e-K4OI-DYV9vLbM2818s94PbROH5aQM8YJobdeg0yGnEGLS2TDKm68TbDWWS9Ixi82A9_zlsVsrO_h_I4Ug5Qz_eQ8HHI25EISVuiMYtMs9pKgSlkKXoFhEwYJOf4DGRNQlZKDiozM4YeMdqkl7QqdlGBnmSoLg",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-21 02:56:04,302:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-21 02:56:04,303:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Tue, 21 Jul 2026 06:56:04 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/534824895815
Replay-Nonce: DeP8OpbNNxOK9XlnBg-SGICo6g3guGMQ8gcO0JYQF90Xdf0NKC0
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-28T06:56:04Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743440785245"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/534824895815"
}
2026-07-21 02:56:04,303:DEBUG:acme.client:Storing nonce: DeP8OpbNNxOK9XlnBg-SGICo6g3guGMQ8gcO0JYQF90Xdf0NKC0
2026-07-21 02:56:04,304:DEBUG:acme.client:JWS payload:
b''
2026-07-21 02:56:04,306:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743440785245:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTk54T0s5WGxuQmctU0dJQ282ZzNndUdNUThnY08wSllRRjkwWGRmME5LQzAiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQzNDQwNzg1MjQ1In0",
  "signature": "TG26Mxx_tbRI0oOCmEQ5ps14LfjEZN8OOu9gE4WwVi030ixUNzUjNFUPWvjdDNy-ljSNXFTFEil1XdSXdQxHoOEUZB45RRj3hsYQa-9xjk0VJ9HNJOwE8HJOWycVD9KH0etz3WpkTXsrodV5ZlkPQ2tMza3OFlgpZlCSL5f2oV9wZUUGCUE90vQBX-zSLFvtmYBGESHKaxYfVZu08laKAdF6oL3VOT0Dbfw1Zm_LNpyatR0pxNkrAQTuUJ0w9CmvkyDq0xEWL-kA1u6mrmtmneIAQfjRidvFMkkNW69-lJOXuOIVvDzLxBKxfdjOHuNjePeEIH-zqznwU0C45fhpiA",
  "payload": ""
}
2026-07-21 02:56:04,449:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/743440785245 HTTP/1.1" 200 822
2026-07-21 02:56:04,449:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 06:56:04 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbN_uUs8TEBFOXm5cnFjQepBitflNTJwHbhFUk3lJ64zZE
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-28T06:56:04Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/xOjR0g",
      "status": "pending",
      "token": "kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/nLdYrA",
      "status": "pending",
      "token": "kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/zmHrDQ",
      "status": "pending",
      "token": "kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk"
    }
  ]
}
2026-07-21 02:56:04,449:DEBUG:acme.client:Storing nonce: DeP8OpbN_uUs8TEBFOXm5cnFjQepBitflNTJwHbhFUk3lJ64zZE
2026-07-21 02:56:04,450:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-21 02:56:04,450:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-21 02:56:04,450:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-21 02:56:04,450:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-21 02:56:04,452:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk
2026-07-21 02:56:04,453:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-21 02:56:04,454:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/xOjR0g:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTl91VXM4VEVCRk9YbTVjbkZqUWVwQml0ZmxOVEp3SGJoRlVrM2xKNjR6WkUiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQzNDQwNzg1MjQ1L3hPalIwZyJ9",
  "signature": "eFI7H9wxYiJsVPHlX-B8-jjPuTPRUT4VSEZcvEu3g5OW1WfOj7uDbpevm_A-Cz9_uq0QkYklcwY9hyNS5HyN8n_UXISwadWS7VK7-G7jPvI70wVmItCnYkZwJN5t0IHlG_JgJe9wddz0tnbjeC07X9HlbW1rSc8tD_Cluo61xBbwA2DEfzUGg3zNdrooJXIL0uWrVq9pAeAhETGsU8jkwwj7gMKEw4VUJH09SDHv-9IxQfKHfFrnqafEMCJHruVVmhBQQc-DJysNrVdbHgPyUTnX0Paz5U2FGzkG0Xu1YsNU2kAKtC2CfzXB0EpIpFpaWVB_nkt8m_SnRXkoNvsFbA",
  "payload": "e30"
}
2026-07-21 02:56:04,601:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/743440785245/xOjR0g HTTP/1.1" 200 195
2026-07-21 02:56:04,601:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 06:56:04 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743440785245>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/xOjR0g
Replay-Nonce: YUeQbvp2i5OEFH7QijWtwq7pEOZrZyAb3KnjBm7eS5hg0bRduxY
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/xOjR0g",
  "status": "pending",
  "token": "kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk"
}
2026-07-21 02:56:04,601:DEBUG:acme.client:Storing nonce: YUeQbvp2i5OEFH7QijWtwq7pEOZrZyAb3KnjBm7eS5hg0bRduxY
2026-07-21 02:56:04,602:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-21 02:56:05,603:DEBUG:acme.client:JWS payload:
b''
2026-07-21 02:56:05,604:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743440785245:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMmk1T0VGSDdRaWpXdHdxN3BFT1pyWnlBYjNLbmpCbTdlUzVoZzBiUmR1eFkiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQzNDQwNzg1MjQ1In0",
  "signature": "iqWKvMj3tf4feeQp-fhva6S7k34bp12lM3uZk8cctnalL_BGTqAGxVFpmJqvbGw0qs3vcjh1PSny9H6S_AnN8aDFznxxm10j6h7OjnwPkDQBlsVY5ylDIj-6tGIx2RwL2a_-5OXpoiLD2NhHWLWLzDfn6mOt2zO6N185qUMJgPOiz98o-XMuSQ-hS-d5C_12IAKoBIAnho2gHb_HeVEZvRgLyyEuebmRjUoaSfucndJ6gONAS5abgJleVM8L8AD-N_xnWjV4fr5LjznI57SfNRmzhN7MesBzRqeaMLLfSTM01DN9q4wUrrx38bd9z6aRjheWBk4g-WbXxHvYtpSbXA",
  "payload": ""
}
2026-07-21 02:56:05,763:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/743440785245 HTTP/1.1" 200 1032
2026-07-21 02:56:05,763:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 06:56:05 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNRxNrpKoMKpJlI1AD8z2CphzYBjkIK5cvc8BI7xQOlJU
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-28T06:56:04Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743440785245/xOjR0g",
      "status": "invalid",
      "validated": "2026-07-21T06:56:04Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk: 404",
        "status": 403
      },
      "token": "kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-21 02:56:05,763:DEBUG:acme.client:Storing nonce: DeP8OpbNRxNrpKoMKpJlI1AD8z2CphzYBjkIK5cvc8BI7xQOlJU
2026-07-21 02:56:05,764:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-21 02:56:05,764:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-21 02:56:05,764:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-21 02:56:05,765:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-21 02:56:05,765:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-21 02:56:05,765:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-21 02:56:05,765:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/kFMzU4RZiwrqJYTbvWKIMqj65zY5EIYHDSy7zkB24qk
2026-07-21 02:56:05,766:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-21 02:56:05,766:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-21 02:56:05,768:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-21 02:56:05,768:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-21 02:56:05,769:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-21 02:56:05,769:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-21 02:56:05,769:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-21 02:56:05,769:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-21 02:56:05,769:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-21 14:44:06,821:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-21 14:44:06,821:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-21 14:44:06,821:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-21 14:44:06,823:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-21 14:44:06,839:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-21 14:44:06,842:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-21 14:44:06,843:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-21 14:44:06,867:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-21 14:44:06,870:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-21 14:44:06,870:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-21 14:44:06,870:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-21 14:44:06,870:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f15f01bea00>
Prep: True
2026-07-21 14:44:06,871:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f15f01bea00> and installer None
2026-07-21 14:44:06,871:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-21 14:44:06,931:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-21 14:44:06,931:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-21 14:44:06,936:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-21 14:44:07,362:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-21 14:44:07,363:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "rAzubD7_gVQ": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-21 14:44:07,364:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-21 14:44:07,369:DEBUG:acme.client:Requesting fresh nonce
2026-07-21 14:44:07,369:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-21 14:44:07,507:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-21 14:44:07,508:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 18:44:07 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2HYt73Pd5ALMDD6LXkEhVjjvxr4A6-efyH-ryNNMRKJw
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-21 14:44:07,509:DEBUG:acme.client:Storing nonce: YUeQbvp2HYt73Pd5ALMDD6LXkEhVjjvxr4A6-efyH-ryNNMRKJw
2026-07-21 14:44:07,509:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-21 14:44:07,511:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMkhZdDczUGQ1QUxNREQ2TFhrRWhWamp2eHI0QTYtZWZ5SC1yeU5OTVJLSnciLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "f7p7DsGBsjxwxQ0kGoljsq87qvbEMkazqNlkzg7_zS3MrW4SRItDqNb1vjaWqLhct4LiDccMTGl0ffHGszAad_qVchiS9jMMgdQ9So3vlgAbPa5sKTFuTlmsW_cGr5Pu3SXijj7vcD-zoRBxDMDqobLSQ_os8mqV61a1am-AbHlmVC7uTjx37kCH0XuBfKd2NUQn3SRPiixYTXsLxzhlq8Le8wHk1Ibn_isqVuwrJuBKuVuCCGkk6tWViJcc3gKP5Tg8jYXLSRlgElrCCCD4YG_ve_mZ214fgJfquJtxSM6O-fGVO1ipnvv3a35ef5Ie-weVJvBwP5BnSMv18hBSUw",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-21 14:44:07,732:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-21 14:44:07,733:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Tue, 21 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/535029394245
Replay-Nonce: DeP8OpbNUSh-usRI6p-R8qfLe6xnuNDXC-rTTm60QR-5tv38oik
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-28T18:44:07Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743762989295"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/535029394245"
}
2026-07-21 14:44:07,733:DEBUG:acme.client:Storing nonce: DeP8OpbNUSh-usRI6p-R8qfLe6xnuNDXC-rTTm60QR-5tv38oik
2026-07-21 14:44:07,733:DEBUG:acme.client:JWS payload:
b''
2026-07-21 14:44:07,734:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743762989295:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTlVTaC11c1JJNnAtUjhxZkxlNnhudU5EWEMtclRUbTYwUVItNXR2MzhvaWsiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQzNzYyOTg5Mjk1In0",
  "signature": "dM3-UF6bZtktceM4j_gcGfET14Y1iugFoETrNfbfxrp6PDr37oh1wKS3582g70IjCmL_YBm70u0GKgwIyxf6gzNZflrGS6ouFmDTItIZxlXsyl-uTUQBqmhacNTUtQbYuCwkNDWyPwnmss5ai3I7gQKkYSiYMC4N_rwZbPfUP13BOe3ARe7WQ6Tey1FM3lU5mI6b1Cz6oRB8Tf2IaSN7RWFeD4mHU7Q5lY-ob8XAGDbUEB3r4tVMj85pK9hC6tOU9osntp_EX0yL7nHx5B_fOp5I3CNlhdFVHHAe_TfdlzjOJeGEJRhVl353KNAer7AfmwDOLPRcYiqxSHvQAE5VYw",
  "payload": ""
}
2026-07-21 14:44:07,871:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/743762989295 HTTP/1.1" 200 822
2026-07-21 14:44:07,871:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2cb5m9SYLmCI8rQt1wKiUb6f597ajngs0tkGsLXHV4os
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-28T18:44:07Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/7t_5pA",
      "status": "pending",
      "token": "P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/-lsDrw",
      "status": "pending",
      "token": "P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/QKiFUg",
      "status": "pending",
      "token": "P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34"
    }
  ]
}
2026-07-21 14:44:07,871:DEBUG:acme.client:Storing nonce: YUeQbvp2cb5m9SYLmCI8rQt1wKiUb6f597ajngs0tkGsLXHV4os
2026-07-21 14:44:07,872:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-21 14:44:07,872:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-21 14:44:07,872:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-21 14:44:07,872:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-21 14:44:07,874:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34
2026-07-21 14:44:07,875:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-21 14:44:07,877:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/7t_5pA:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMmNiNW05U1lMbUNJOHJRdDF3S2lVYjZmNTk3YWpuZ3MwdGtHc0xYSFY0b3MiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQzNzYyOTg5Mjk1Lzd0XzVwQSJ9",
  "signature": "b94gZOgIC8uUzuAjzdA9UXiTrSfoDXH6-eBRtK0VM2IfebIinFOYTxXYxEKbpy5u9HFTrB91HGIYdzt4cOQM_utFULVFTSHcWWkH170Wlit-dk0HHicc3GfgE7Z8nj88JEZvf5pTtjuYGVnjj1H6wPCWZHJ6rllhNSU8f9RnLdRt6o2WO2qb1DvC6jc5HDPgVqZeeyhlmsH6xt0RZP7bWUm3kEhTnaA7MyZE6SsZSZIsCCFw3AhH5hstI-1NWMrZ0rQqNNMb3pwt7yh-b9IPfUwIQ1vC7GNvnNvoSsXj5aBsXLUcAHkruv9SROeCQY901UOOewP4Pt6b1g-FCVRGUw",
  "payload": "e30"
}
2026-07-21 14:44:08,028:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/743762989295/7t_5pA HTTP/1.1" 200 195
2026-07-21 14:44:08,029:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 18:44:07 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743762989295>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/7t_5pA
Replay-Nonce: YUeQbvp2ver4m5aR6X4swOFFpm7LDDEFUyaWUTCl6zoR-c3-YFY
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/7t_5pA",
  "status": "pending",
  "token": "P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34"
}
2026-07-21 14:44:08,030:DEBUG:acme.client:Storing nonce: YUeQbvp2ver4m5aR6X4swOFFpm7LDDEFUyaWUTCl6zoR-c3-YFY
2026-07-21 14:44:08,030:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-21 14:44:09,031:DEBUG:acme.client:JWS payload:
b''
2026-07-21 14:44:09,033:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/743762989295:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMnZlcjRtNWFSNlg0c3dPRkZwbTdMRERFRlV5YVdVVENsNnpvUi1jMy1ZRlkiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQzNzYyOTg5Mjk1In0",
  "signature": "Kp12Mov-P-ge8riu92byw70aOhltkZK3dmRltbMNOp2bSc6I1yq1ZNVxodt-AiN4g8mXPToBRAic5UCEASLI8lbCgwaugu-2miY8uIlz1Thl90fYuPBO4xTJE7VhcicjqnUEuwnZQ-K8oPRgxOBD4jHn9E6B2a6_5Iw57HibpnU6AB_wqvLW5jExZ4zTgDC3mv63mUudQUqffKG4bAT3KjKD3KlvQfK7lOx19OCNpII7koW4MFieX_oZ35sbobVk7O64qcUWBmV1eWBzaplJ8zsgnclnNaP8IigH86UTEqIsO28vzlDIGB5NmEaCiwxNmHREvnYiPOrSg6S3-jSP6A",
  "payload": ""
}
2026-07-21 14:44:09,179:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/743762989295 HTTP/1.1" 200 1032
2026-07-21 14:44:09,180:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Tue, 21 Jul 2026 18:44:09 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNTKZ_ypmXbhHR-_Lb8sT0jyajdb62E_Xif1HIdsv2kSk
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-28T18:44:07Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/743762989295/7t_5pA",
      "status": "invalid",
      "validated": "2026-07-21T18:44:07Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34: 404",
        "status": 403
      },
      "token": "P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-21 14:44:09,180:DEBUG:acme.client:Storing nonce: DeP8OpbNTKZ_ypmXbhHR-_Lb8sT0jyajdb62E_Xif1HIdsv2kSk
2026-07-21 14:44:09,181:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-21 14:44:09,181:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-21 14:44:09,181:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-21 14:44:09,182:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-21 14:44:09,182:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-21 14:44:09,182:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-21 14:44:09,182:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/P8a2gRZd9mv6D03JNQ1dzay10k3ee8LwFVZekw3yU34
2026-07-21 14:44:09,182:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-21 14:44:09,183:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-21 14:44:09,185:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-21 14:44:09,186:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-21 14:44:09,187:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-21 14:44:09,187:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-21 14:44:09,187:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-21 14:44:09,187:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-21 14:44:09,188:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-22 00:56:03,171:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-22 00:56:03,171:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-22 00:56:03,171:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-22 00:56:03,172:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-22 00:56:03,181:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-22 00:56:03,183:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-22 00:56:03,185:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-22 00:56:03,206:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-22 00:56:03,208:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-22 00:56:03,209:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-22 00:56:03,209:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-22 00:56:03,209:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f47bd615a00>
Prep: True
2026-07-22 00:56:03,209:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f47bd615a00> and installer None
2026-07-22 00:56:03,209:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-22 00:56:03,251:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-22 00:56:03,252:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-22 00:56:03,254:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-22 00:56:03,679:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-22 00:56:03,680:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 04:56:03 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "OFcs-vzD1XE": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-22 00:56:03,682:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-22 00:56:03,684:DEBUG:acme.client:Requesting fresh nonce
2026-07-22 00:56:03,684:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-22 00:56:03,821:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-22 00:56:03,821:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 04:56:03 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2lAdxWiUxJoAthAZFdfu4VFY2w-QxJ9u3otryesJs814
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-22 00:56:03,822:DEBUG:acme.client:Storing nonce: YUeQbvp2lAdxWiUxJoAthAZFdfu4VFY2w-QxJ9u3otryesJs814
2026-07-22 00:56:03,822:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-22 00:56:03,824:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMmxBZHhXaVV4Sm9BdGhBWkZkZnU0VkZZMnctUXhKOXUzb3RyeWVzSnM4MTQiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "i9YvoD-9kHHvd8PI3mBTcbu2EVNwvHe60MtdjjPYlgc6LFU15j3Fcbao9t8NQcbAZ2MBsvSjdq4OqcSroxvM5MaPxPgSI16deaBh33vNsTrLNCgbTpV7NjVf20daXsSiVaQ0saBpDIFarN0tiH_NsV5kKyR2fr1Ji70zOOw9u7H3KdrBe4ZCF7PWIC7yDyI36SAVPx416Z9PvZGopUMcGIs-7rm57IgjA6wCkbFl4U-MjvvBMw3CTD2S3lSadmD54PZuS0CAmakTqQFS7GNbBwiZNpB7XgHYc_GQ_z3MfgNhAIestGBOLo0NFwwM68rUYTYK1UJS-Hr8a59_-YVeZA",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-22 00:56:03,982:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-22 00:56:03,983:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Wed, 22 Jul 2026 04:56:03 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/535207365125
Replay-Nonce: DeP8OpbNzcQj-cgy-69cfS4mFPaO0tbvlOrIqzDY8z6EeFeAOl0
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-29T04:56:03Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744043251425"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/535207365125"
}
2026-07-22 00:56:03,983:DEBUG:acme.client:Storing nonce: DeP8OpbNzcQj-cgy-69cfS4mFPaO0tbvlOrIqzDY8z6EeFeAOl0
2026-07-22 00:56:03,983:DEBUG:acme.client:JWS payload:
b''
2026-07-22 00:56:03,984:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744043251425:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTnpjUWotY2d5LTY5Y2ZTNG1GUGFPMHRidmxPcklxekRZOHo2RWVGZUFPbDAiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0MDQzMjUxNDI1In0",
  "signature": "GzfPPPMAGy1mGG09CAMS0yb_GJOQ0MNjqXomCQMSaThqKJJZpb_jdXa-D9uSGBFC5TUaF1CAgAP5O_TIqIGWQ8Jr-ZSm3Yg6QHpIrqU1iGv7XPN1tnnUWRZyySNKFs8kQXeAiqL75NP0lnntedKbKY3oltqxD7Ipoe4luiHiDNZeVJn3NN-4fO0FzTjgYZUUT_ICx0Rhy-dL5AQUCMmI5DvaLezi_SSAiinls8e-sLuCEPUT891PeP5AZNau2tm4LLOLdboStm_UZ1-IGBP9okFJPfBrzNxklP1Ff2p-riSJDzBxAs9NLZpX_FdBF-o21Ztmdaf1-uYDnn_UH9XPyg",
  "payload": ""
}
2026-07-22 00:56:04,122:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744043251425 HTTP/1.1" 200 822
2026-07-22 00:56:04,123:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 04:56:04 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2VKKygGy1MDwbwUBr86STAfImKtbDFQAGmsfl3t8jQW8
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-29T04:56:03Z",
  "challenges": [
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/voSXbw",
      "status": "pending",
      "token": "8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/oFE_gw",
      "status": "pending",
      "token": "8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/0igVhw",
      "status": "pending",
      "token": "8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0"
    }
  ]
}
2026-07-22 00:56:04,123:DEBUG:acme.client:Storing nonce: YUeQbvp2VKKygGy1MDwbwUBr86STAfImKtbDFQAGmsfl3t8jQW8
2026-07-22 00:56:04,123:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-22 00:56:04,123:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-22 00:56:04,123:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-22 00:56:04,124:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-22 00:56:04,125:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0
2026-07-22 00:56:04,126:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-22 00:56:04,127:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/0igVhw:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMlZLS3lnR3kxTUR3YndVQnI4NlNUQWZJbUt0YkRGUUFHbXNmbDN0OGpRVzgiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ0MDQzMjUxNDI1LzBpZ1ZodyJ9",
  "signature": "Zkbx_oUGh0CMAljlrex4yMXhTq8MaiUuMfcgbCP0qiquA7kaB4V1xYHMHqROtlhCXMkDgfeoHe5dPmTdvh2jMN_bcZrqfxSkQF79gXUEejqg2hadphMGthipeQ20okp__8B0tY0FjJYVz7hl3KcJpKpY0-BfFdtSOo4_LtTO4C3HxYqz27avg8twCIMw39OZtdRooeGQN7BM4IJfE_e_2a5FcMz0222Bec_sUVsDeog_Z3FEkwHYO8AuEDxr592MszkoNUMo3ROriQRXFNW9wi8HhVuVEh_hdDhO2FpF8Rf-KMSIiTA-hP3yIArQ9fWAHmZzPK4K8sDHfsqEOChI2Q",
  "payload": "e30"
}
2026-07-22 00:56:04,286:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/744043251425/0igVhw HTTP/1.1" 200 195
2026-07-22 00:56:04,286:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 04:56:04 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744043251425>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/0igVhw
Replay-Nonce: YUeQbvp2nzxGXjvF58NoJdofapAof4GkvZmhd7fhlAIohw4IEOI
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/0igVhw",
  "status": "pending",
  "token": "8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0"
}
2026-07-22 00:56:04,286:DEBUG:acme.client:Storing nonce: YUeQbvp2nzxGXjvF58NoJdofapAof4GkvZmhd7fhlAIohw4IEOI
2026-07-22 00:56:04,287:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-22 00:56:05,288:DEBUG:acme.client:JWS payload:
b''
2026-07-22 00:56:05,289:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744043251425:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMm56eEdYanZGNThOb0pkb2ZhcEFvZjRHa3ZabWhkN2ZobEFJb2h3NElFT0kiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0MDQzMjUxNDI1In0",
  "signature": "WQjF7nNEhCeibakpapSsxB0qp0Wckxpj5TVu1KGfeBk17Hwx9Xodf2HGf9cs1PIwuOrXYST-GKdfHQ80WC4plIdwfFusyUh-18BYBW3mf5P7LzEO1auemM3ozRotB-NtnYGc5TkmGeQCo6wklkOa4R-4BLEZ9eiMg0ZeEODSSRo31bvFA0TQPxr_VYkAk8ASACkDJj7ujTDeABa6k1lXfkljy1k6uzoOXuctd-PRooYkRtsLawOcVuUemSY6lXBMrIN0P4nSc4ijjTRM9zUwtnJ7ncFsWGEV9PVZ-MeDP3TeJjwAmr8moCBdvxbcL-oRUjqN1cCRtsTQCcbHV6eAyQ",
  "payload": ""
}
2026-07-22 00:56:05,438:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744043251425 HTTP/1.1" 200 1032
2026-07-22 00:56:05,438:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 04:56:05 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNXOnlns111_oB4Fjdkk_auUhTUJksUd1IULDxi1mN3FU
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-29T04:56:03Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744043251425/0igVhw",
      "status": "invalid",
      "validated": "2026-07-22T04:56:04Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0: 404",
        "status": 403
      },
      "token": "8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-22 00:56:05,438:DEBUG:acme.client:Storing nonce: DeP8OpbNXOnlns111_oB4Fjdkk_auUhTUJksUd1IULDxi1mN3FU
2026-07-22 00:56:05,439:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-22 00:56:05,439:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-22 00:56:05,439:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-22 00:56:05,440:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-22 00:56:05,440:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-22 00:56:05,440:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-22 00:56:05,440:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/8lSOOHEt4z3DVk63Uw5q65IMTq6Zj8xrPmf-aahXqP0
2026-07-22 00:56:05,440:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-22 00:56:05,440:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-22 00:56:05,443:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-22 00:56:05,444:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-22 00:56:05,444:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-22 00:56:05,444:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-22 00:56:05,444:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-22 00:56:05,444:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-22 00:56:05,444:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-22 13:44:08,399:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-22 13:44:08,400:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-22 13:44:08,400:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-22 13:44:08,402:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-22 13:44:08,418:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-22 13:44:08,421:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-22 13:44:08,424:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-22 13:44:08,470:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-22 13:44:08,475:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-22 13:44:08,477:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-22 13:44:08,478:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-22 13:44:08,478:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f5415c88a00>
Prep: True
2026-07-22 13:44:08,481:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f5415c88a00> and installer None
2026-07-22 13:44:08,481:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-22 13:44:08,535:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-22 13:44:08,536:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-22 13:44:08,537:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-22 13:44:08,965:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-22 13:44:08,966:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 17:44:08 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "iwAsjlzr4Rc": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-22 13:44:08,967:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-22 13:44:08,968:DEBUG:acme.client:Requesting fresh nonce
2026-07-22 13:44:08,969:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-22 13:44:09,104:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-22 13:44:09,104:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 17:44:09 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2gdVPRN91M6AOfbBubB29zV-zunOht5pr9Bvkxl9vPdc
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-22 13:44:09,104:DEBUG:acme.client:Storing nonce: YUeQbvp2gdVPRN91M6AOfbBubB29zV-zunOht5pr9Bvkxl9vPdc
2026-07-22 13:44:09,105:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-22 13:44:09,108:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMmdkVlBSTjkxTTZBT2ZiQnViQjI5elYtenVuT2h0NXByOUJ2a3hsOXZQZGMiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "ZqRWPAHWiCxw3lF-eSpa4Z_TWV3VgxHr6WXHbrzkLZTWrO7-O_dimoT5I6ua_x6YzZ84QSUO2Eq7uRfHsc4-MuCmlIHzElvaFKUdz7cbDZ9hNEtnyF2zWo8I6R1yBsZjAEx_G7bBZFCS7YDbTf6HNdwSrqSsvnFMu7_VSncuXAZfBjVL8LpFJQVP0n5Fu4wdMGNPnWydVY6rcMVLFEeaHBRGDXRi8WOyWP229_WuaBm3w_HEeXJGnsTs01lVGw635FrFRGEFucETqKoPSFEtMBNbPd8vFh1wPa8HOzwcWZxUTnWtb2nVdmp5EOaUaKcXepesFsDsrvD-N_Kl4Q8NGQ",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-22 13:44:09,271:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-22 13:44:09,271:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Wed, 22 Jul 2026 17:44:09 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/535418818235
Replay-Nonce: DeP8OpbNnmZZuZartbmNXP4X4CHRjrgvy61roro9MdH8Rx-OCKk
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-29T17:44:09Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744378149805"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/535418818235"
}
2026-07-22 13:44:09,271:DEBUG:acme.client:Storing nonce: DeP8OpbNnmZZuZartbmNXP4X4CHRjrgvy61roro9MdH8Rx-OCKk
2026-07-22 13:44:09,272:DEBUG:acme.client:JWS payload:
b''
2026-07-22 13:44:09,273:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744378149805:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTm5tWlp1WmFydGJtTlhQNFg0Q0hSanJndnk2MXJvcm85TWRIOFJ4LU9DS2siLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0Mzc4MTQ5ODA1In0",
  "signature": "ZmxwH8LoIEspjTqfH1mRmz1GGEVDPF0ahyZ3TNni8BZVanuB2KdBNsVNF6v__10-yP9q1NBcdyFNnAbH_4alsa4wZsG6SpoBwc11mwtoeQRDHQWINhBvkcZWG4V88lp2c79nYq9m7ztB492fcw-YzEAMtYH9Gr09g69DCMyJ8l8eC5HWGWQg-2eTVfBCrjo_jwSEqBjwbWWxVn5PfvYiDW-O-VEdbc1fELCpRqdgBnj9GgVDII7A9RPr6JEwObp9HBCtvmZ3dzz87VfB257099jKzNHyZEG5L0sauQJCxae-AuUq_p78RiNUxx9yKxMsgSBivZSujO2svJ9sUURhpQ",
  "payload": ""
}
2026-07-22 13:44:09,414:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744378149805 HTTP/1.1" 200 822
2026-07-22 13:44:09,415:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 17:44:09 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNYDQT1qBKGUBy5qtVZUZS0Wp3TIbDgxSmsfMKKlwgQHM
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-29T17:44:09Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/09IwVw",
      "status": "pending",
      "token": "UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/kND9vg",
      "status": "pending",
      "token": "UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/UsZKiA",
      "status": "pending",
      "token": "UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo"
    }
  ]
}
2026-07-22 13:44:09,415:DEBUG:acme.client:Storing nonce: DeP8OpbNYDQT1qBKGUBy5qtVZUZS0Wp3TIbDgxSmsfMKKlwgQHM
2026-07-22 13:44:09,416:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-22 13:44:09,416:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-22 13:44:09,417:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-22 13:44:09,417:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-22 13:44:09,418:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo
2026-07-22 13:44:09,419:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-22 13:44:09,420:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/09IwVw:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTllEUVQxcUJLR1VCeTVxdFZaVVpTMFdwM1RJYkRneFNtc2ZNS0tsd2dRSE0iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ0Mzc4MTQ5ODA1LzA5SXdWdyJ9",
  "signature": "mZgzpjFi9lX5Mhj1GgFoyZZWgcM6dpBwSizu8Qis2Lba3FfAlEE2aRpSA2LYsJVn3J5b_K8B-_75WuDR57oEzaDa-UgPBTerj_bbSf9bFuRSkYXOPKQIB9zBFGlCjCVEjuMr7fBVgsi6Lj-qulN6V7OeZawKXCFAY8TYekw-V5qOUglQVHXp-0K6Fz3-IcTAu22VqwDxPDtwL7Vs0n3JgreejRNmgJZlzV9sNGtZjYjVOr74LaRWk8Dv12ZB80GAqk3XNcp2mq6gZ3nYTYhwSQWu51XzeHiDrL-fg3-srZLuQu_mBxai2h54FS0uuLjeJFSk5eOdt0_LLWOQbTW2Hg",
  "payload": "e30"
}
2026-07-22 13:44:09,560:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/744378149805/09IwVw HTTP/1.1" 200 195
2026-07-22 13:44:09,561:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 17:44:09 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744378149805>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/09IwVw
Replay-Nonce: DeP8OpbNSf64NqSaCC72RdfdnGqGPsmIV3FXkaB4s5SrwO-FDW0
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/09IwVw",
  "status": "pending",
  "token": "UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo"
}
2026-07-22 13:44:09,561:DEBUG:acme.client:Storing nonce: DeP8OpbNSf64NqSaCC72RdfdnGqGPsmIV3FXkaB4s5SrwO-FDW0
2026-07-22 13:44:09,561:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-22 13:44:10,561:DEBUG:acme.client:JWS payload:
b''
2026-07-22 13:44:10,563:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744378149805:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTlNmNjROcVNhQ0M3MlJkZmRuR3FHUHNtSVYzRlhrYUI0czVTcndPLUZEVzAiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0Mzc4MTQ5ODA1In0",
  "signature": "PbBs1QxAyoFujG5yRTk9x6ui6YLnAkdDa83CWOZqankFKKS7W6Xe7pkauG3vND29ADoHyZKOejiOzL_Awh0PIXkcH5YAkMHOyUioqfaopwqayGIl8JmC-3wxlkob173WHJ-JRhnQd-bhyg-u_Mp6sXy6fyvX3h_lc_yxsYX49Q8z8Z7pMDYn0ltdikV6jZxgq7bhfBpcOVaEuWc_Ro_DfDKJ99n58pppJvcUkNdXe195cmttKJ5rop4Q6ufPW2rPWOYg6kS9MXI2kI4sAlbaFurDNiLeXtz93rbnC7x770M-IOpA-gSQG9qaX47ezgBDXLQFOHz6Em2HO9kKgPgzhA",
  "payload": ""
}
2026-07-22 13:44:10,701:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744378149805 HTTP/1.1" 200 1032
2026-07-22 13:44:10,701:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Wed, 22 Jul 2026 17:44:10 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2qzJqNkBbC0FIY9xUrcY5YA9GQmQXEMBOMd6xe6VGX1U
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-29T17:44:09Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744378149805/09IwVw",
      "status": "invalid",
      "validated": "2026-07-22T17:44:09Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo: 404",
        "status": 403
      },
      "token": "UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-22 13:44:10,702:DEBUG:acme.client:Storing nonce: YUeQbvp2qzJqNkBbC0FIY9xUrcY5YA9GQmQXEMBOMd6xe6VGX1U
2026-07-22 13:44:10,702:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-22 13:44:10,702:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-22 13:44:10,702:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-22 13:44:10,703:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-22 13:44:10,703:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-22 13:44:10,703:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-22 13:44:10,703:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/UTe1igJ5Hl5l_4pojdd2kZgpBIG__pbKq7z5F1LUbeo
2026-07-22 13:44:10,703:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-22 13:44:10,704:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-22 13:44:10,706:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-22 13:44:10,707:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-22 13:44:10,707:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-22 13:44:10,707:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-22 13:44:10,707:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-22 13:44:10,707:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-22 13:44:10,708:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-23 01:56:04,905:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-23 01:56:04,906:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-23 01:56:04,906:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-23 01:56:04,907:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-23 01:56:04,918:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-23 01:56:04,919:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-23 01:56:04,923:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-23 01:56:04,946:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-23 01:56:04,948:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-23 01:56:04,948:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-23 01:56:04,949:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-23 01:56:04,949:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f0e9127da00>
Prep: True
2026-07-23 01:56:04,949:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f0e9127da00> and installer None
2026-07-23 01:56:04,949:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-23 01:56:04,988:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-23 01:56:04,988:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-23 01:56:04,990:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-23 01:56:05,415:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-23 01:56:05,416:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 05:56:05 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "c90MkWZmg24": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-23 01:56:05,417:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-23 01:56:05,419:DEBUG:acme.client:Requesting fresh nonce
2026-07-23 01:56:05,419:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-23 01:56:05,553:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-23 01:56:05,554:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 05:56:05 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNOjfRFgieZOxxdZPMaXlLmfMhAryLBrqkq32pwqFLrTo
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-23 01:56:05,554:DEBUG:acme.client:Storing nonce: DeP8OpbNOjfRFgieZOxxdZPMaXlLmfMhAryLBrqkq32pwqFLrTo
2026-07-23 01:56:05,554:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-23 01:56:05,556:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTk9qZlJGZ2llWk94eGRaUE1hWGxMbWZNaEFyeUxCcnFrcTMycHdxRkxyVG8iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "TbiTAsabrcfrsHxRKnzrAmR4v9650wsGQtlgb0WRxeJofdrU1BFrUQ40FL9RhHzltbQBtQjQT8cqXgOdGlU0ODdxZZZfiZREH2nNseAZpRUxX1jJMo5GQUYVE2mon4-fyFuToZDP6zhzEfDSa3JExHsAh9a6vzY5fUv9V6p4EzIagAdYRlpR5SdhWf0EBEYEYo2bFaFfoLNGN4966G0T-CM98vqiUGx1za5QdQuFCJtDo5KFNRoqE5cXjuG6w0g1reWVySmgzaM-CepOaoPaw54iEUP6r-WDtEg-H5fNZFxI0L7269tOyvEYL_w_IMisKpvOmHA55nUFDrmDr7ZsKw",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-23 01:56:05,711:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-23 01:56:05,711:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Thu, 23 Jul 2026 05:56:05 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/535630617505
Replay-Nonce: DeP8OpbNKOHVEVL9rOyyTs9QekEN_x0gg2jfE2aNTEKVLfol0qs
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-30T05:56:05Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744710509515"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/535630617505"
}
2026-07-23 01:56:05,712:DEBUG:acme.client:Storing nonce: DeP8OpbNKOHVEVL9rOyyTs9QekEN_x0gg2jfE2aNTEKVLfol0qs
2026-07-23 01:56:05,712:DEBUG:acme.client:JWS payload:
b''
2026-07-23 01:56:05,714:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744710509515:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTktPSFZFVkw5ck95eVRzOVFla0VOX3gwZ2cyamZFMmFOVEVLVkxmb2wwcXMiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0NzEwNTA5NTE1In0",
  "signature": "PLSF23cwpFF_Qoh2zVDtbj9uYa1k8cVorFP7riHAMjhgdQnT921v35nDxhthdxCtB-O_8gF3VOOFy5H5NHRVme00n6gPQ2jcSwBezUUWqFef88otH-RZ2UzDIOL1RlKwQy47kMflEaqdlB_KBQdhbvuF24h8wulcFGGRe3rJZmJ6vaChWYCp9i0ey4vRCIg9M2tMY3MZsqIPa018NJaWb7nt8oTYc06fyK5npxs3gwiRQMKoRQbWxmGzGFqWxxRGy9gbytxpV9UbN-b6XD3vng4_DXtpSUa--Z07T_aMXzWX3x2WISgcZJJ43Vb8HZ4OZTK-_LjWCtGqZu4259fXEA",
  "payload": ""
}
2026-07-23 01:56:05,854:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744710509515 HTTP/1.1" 200 822
2026-07-23 01:56:05,854:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 05:56:05 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2X3d0yS1dJ_U7zrXJLohSiiA1i_2GC6r1RAtaOliZNaU
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-30T05:56:05Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/r6mcPQ",
      "status": "pending",
      "token": "sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/mfEauA",
      "status": "pending",
      "token": "sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/YlOa9g",
      "status": "pending",
      "token": "sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q"
    }
  ]
}
2026-07-23 01:56:05,854:DEBUG:acme.client:Storing nonce: YUeQbvp2X3d0yS1dJ_U7zrXJLohSiiA1i_2GC6r1RAtaOliZNaU
2026-07-23 01:56:05,855:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-23 01:56:05,855:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-23 01:56:05,855:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-23 01:56:05,855:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-23 01:56:05,857:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q
2026-07-23 01:56:05,859:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-23 01:56:05,860:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/r6mcPQ:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMlgzZDB5UzFkSl9VN3pyWEpMb2hTaWlBMWlfMkdDNnIxUkF0YU9saVpOYVUiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ0NzEwNTA5NTE1L3I2bWNQUSJ9",
  "signature": "GIkKkEh-Lj7Jvt4KTBagGyg7SIUm6gL6NWgaxMW6cIQzaftVaM8DI56Og4Rnz6tUIpoonDKl9zrQHve-f06RDdELIQ9XvJdh48E9Ks37Lco3zRDnYVEaAR545lAYnHVJBSi0h6GMJXF81_Uam4C0ep58aLSxUTMG_oNGLEpAgyQl93wSMreNU4vNQRcsySDE9Q041VMdqnvdhwbFl58Yo841WmAaiXroR34NklRCmQb960kmZCUgexvTDCamChMQVkV1dV-CIapFS3Jkm_kZHfXHUblmP6N-V7_A90ORXGPN9dRBI-yuXNDT8gAIMkXo9xsMSs8xxrfdRlHvFySl7A",
  "payload": "e30"
}
2026-07-23 01:56:06,011:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/744710509515/r6mcPQ HTTP/1.1" 200 195
2026-07-23 01:56:06,012:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 05:56:05 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744710509515>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/r6mcPQ
Replay-Nonce: YUeQbvp2-teVetpPYcymOtLrjNEpCJWgaS--v9t3Pn36mBa4H24
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/r6mcPQ",
  "status": "pending",
  "token": "sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q"
}
2026-07-23 01:56:06,012:DEBUG:acme.client:Storing nonce: YUeQbvp2-teVetpPYcymOtLrjNEpCJWgaS--v9t3Pn36mBa4H24
2026-07-23 01:56:06,013:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-23 01:56:07,014:DEBUG:acme.client:JWS payload:
b''
2026-07-23 01:56:07,015:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744710509515:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMi10ZVZldHBQWWN5bU90THJqTkVwQ0pXZ2FTLS12OXQzUG4zNm1CYTRIMjQiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0NzEwNTA5NTE1In0",
  "signature": "B3lBcms2e2Iegy3wIYPioEHFWOFH4oyrX2hCtkZJsXFH3bDSOmN-IXjLuTfgc-gTLzbnU8H7r3caas9imbLgs5QVWlfWoswyrpLPKyM5V1v86BNyBEN5H8SK_q6GromaVGB_qqo9dGadMoSM-ZLLCEbtU9LIYFhUKr6ew2IzQ3BSJxBMEg3UrzZu-nzZ4XkU_at1pGUVZj2giCAxQRKjEyJR2UAC22OXqeRowEtCU6QNXN8dle_-NaGyd7KskT13aqhuSSXiE_fSH2AuOZeGgAabc7eq7Hdzaxomel4UP5cS83279y6u-1eW3zaYE5dwtniw_bPHymesilhyZ2tbLQ",
  "payload": ""
}
2026-07-23 01:56:07,155:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744710509515 HTTP/1.1" 200 1032
2026-07-23 01:56:07,155:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 05:56:07 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2KqdsIrOgk92hs85i3ZrWhRbOyk54wjpJqMhd3I5rucg
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-30T05:56:05Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744710509515/r6mcPQ",
      "status": "invalid",
      "validated": "2026-07-23T05:56:05Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q: 404",
        "status": 403
      },
      "token": "sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-23 01:56:07,155:DEBUG:acme.client:Storing nonce: YUeQbvp2KqdsIrOgk92hs85i3ZrWhRbOyk54wjpJqMhd3I5rucg
2026-07-23 01:56:07,155:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-23 01:56:07,156:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-23 01:56:07,156:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-23 01:56:07,156:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-23 01:56:07,156:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-23 01:56:07,156:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-23 01:56:07,157:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/sgS41b3i1L7teY1poWUIx6P3mAC8hvsP7g0tzye-p4Q
2026-07-23 01:56:07,157:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-23 01:56:07,157:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-23 01:56:07,159:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-23 01:56:07,160:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-23 01:56:07,160:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-23 01:56:07,160:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-23 01:56:07,160:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-23 01:56:07,160:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-23 01:56:07,160:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-23 12:26:37,318:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-23 12:26:37,318:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-23 12:26:37,318:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-23 12:26:37,319:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-23 12:26:37,330:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-23 12:26:37,331:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-23 12:26:37,333:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-23 12:26:37,357:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-23 12:26:37,359:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-23 12:26:37,359:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-23 12:26:37,359:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-23 12:26:37,359:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f037e9d8a00>
Prep: True
2026-07-23 12:26:37,359:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f037e9d8a00> and installer None
2026-07-23 12:26:37,360:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-23 12:26:37,402:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-23 12:26:37,403:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-23 12:26:37,405:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-23 12:26:37,837:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-23 12:26:37,837:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 16:26:37 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "baJMG7ZDgFw": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-23 12:26:37,839:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-23 12:26:37,843:DEBUG:acme.client:Requesting fresh nonce
2026-07-23 12:26:37,844:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-23 12:26:37,979:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-23 12:26:37,980:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 16:26:37 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2Md0iV0wGj5rC0KlzacGQlEax4C0vO1aGKgptDbYcyFo
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-23 12:26:37,980:DEBUG:acme.client:Storing nonce: YUeQbvp2Md0iV0wGj5rC0KlzacGQlEax4C0vO1aGKgptDbYcyFo
2026-07-23 12:26:37,980:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-23 12:26:37,982:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMk1kMGlWMHdHajVyQzBLbHphY0dRbEVheDRDMHZPMWFHS2dwdERiWWN5Rm8iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "MzuDIW_EBK51879EOOibGKje493OMGR-ggpbjlNwG49Aj698k373w_0KTj1vIMwH9QoXLIFzWbZaNI1m7RLf0sVDU66wj5OzZtS5F0gpqRIV8LwoSv_AztBOVKKDfomYDi5eFdJGwcHtHxFzQxRgX6nimtZcQxmeJpZMS9vg0sk18tuCaLVMtsYwKZisIB4TPXttg4BHUGaAocKPXfDbj_xNvexhKjjM8kPKw2TD8pH71Q8xj1vizNWkODRum3lymKhc8qoBLId3b1VADdNQ8hB-9g6qpfUiwiXJ9Di9OInSEjgspCY6IXUxv8xYgvodiveX7WN3mKaVHBXUn5iDjQ",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-23 12:26:38,142:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-23 12:26:38,143:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Thu, 23 Jul 2026 16:26:38 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/535807114525
Replay-Nonce: DeP8OpbNGfbfVqv2zt-QNkGTWa8K4IG9sTMhOlh8RlC03wSnP8U
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-30T16:26:38Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744988189135"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/535807114525"
}
2026-07-23 12:26:38,143:DEBUG:acme.client:Storing nonce: DeP8OpbNGfbfVqv2zt-QNkGTWa8K4IG9sTMhOlh8RlC03wSnP8U
2026-07-23 12:26:38,143:DEBUG:acme.client:JWS payload:
b''
2026-07-23 12:26:38,144:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744988189135:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTkdmYmZWcXYyenQtUU5rR1RXYThLNElHOXNUTWhPbGg4UmxDMDN3U25QOFUiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0OTg4MTg5MTM1In0",
  "signature": "h7sA2P2ZqulFHp83qUUjTZcTm4DiMtz8pUG4hD00_rRK0R2ft_rms4FuKuNU46uGy4iBAwAeaEPjbx0JmjQAsbcAQ4otKiwj0XYwF3cz6aA9YZ6HK7W_TnWQR49OlCYA1QqiBxNCZOCinZbaztndE0cp1lw-B1orVPLlCwVQLZZ53zyFhfz6UIomMTIcr7CyuHSugCnG_O-ITagK-mb1aG4o2o347_4pCcTX-5SAb3LfFqM3F0LFpuHZ2g7zyvXJrGHKAuNyrdllV1JLpyOdWM92-mzPDcduSsCfBQJ99PUqoiulfgbTySatUnYB4ZdhAzRRJz7UoqN9HE1y4Lq1qw",
  "payload": ""
}
2026-07-23 12:26:38,283:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744988189135 HTTP/1.1" 200 822
2026-07-23 12:26:38,283:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 16:26:38 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2onqNZibSz6foISEWBS_MmljroNlxuQ1EFT1l4lKuxzE
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-30T16:26:38Z",
  "challenges": [
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/tnbOHg",
      "status": "pending",
      "token": "-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/Npvxdw",
      "status": "pending",
      "token": "-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/LYNM1Q",
      "status": "pending",
      "token": "-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E"
    }
  ]
}
2026-07-23 12:26:38,284:DEBUG:acme.client:Storing nonce: YUeQbvp2onqNZibSz6foISEWBS_MmljroNlxuQ1EFT1l4lKuxzE
2026-07-23 12:26:38,284:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-23 12:26:38,284:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-23 12:26:38,285:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-23 12:26:38,285:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-23 12:26:38,287:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E
2026-07-23 12:26:38,288:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-23 12:26:38,289:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/LYNM1Q:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMm9ucU5aaWJTejZmb0lTRVdCU19NbWxqcm9ObHh1UTFFRlQxbDRsS3V4ekUiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ0OTg4MTg5MTM1L0xZTk0xUSJ9",
  "signature": "fTNVpqaqWbN8LybWMz7onT7HLbM6Ya7mfavu95lv5Tw-a2uchZzqRB0nWqf7klG9Iugh-esNlYuyKWMuK_ipglY4ET8I7_bcsBTcWh40NXTc49ZNg96K5MfJ5-LPnzpT397bYa6ZcNbMdiHwYOzxIJUbIF5ukZhiY5vXYOYJsWPjgreCzWKVuU2pdpwV8vSERnheiW_PjLI6-KDWQ358b8iKhE94OOb4wo8XMeLdzA5v9Ch1o9AYT1R8pF12R4yVCjA0ReLAHV55fM_nsl3jjH5CNRFq_gQSzSZg3K7xpkAY-LCMmtXdLNAtEP6c9R3DPwTDoumvwIcXnZIPd8kh1Q",
  "payload": "e30"
}
2026-07-23 12:26:38,430:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/744988189135/LYNM1Q HTTP/1.1" 200 195
2026-07-23 12:26:38,431:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 16:26:38 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744988189135>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/LYNM1Q
Replay-Nonce: DeP8OpbN0fAQhD1d5n5N3dp9Fz_BzBqg5_6HQyxat9_fbZxTA_c
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/LYNM1Q",
  "status": "pending",
  "token": "-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E"
}
2026-07-23 12:26:38,431:DEBUG:acme.client:Storing nonce: DeP8OpbN0fAQhD1d5n5N3dp9Fz_BzBqg5_6HQyxat9_fbZxTA_c
2026-07-23 12:26:38,432:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-23 12:26:39,434:DEBUG:acme.client:JWS payload:
b''
2026-07-23 12:26:39,435:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/744988189135:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTjBmQVFoRDFkNW41TjNkcDlGel9CekJxZzVfNkhReXhhdDlfZmJaeFRBX2MiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ0OTg4MTg5MTM1In0",
  "signature": "HxmaUDxoa1RXhzTGIhfAJQHboYPgetZ_sasnGt1doM8rUiBywDjib-UvcizolTQr12nfzrOqFuJKpS--rJ6lZomkzJRweNaDbvIEhErLMei3kE2zq1eTEV_EdWitCOZhiX7LDVD1r-cNqQFi8PGb-2npJE39aO9TMxRP412ueUqLWtRab_5VG9DNSDlqV3Z6jxOHbnUkqLMO4SZ12ODJZQcVIU7ZsO71HQ57lrGr3ZL2L0vFf3-1fkuLCQF-HwlaKWRe7bA2BexfmERcQcOTL8A9SFni1m1a3OEh67OYhlTJ6YKaFQI9ZGz6qDCU_eBtfEFobDs_ORpWXTi-bglY1w",
  "payload": ""
}
2026-07-23 12:26:39,574:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/744988189135 HTTP/1.1" 200 1032
2026-07-23 12:26:39,574:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Thu, 23 Jul 2026 16:26:39 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNHFAeRHArFM4hSgED8yFtQrIbpfLPLjvb5b4SHf76KX4
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-30T16:26:38Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/744988189135/LYNM1Q",
      "status": "invalid",
      "validated": "2026-07-23T16:26:38Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E: 404",
        "status": 403
      },
      "token": "-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-23 12:26:39,575:DEBUG:acme.client:Storing nonce: DeP8OpbNHFAeRHArFM4hSgED8yFtQrIbpfLPLjvb5b4SHf76KX4
2026-07-23 12:26:39,575:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-23 12:26:39,575:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-23 12:26:39,575:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-23 12:26:39,577:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-23 12:26:39,577:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-23 12:26:39,577:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-23 12:26:39,577:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/-N7vqLJA7g2rUD7dnJueqibDiretYr0sFlQc6uJGN1E
2026-07-23 12:26:39,577:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-23 12:26:39,578:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-23 12:26:39,579:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-23 12:26:39,580:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-23 12:26:39,580:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-23 12:26:39,581:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-23 12:26:39,581:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-23 12:26:39,581:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-23 12:26:39,581:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-24 02:44:06,640:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-24 02:44:06,640:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-24 02:44:06,640:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-24 02:44:06,641:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-24 02:44:06,657:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-24 02:44:06,660:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-24 02:44:06,663:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-24 02:44:06,688:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-24 02:44:06,690:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-24 02:44:06,690:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-24 02:44:06,691:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-24 02:44:06,691:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7fd87bdb4a00>
Prep: True
2026-07-24 02:44:06,691:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7fd87bdb4a00> and installer None
2026-07-24 02:44:06,691:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-24 02:44:06,745:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-24 02:44:06,746:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-24 02:44:06,749:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-24 02:44:07,169:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-24 02:44:07,170:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 06:44:07 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert",
  "x0G0YasiOe8": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417"
}
2026-07-24 02:44:07,171:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-24 02:44:07,173:DEBUG:acme.client:Requesting fresh nonce
2026-07-24 02:44:07,173:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-24 02:44:07,305:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-24 02:44:07,305:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 06:44:07 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: DeP8OpbNKhFLxg7D0bLPh8YfqKLhNXK2o_eO1snCeGCvUHr2zY4
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-24 02:44:07,306:DEBUG:acme.client:Storing nonce: DeP8OpbNKhFLxg7D0bLPh8YfqKLhNXK2o_eO1snCeGCvUHr2zY4
2026-07-24 02:44:07,306:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-24 02:44:07,308:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTktoRkx4ZzdEMGJMUGg4WWZxS0xoTlhLMm9fZU8xc25DZUdDdlVIcjJ6WTQiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "Hvk3gfXXBgTPLPmkFTt5gs_8lyPvKBeH0322tfu5Y2-p4dPM6w8hVo1I71vFzxeajq2NpYRJ50eVOeKlxz_Q_A3AZ7763uToCcn-oEHwUp18IzOtxSke8NfYu2jf987GWJSXE553l3Mna5rb4hLhblMb6o8g_qUhRgQVhyMWBTxG78u_dUhNYxS94EJuxjkjY0UenApOtFUb97OMcosNLLr86_RkSGsc0Zxwhvwu0EvsB5Uso_qrwTb5DpGmPSY6qcFJVEXabGwQvshQGkR-F5K2PmcWAdgikSGmUrsIL24Nf9rnk8-2K51mNZild4zEuAKBZa66XFfRlUvVMX8WPQ",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-24 02:44:07,464:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-24 02:44:07,465:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Fri, 24 Jul 2026 06:44:07 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/536051583515
Replay-Nonce: YUeQbvp20YYovfjwvOvtSw3H3JMfnyaHLPCuOdaSRo0HTztOMoQ
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-31T06:44:07Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745372523205"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/536051583515"
}
2026-07-24 02:44:07,465:DEBUG:acme.client:Storing nonce: YUeQbvp20YYovfjwvOvtSw3H3JMfnyaHLPCuOdaSRo0HTztOMoQ
2026-07-24 02:44:07,465:DEBUG:acme.client:JWS payload:
b''
2026-07-24 02:44:07,467:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745372523205:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMjBZWW92Zmp3dk92dFN3M0gzSk1mbnlhSExQQ3VPZGFTUm8wSFR6dE9Nb1EiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ1MzcyNTIzMjA1In0",
  "signature": "GDr-Rk1NkvuwE-vaY8eby0YcoA5TpM3kIQyOF1wNQocT7DVRNGsF5_jLqghFR1NKcNvocxKtFA9hlM-QD_gQj3H4-wioq4qWjq9zTKHTB8EcLC9Ez4u7yOdDVLrLDWU76Dn6YFUj1rhy-k09kb1pdT-kafG7gh9hs1RfBY-N06qzoEwckQQStIb-uR7d8IMuR9fSI7v3H3ZAYmj1L-hEH8wEfwgnN0KYelh1-wZ3Gu4FnXP7nHCOxYqiIWeB5GGVNWvl_q7Yz9bCGAkLMG1tGUe4swL25VeaVTFfgXUb8opuLigxAq7OyWampKPadTMTD6eQypQYT9cdXBpgzLe5Rg",
  "payload": ""
}
2026-07-24 02:44:07,605:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/745372523205 HTTP/1.1" 200 822
2026-07-24 02:44:07,605:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 06:44:07 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2AxUNwr8r4f19vfh7OG75A_cHQxaUpgDl50VpNU-KipU
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-31T06:44:07Z",
  "challenges": [
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/2-Ua0Q",
      "status": "pending",
      "token": "rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/doGOPA",
      "status": "pending",
      "token": "rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/BYnCVw",
      "status": "pending",
      "token": "rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8"
    }
  ]
}
2026-07-24 02:44:07,605:DEBUG:acme.client:Storing nonce: YUeQbvp2AxUNwr8r4f19vfh7OG75A_cHQxaUpgDl50VpNU-KipU
2026-07-24 02:44:07,606:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-24 02:44:07,606:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-24 02:44:07,606:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-24 02:44:07,606:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-24 02:44:07,608:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8
2026-07-24 02:44:07,608:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-24 02:44:07,610:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/BYnCVw:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJZVWVRYnZwMkF4VU53cjhyNGYxOXZmaDdPRzc1QV9jSFF4YVVwZ0RsNTBWcE5VLUtpcFUiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ1MzcyNTIzMjA1L0JZbkNWdyJ9",
  "signature": "l4pKKjsRtVSEH-IhpYImVnDVD20Xc0tTRoVppy77c6PAwkmI2OxH35kK4zazOyAGMP_YfLei6F0UypqU0nlOLCef1nn5WyRKezjb5HjMkG6yJ-o_tUzK95Ab_Hf9ciSxFbYCb6JN1L3y86CR4WTI30DmJf9nOmSSQUbmLDhMaGx6Dql6CdCOojrfLTZqEGBdQY21xJZN70QvrsA3nbRld4WaPZB5S2f_n_f_7SE91-sQiSJsieP27Pkw1axBQlDXeFVIucMDLxklSakrM9foYDmB21aXC-oFyX3FSvrZ57bF8--5yGfVQsHjyf1s9n_wIrPIu6-R85Vp6a2tNZovIw",
  "payload": "e30"
}
2026-07-24 02:44:07,759:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/745372523205/BYnCVw HTTP/1.1" 200 195
2026-07-24 02:44:07,760:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 06:44:07 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745372523205>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/BYnCVw
Replay-Nonce: DeP8OpbND1FcNGzNVi3Q3RnaaCjkV5vOVxghb69W7eMc1s7sf2k
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/BYnCVw",
  "status": "pending",
  "token": "rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8"
}
2026-07-24 02:44:07,760:DEBUG:acme.client:Storing nonce: DeP8OpbND1FcNGzNVi3Q3RnaaCjkV5vOVxghb69W7eMc1s7sf2k
2026-07-24 02:44:07,760:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-24 02:44:08,761:DEBUG:acme.client:JWS payload:
b''
2026-07-24 02:44:08,762:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745372523205:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJEZVA4T3BiTkQxRmNOR3pOVmkzUTNSbmFhQ2prVjV2T1Z4Z2hiNjlXN2VNYzFzN3NmMmsiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ1MzcyNTIzMjA1In0",
  "signature": "QzhbpWc4hiy6y10tvcgSMBruBF99RGHMKKWe56Bl2DIkU7ttt9YI0wMYX1PBE28f20ELW5hSNBfLJwlXixQpKq85HbzVp2z8jrRIzx-QsS0t7tCZrMVxC7-3dX_PRpFbYeIFFrDrUpQ9Ac7CepVHl_lZchuVOQVCjkbwzKKL_0vAyhV1r5kypN5ygL0YGrGq6MjTWy5_ZSLzgmDVitrleOozGBgTirqfDBuxUctDjcS64IsX_8Tb8u7LI0Q6b4WWbZzh3PaAIKj9nHZlJdhFo0wCM-wq4ND-RPI83cj9iRxMDRJqab_CFmTCrtYXE1cYIr6dpihTTDJqpcsUku7MUw",
  "payload": ""
}
2026-07-24 02:44:08,902:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/745372523205 HTTP/1.1" 200 1032
2026-07-24 02:44:08,903:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 06:44:08 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: YUeQbvp2IZx0XOwLosc7UUi_gjFrIT8oS7CsjP-WM1wWGvtF8zQ
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-31T06:44:07Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745372523205/BYnCVw",
      "status": "invalid",
      "validated": "2026-07-24T06:44:07Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8: 404",
        "status": 403
      },
      "token": "rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-24 02:44:08,903:DEBUG:acme.client:Storing nonce: YUeQbvp2IZx0XOwLosc7UUi_gjFrIT8oS7CsjP-WM1wWGvtF8zQ
2026-07-24 02:44:08,903:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-24 02:44:08,903:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-24 02:44:08,903:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-24 02:44:08,904:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-24 02:44:08,904:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-24 02:44:08,904:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-24 02:44:08,904:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/rxYMARUTAYhY3-_hXPl5BIO_K_1EHudsW2-N9wtEZN8
2026-07-24 02:44:08,905:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-24 02:44:08,905:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-24 02:44:08,907:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-24 02:44:08,907:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-24 02:44:08,907:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-24 02:44:08,907:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-24 02:44:08,908:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-24 02:44:08,908:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-24 02:44:08,908:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-24 15:56:02,753:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-24 15:56:02,753:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-24 15:56:02,753:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-24 15:56:02,755:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-24 15:56:02,768:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-24 15:56:02,772:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-24 15:56:02,775:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-24 15:56:02,805:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-24 15:56:02,807:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-24 15:56:02,807:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-24 15:56:02,808:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-24 15:56:02,808:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7ff3f444fa00>
Prep: True
2026-07-24 15:56:02,808:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7ff3f444fa00> and installer None
2026-07-24 15:56:02,808:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-24 15:56:02,854:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-24 15:56:02,855:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-24 15:56:02,857:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-24 15:56:03,279:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-24 15:56:03,280:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 19:56:03 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "HgH4nHYRG2c": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-24 15:56:03,281:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-24 15:56:03,283:DEBUG:acme.client:Requesting fresh nonce
2026-07-24 15:56:03,283:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-24 15:56:03,416:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-24 15:56:03,417:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 19:56:03 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: -zoI5xr2-rvLiZwlVXlUkPNoZPmHdClCHB4d6No0OllZk5zwIPM
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-24 15:56:03,417:DEBUG:acme.client:Storing nonce: -zoI5xr2-rvLiZwlVXlUkPNoZPmHdClCHB4d6No0OllZk5zwIPM
2026-07-24 15:56:03,417:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-24 15:56:03,419:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICItem9JNXhyMi1ydkxpWndsVlhsVWtQTm9aUG1IZENsQ0hCNGQ2Tm8wT2xsWms1endJUE0iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "FiLbuqZ2oFjLkQ8jN7LtXSSf4WsjXUm5CkhBKgf0_AeUgLRlfVC9LhGlZLI_VBBPk5XjQho67PsucsW85vHy86pfWZPQkGkuRcu1MNidMBgmPLvBRYToXftPYaPrCThj-1d_T0hkltPi4IBcVCPr-rBcnENwMQu7lFoTPPSbStkX6qQD0SqKtmLuTdGp8svKzSCAedpbffxr9qZpzN5DNo3br6PEyFhwyqf6aerBQitU1z5LG4woSaiJXqtUBB043By3HcYMpUUfaylmGXiIGgz9Mu_GEL6xdOj2sWqM8K1tdJL5aJQ0mpfi85T4V2wUwimAYOvxIV-Xddlbwg5vcQ",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-24 15:56:03,574:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-24 15:56:03,575:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Fri, 24 Jul 2026 19:56:03 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/536266078175
Replay-Nonce: QSsEHsAEAjXesa69F6tjdd--4dfWK_VUTMOXDneCCa8kwY-2gcA
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-07-31T19:56:03Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745713068235"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/536266078175"
}
2026-07-24 15:56:03,575:DEBUG:acme.client:Storing nonce: QSsEHsAEAjXesa69F6tjdd--4dfWK_VUTMOXDneCCa8kwY-2gcA
2026-07-24 15:56:03,575:DEBUG:acme.client:JWS payload:
b''
2026-07-24 15:56:03,578:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745713068235:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJRU3NFSHNBRUFqWGVzYTY5RjZ0amRkLS00ZGZXS19WVVRNT1hEbmVDQ2E4a3dZLTJnY0EiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ1NzEzMDY4MjM1In0",
  "signature": "Hgc5EIHGHGuDE8gW5_r98NSzlVZBASvGdxwIx7-RLjfV7ggdEfF7JWUzS9h3g_LHnvxh3adsc_RiCCZhg9zjY7hou28TgZsl-Z09sP6VJJog7mQ7BGlGQ44cxDHj61aTNFSNAwkbIMRC4RQ-o1Axadkxwi0JjSQPo8R7hfI6F0AO9hqepwD8-W_dn7pGFqvOSEdU7NSpF-tP_rAW4vAv76XC_6uBsmajxp2ZqfrKwAt5ARYqECDX3MnhfuaJ9Dxax0WfgZR676TEcdoH7_P7wmUBTazvpeSDtgJxCGZbeurx_aLWujEJLNNdfi9k_wh92dV-ZJeWF9nKSfIY4yghXA",
  "payload": ""
}
2026-07-24 15:56:03,715:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/745713068235 HTTP/1.1" 200 822
2026-07-24 15:56:03,716:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 19:56:03 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: QSsEHsAEEFBli7meGa44OjPpUfw6GGg_YuJcBP2HDmy6Q_KIhxI
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-07-31T19:56:03Z",
  "challenges": [
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/ijILtg",
      "status": "pending",
      "token": "looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/E00s1A",
      "status": "pending",
      "token": "looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/wsTx3A",
      "status": "pending",
      "token": "looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A"
    }
  ]
}
2026-07-24 15:56:03,716:DEBUG:acme.client:Storing nonce: QSsEHsAEEFBli7meGa44OjPpUfw6GGg_YuJcBP2HDmy6Q_KIhxI
2026-07-24 15:56:03,716:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-24 15:56:03,716:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-24 15:56:03,716:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-24 15:56:03,717:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-24 15:56:03,718:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A
2026-07-24 15:56:03,719:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-24 15:56:03,720:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/E00s1A:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJRU3NFSHNBRUVGQmxpN21lR2E0NE9qUHBVZnc2R0dnX1l1SmNCUDJIRG15NlFfS0loeEkiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ1NzEzMDY4MjM1L0UwMHMxQSJ9",
  "signature": "sD-lI0wqXeOLCB9rG2Hd6TxDM8Uextl1mB3XtmahOVWXZq0v_81DnZaWFolo9Trd_mSMrXF93TMotgB_xsYUnj4zpHYyUmnSfbxxcatXbkm15XhlBY9n7rx03Q2DKS4TBVSo4hDiQlO0_qV2JLb9tXnyeszliSSkosU1NhcKqCJGUGINajHf70kIEI52W-TmshVg_GAJbfWXiMfB4djpcPam9utDA3srN_SH3B5Ay5zHQ5Kg3lVFrBlU4kcIGeneOf-xH3Jf2dbcrYW6Sh1mi3SON-h1C8Gi4anhxtN9_NC9ZNDLiK7eUAkbjX4IjA_XOO0ZVRQJZnWBI7GasV4pPg",
  "payload": "e30"
}
2026-07-24 15:56:03,857:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/745713068235/E00s1A HTTP/1.1" 200 195
2026-07-24 15:56:03,858:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 19:56:03 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745713068235>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/E00s1A
Replay-Nonce: QSsEHsAE87Aey2kKZe-2qL30m6NIxfDBRAWqTyWn1KBnbkTlubo
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/E00s1A",
  "status": "pending",
  "token": "looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A"
}
2026-07-24 15:56:03,858:DEBUG:acme.client:Storing nonce: QSsEHsAE87Aey2kKZe-2qL30m6NIxfDBRAWqTyWn1KBnbkTlubo
2026-07-24 15:56:03,859:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-24 15:56:04,859:DEBUG:acme.client:JWS payload:
b''
2026-07-24 15:56:04,860:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745713068235:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJRU3NFSHNBRTg3QWV5MmtLWmUtMnFMMzBtNk5JeGZEQlJBV3FUeVduMUtCbmJrVGx1Ym8iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ1NzEzMDY4MjM1In0",
  "signature": "Gp24fWlutPTvPMw9UJyx9winI2e9e2UC-JOy3pTP0hxxq_1Ff4Rmas8goYR0QOgiHX7lSZChE_FMWrFrg45muVWLTB5qIxzsDe21cnJ4H31Z7cSDtReFA51YcFIzg8X72biA5IHk4WDUEfMsC6g5i9svrYn34hKEOJBQb7f86iHpt8KsnzL4-abDfOUTNTyVM1Ci88VwMY0KI6C2XnfVA9M6PMDexShZX7BLMQNkxeNlXzxyIik5IYt49kFOX9R85H5jqJLUZLC_lD3YXbRAUQ6Q8Bl3pvh-7JqRVTaXmd5P5kQRGe1TlIP1_gkk1y6hICRCIXaUIewtbIM1IlYMmg",
  "payload": ""
}
2026-07-24 15:56:04,997:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/745713068235 HTTP/1.1" 200 1032
2026-07-24 15:56:04,998:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Fri, 24 Jul 2026 19:56:04 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: -zoI5xr24WKMJQEji3VOC6ZHLrSDAJ93Re-JqE6PxtnqGN_RmZ4
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-07-31T19:56:03Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745713068235/E00s1A",
      "status": "invalid",
      "validated": "2026-07-24T19:56:03Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A: 404",
        "status": 403
      },
      "token": "looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-24 15:56:04,999:DEBUG:acme.client:Storing nonce: -zoI5xr24WKMJQEji3VOC6ZHLrSDAJ93Re-JqE6PxtnqGN_RmZ4
2026-07-24 15:56:04,999:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-24 15:56:04,999:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-24 15:56:05,000:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-24 15:56:05,002:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-24 15:56:05,002:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-24 15:56:05,002:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-24 15:56:05,002:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/looBT4rixh5Khex58wVZblMygxgQtx8NgCvVj17_I_A
2026-07-24 15:56:05,002:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-24 15:56:05,002:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-24 15:56:05,006:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-24 15:56:05,008:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-24 15:56:05,009:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-24 15:56:05,009:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-24 15:56:05,009:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-24 15:56:05,010:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-24 15:56:05,011:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-25 00:44:09,595:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-25 00:44:09,595:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-25 00:44:09,595:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-25 00:44:09,600:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-25 00:44:09,634:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-25 00:44:09,636:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-25 00:44:09,639:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-25 00:44:09,685:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-25 00:44:09,688:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-25 00:44:09,689:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-25 00:44:09,689:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-25 00:44:09,689:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f5ccbaa0a00>
Prep: True
2026-07-25 00:44:09,689:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f5ccbaa0a00> and installer None
2026-07-25 00:44:09,690:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-25 00:44:09,774:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-25 00:44:09,775:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-25 00:44:09,777:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-25 00:44:10,173:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-25 00:44:10,175:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 04:44:10 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "9-qxGMhg5YE": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-25 00:44:10,176:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-25 00:44:10,178:DEBUG:acme.client:Requesting fresh nonce
2026-07-25 00:44:10,178:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-25 00:44:10,301:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-25 00:44:10,301:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 04:44:10 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: VnRLvUymHaYWEfmhucsD6sWl0qXGJpNIOlPGRe0ChcQjI_kd52c
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-25 00:44:10,301:DEBUG:acme.client:Storing nonce: VnRLvUymHaYWEfmhucsD6sWl0qXGJpNIOlPGRe0ChcQjI_kd52c
2026-07-25 00:44:10,302:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-25 00:44:10,303:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJWblJMdlV5bUhhWVdFZm1odWNzRDZzV2wwcVhHSnBOSU9sUEdSZTBDaGNRaklfa2Q1MmMiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "n5elhtQWhfcd8YQUMJGqcCdKL8KgFRpp1AYfHVOBTpbMd8OOjap57x2SKb47vSN_LKmaYrMOoy5zlEdWW31SAJQUN0K7_7BBoq1pCboVe3yMhxMi8sRd80lzui7rWvzRA5s-aoiStsoA07agvhMZ282aXeePOuV2kL8tsoIIGGfSigzhrmRPDh8bybVKv346TH9_Jm7qJwIa2XAkaI-dOvgJM3D-0nrwf0BJ_BeDJMuQ7koxXc3rjh2tjaN6VbogG8pbZZUaAwI5u5PV0sEA2D5ZUNJSIvouqU5sJR_Yd5Cb6xeD_boMNFYZYLFwJWcXWedHHEQRaOpGMX0LslWyVA",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-25 00:44:10,528:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-25 00:44:10,529:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Sat, 25 Jul 2026 04:44:10 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/536416484245
Replay-Nonce: VnRLvUymvjKRoIEPYmXTHV1dS5iEXoyKQBao-ldW82cbGPdd1Rs
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-08-01T04:44:10Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745952869045"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/536416484245"
}
2026-07-25 00:44:10,529:DEBUG:acme.client:Storing nonce: VnRLvUymvjKRoIEPYmXTHV1dS5iEXoyKQBao-ldW82cbGPdd1Rs
2026-07-25 00:44:10,529:DEBUG:acme.client:JWS payload:
b''
2026-07-25 00:44:10,530:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745952869045:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJWblJMdlV5bXZqS1JvSUVQWW1YVEhWMWRTNWlFWG95S1FCYW8tbGRXODJjYkdQZGQxUnMiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ1OTUyODY5MDQ1In0",
  "signature": "WGhQBVVJSEDJIcG4Z0F2eP6Zky23oAS3D9mIzdcEEIS9D0g2G02Jy_nJHK8Sileaj9zyNcUPhfeqQVQId0LCOJK00KJcRfF-CzIKZZ9xRNFzFHOrFUXSjXdrgO5aBNwgJt5N47aCm5-LdmXbOyiobDCZ0do1OxXngyn1y4fKOt1VyrUIOSJW5ojTSxaaS3dbjAHB1vfYur9WNVtyjcXW3TgkiwxKgbc4CwGuP8FEUvuRzQ6VDydxv5q6yKM4pHv03IMZLN9QUoZCoo5GyDo8s5nz2R8_A8PUpdISqRIlY7vpI3ToML2MXW3p61LY61tuj_B6eIwMrKSkDZCkL1NcHg",
  "payload": ""
}
2026-07-25 00:44:10,656:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/745952869045 HTTP/1.1" 200 822
2026-07-25 00:44:10,656:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 04:44:10 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: H1zRXMT9zdj3dyZOA7C4lNT75PrLPI16OFiv8O4fMwo9EPVGTDM
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-08-01T04:44:10Z",
  "challenges": [
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/o8lR5w",
      "status": "pending",
      "token": "o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/kiTalg",
      "status": "pending",
      "token": "o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50"
    },
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/JiVOqQ",
      "status": "pending",
      "token": "o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50"
    }
  ]
}
2026-07-25 00:44:10,656:DEBUG:acme.client:Storing nonce: H1zRXMT9zdj3dyZOA7C4lNT75PrLPI16OFiv8O4fMwo9EPVGTDM
2026-07-25 00:44:10,657:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-25 00:44:10,657:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-25 00:44:10,657:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-25 00:44:10,657:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-25 00:44:10,658:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50
2026-07-25 00:44:10,659:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-25 00:44:10,660:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/JiVOqQ:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJIMXpSWE1UOXpkajNkeVpPQTdDNGxOVDc1UHJMUEkxNk9GaXY4TzRmTXdvOUVQVkdURE0iLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ1OTUyODY5MDQ1L0ppVk9xUSJ9",
  "signature": "OeLMPXthvbQwJTHSVYiDL-2P_ca_c3JOX9IBaYsY6nAlRITgxnxNHwypp3BUoqIxrqfwjOrEftqZ5yhE_Qe1m7wcmQqIvOJ39vE4X8b287PwiTHzkfCXtJOcoczX5BUYwvYvEqG7LS_lXBTq7g6cF6BJImRnpQID54xiQlByFJCW2CTNKcIEtLEbAXOsALulUeRV6UGCnaZ1EmiYhmckAjoAcVzQehlF5vloXUPzrpotiKbZqsHlsCVqjxmXiPXlyuJTeP8d6h9cAqu9s0vYsApz2odUWf7A4wIbKezROaI5UNjIjF9gUWqY3XLsrWWLOTBmKE006PmaOgqbcqmmMg",
  "payload": "e30"
}
2026-07-25 00:44:10,786:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/745952869045/JiVOqQ HTTP/1.1" 200 195
2026-07-25 00:44:10,787:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 04:44:10 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745952869045>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/JiVOqQ
Replay-Nonce: VnRLvUym8Lh7BwKmzyyNAFrVPSpl9OX2Ncz0izwNiKDE78XCYHw
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/JiVOqQ",
  "status": "pending",
  "token": "o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50"
}
2026-07-25 00:44:10,787:DEBUG:acme.client:Storing nonce: VnRLvUym8Lh7BwKmzyyNAFrVPSpl9OX2Ncz0izwNiKDE78XCYHw
2026-07-25 00:44:10,787:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-25 00:44:11,789:DEBUG:acme.client:JWS payload:
b''
2026-07-25 00:44:11,790:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/745952869045:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJWblJMdlV5bThMaDdCd0ttenl5TkFGclZQU3BsOU9YMk5jejBpendOaUtERTc4WENZSHciLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ1OTUyODY5MDQ1In0",
  "signature": "aMxRk6TQpzfdqLM8WuEYsgskrJL69JzXNaxctu0YDlZlJnUIp3mz0e5qbxY1DfYAV70BXPWORdz5QMhX7KX2UowJ4-bBwd0Q_m_BjaF-_dBxh3PYHwYP1tt-H6gcVl7Wa1T2ybm1GakVp4phYsErgNutDrjArzYKbaYzsy3QI0ggtzJyM9pI0vb_OO7gz-Clz108nD_68NK_ow-Bzs8wn-13AJFEk4sBJmpTuRyKjktjdlmfQPGHKsbjd9vuCkueWVTSdy5LZQMvOhQB1mg02lsYVe5bj_S05jO5z4YDjYAIhd4FybjFBvJnlcTI0VOJfeOOn0Ltpw8iQOXGWcFK9w",
  "payload": ""
}
2026-07-25 00:44:11,928:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/745952869045 HTTP/1.1" 200 1032
2026-07-25 00:44:11,929:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 04:44:11 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: H1zRXMT9vm5nNsmmWaWTmAhyoYLhiAT_k92c6q-ELkbqeie4uLU
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-08-01T04:44:10Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/745952869045/JiVOqQ",
      "status": "invalid",
      "validated": "2026-07-25T04:44:10Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50: 404",
        "status": 403
      },
      "token": "o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-25 00:44:11,929:DEBUG:acme.client:Storing nonce: H1zRXMT9vm5nNsmmWaWTmAhyoYLhiAT_k92c6q-ELkbqeie4uLU
2026-07-25 00:44:11,929:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-25 00:44:11,929:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-25 00:44:11,930:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-25 00:44:11,931:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-25 00:44:11,931:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-25 00:44:11,931:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-25 00:44:11,931:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/o9OB3NMPn4EzRS8k8KIVl0HkRj7QA6rJEeMyCHvqu50
2026-07-25 00:44:11,931:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-25 00:44:11,932:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-25 00:44:11,934:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-25 00:44:11,935:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-25 00:44:11,935:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-25 00:44:11,935:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-25 00:44:11,935:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-25 00:44:11,936:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-25 00:44:11,936:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)
2026-07-25 14:44:09,031:DEBUG:certbot._internal.main:certbot version: 3.1.0
2026-07-25 14:44:09,031:DEBUG:certbot._internal.main:Location of certbot entry point: /usr/bin/certbot
2026-07-25 14:44:09,031:DEBUG:certbot._internal.main:Arguments: ['--noninteractive', '--no-random-sleep-on-renew']
2026-07-25 14:44:09,032:DEBUG:certbot._internal.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#manual,PluginEntryPoint#null,PluginEntryPoint#standalone,PluginEntryPoint#webroot)
2026-07-25 14:44:09,040:DEBUG:certbot._internal.log:Root logging level set at 30
2026-07-25 14:44:09,041:DEBUG:certbot._internal.display.obj:Notifying user: Processing /etc/letsencrypt/renewal/mail.espica.me.conf
2026-07-25 14:44:09,044:DEBUG:certbot._internal.plugins.selection:Requested authenticator None and installer None
2026-07-25 14:44:09,064:INFO:certbot.ocsp:Cannot extract OCSP URI from /etc/letsencrypt/archive/mail.espica.me/cert1.pem
2026-07-25 14:44:09,067:DEBUG:certbot._internal.storage:Should renew, less than 30 days before certificate expiry 2026-08-11 23:31:43 UTC.
2026-07-25 14:44:09,067:INFO:certbot._internal.renewal:Certificate is due for renewal, auto-renewing...
2026-07-25 14:44:09,067:DEBUG:certbot._internal.plugins.selection:Requested authenticator webroot and installer None
2026-07-25 14:44:09,067:DEBUG:certbot._internal.plugins.selection:Single candidate plugin: * webroot
Description: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).
Interfaces: Authenticator, Plugin
Entry point: EntryPoint(name='webroot', value='certbot._internal.plugins.webroot:Authenticator', group='certbot.plugins')
Initialized: <certbot._internal.plugins.webroot.Authenticator object at 0x7f556fae0a00>
Prep: True
2026-07-25 14:44:09,068:DEBUG:certbot._internal.plugins.selection:Selected authenticator <certbot._internal.plugins.webroot.Authenticator object at 0x7f556fae0a00> and installer None
2026-07-25 14:44:09,068:INFO:certbot._internal.plugins.selection:Plugins selected: Authenticator webroot, Installer None
2026-07-25 14:44:09,113:DEBUG:certbot._internal.main:Picked account: <Account(RegistrationResource(body=Registration(key=None, contact=(), agreement=None, status=None, terms_of_service_agreed=None, only_return_existing=None, external_account_binding=None), uri='https://acme-v02.api.letsencrypt.org/acme/acct/3332866786', new_authzr_uri=None, terms_of_service=None), 16f9bbe895785731de66527b923ef6c7, Meta(creation_dt=datetime.datetime(2026, 5, 14, 0, 30, 9, tzinfo=<UTC>), creation_host='mail.espica.me', register_to_eff=None))>
2026-07-25 14:44:09,114:DEBUG:acme.client:Sending GET request to https://acme-v02.api.letsencrypt.org/directory.
2026-07-25 14:44:09,116:DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org:443
2026-07-25 14:44:09,510:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "GET /directory HTTP/1.1" 200 961
2026-07-25 14:44:09,511:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 18:44:09 GMT
Content-Type: application/json
Content-Length: 961
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "XKouXdskfGs": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417",
  "keyChange": "https://acme-v02.api.letsencrypt.org/acme/key-change",
  "meta": {
    "caaIdentities": [
      "letsencrypt.org"
    ],
    "profiles": {
      "classic": "https://letsencrypt.org/docs/profiles#classic",
      "shortlived": "https://letsencrypt.org/docs/profiles#shortlived",
      "tlsserver": "https://letsencrypt.org/docs/profiles#tlsserver"
    },
    "termsOfService": "https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf",
    "website": "https://letsencrypt.org"
  },
  "newAccount": "https://acme-v02.api.letsencrypt.org/acme/new-acct",
  "newNonce": "https://acme-v02.api.letsencrypt.org/acme/new-nonce",
  "newOrder": "https://acme-v02.api.letsencrypt.org/acme/new-order",
  "renewalInfo": "https://acme-v02.api.letsencrypt.org/acme/renewal-info",
  "revokeCert": "https://acme-v02.api.letsencrypt.org/acme/revoke-cert"
}
2026-07-25 14:44:09,512:DEBUG:certbot._internal.display.obj:Notifying user: Renewing an existing certificate for mail.espica.me
2026-07-25 14:44:09,514:DEBUG:acme.client:Requesting fresh nonce
2026-07-25 14:44:09,514:DEBUG:acme.client:Sending HEAD request to https://acme-v02.api.letsencrypt.org/acme/new-nonce.
2026-07-25 14:44:09,637:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "HEAD /acme/new-nonce HTTP/1.1" 200 0
2026-07-25 14:44:09,637:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 18:44:09 GMT
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: H1zRXMT9xbUHrzkjZ-F3GrHrRUYPHbB00W11Qe7_iOmDnsg4yxk
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800


2026-07-25 14:44:09,637:DEBUG:acme.client:Storing nonce: H1zRXMT9xbUHrzkjZ-F3GrHrRUYPHbB00W11Qe7_iOmDnsg4yxk
2026-07-25 14:44:09,637:DEBUG:acme.client:JWS payload:
b'{\n  "identifiers": [\n    {\n      "type": "dns",\n      "value": "mail.espica.me"\n    }\n  ]\n}'
2026-07-25 14:44:09,639:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/new-order:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJIMXpSWE1UOXhiVUhyemtqWi1GM0dySHJSVVlQSGJCMDBXMTFRZTdfaU9tRG5zZzR5eGsiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL25ldy1vcmRlciJ9",
  "signature": "E5AQuLD96yJjJhh3q36U-7cEx2SC-8VRtrd-UcMnS-V9sSTigBBxNypi6CSW2uKvk5odyDDx9bHk_lWCHVhqWLHHr3CJKzBDXDNCyVN1R1MYwAgqwl2ROuFWDFYCO3Ah2UMd-TXICMdwSB2-xiQPK4GNQ2eElTKHMdj9br1mwT8cJwWy5Ba_WzyffWZWy0dpX1B3JUkJN0DYTto4VLShv3uoTH4jqEDlOvQEXCwGBeW98rkRi0_A8DTcWegqL7MrHHhG0rHjrZ1gnwhEpizvz80rp0quDqDsTpARhgMf7GjvHKFR02axxA3Y-nhWUK_neVkYSGUG76BxeyTO4zYjBA",
  "payload": "ewogICJpZGVudGlmaWVycyI6IFsKICAgIHsKICAgICAgInR5cGUiOiAiZG5zIiwKICAgICAgInZhbHVlIjogIm1haWwuZXNwaWNhLm1lIgogICAgfQogIF0KfQ"
}
2026-07-25 14:44:09,863:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/new-order HTTP/1.1" 201 348
2026-07-25 14:44:09,863:DEBUG:acme.client:Received response:
HTTP 201
Server: nginx
Date: Sat, 25 Jul 2026 18:44:09 GMT
Content-Type: application/json
Content-Length: 348
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Location: https://acme-v02.api.letsencrypt.org/acme/order/3332866786/536640035305
Replay-Nonce: H1zRXMT9Ut1QfpUbAe-qHErLBSrrZXS_j0f2cnyAMA9iM5SsIf4
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "status": "pending",
  "expires": "2026-08-01T18:44:09Z",
  "identifiers": [
    {
      "type": "dns",
      "value": "mail.espica.me"
    }
  ],
  "authorizations": [
    "https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/746313964535"
  ],
  "finalize": "https://acme-v02.api.letsencrypt.org/acme/finalize/3332866786/536640035305"
}
2026-07-25 14:44:09,863:DEBUG:acme.client:Storing nonce: H1zRXMT9Ut1QfpUbAe-qHErLBSrrZXS_j0f2cnyAMA9iM5SsIf4
2026-07-25 14:44:09,863:DEBUG:acme.client:JWS payload:
b''
2026-07-25 14:44:09,865:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/746313964535:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJIMXpSWE1UOVV0MVFmcFViQWUtcUhFckxCU3JyWlhTX2owZjJjbnlBTUE5aU01U3NJZjQiLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ2MzEzOTY0NTM1In0",
  "signature": "APTE9RjTAqirQ3l_c2ckJWxMsRLEN23P1zgo1Q3kJOcr3Dw5NTSKLZuDg4SNfmjMUUTr2q-2TkMlrmXyCT6Mt8J9gtAyGRoG2lpx5U7E9EqouXclESU6HvD82cxLFDwt6v8nKYDulZjQJ67JSmkWjAQ8hxMoP-lBq0kWAXlwbnL510gr629MHr7bugvWMkyqu3Rrm0h1QGUxPz22jbXtLW7G4gOwLu7GVSS7oWXQH3sEKA2cHiglRwBooqostDcw2L5SXxLF6XOlsULd8wtgxUVpymESQIYc5vFlRA5QaTmTEEOUg6F6kKyawuGnCedgnTu0DJm7osvGbNUCGoHpLg",
  "payload": ""
}
2026-07-25 14:44:09,990:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/746313964535 HTTP/1.1" 200 822
2026-07-25 14:44:09,991:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 18:44:09 GMT
Content-Type: application/json
Content-Length: 822
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: VnRLvUym1_Dve4xVihzgRLQXJbylFJfpP4Y1WkV54MxpB9XY8Qg
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "pending",
  "expires": "2026-08-01T18:44:09Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/CdZgHA",
      "status": "pending",
      "token": "TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ"
    },
    {
      "type": "tls-alpn-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/OderEw",
      "status": "pending",
      "token": "TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ"
    },
    {
      "type": "dns-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/IG8F0Q",
      "status": "pending",
      "token": "TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ"
    }
  ]
}
2026-07-25 14:44:09,992:DEBUG:acme.client:Storing nonce: VnRLvUym1_Dve4xVihzgRLQXJbylFJfpP4Y1WkV54MxpB9XY8Qg
2026-07-25 14:44:09,992:INFO:certbot._internal.auth_handler:Performing the following challenges:
2026-07-25 14:44:09,992:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-25 14:44:09,993:INFO:certbot._internal.plugins.webroot:Using the webroot path /var/www/html for all unmatched domains.
2026-07-25 14:44:09,993:DEBUG:certbot._internal.plugins.webroot:Creating root challenges validation dir at /var/www/html/.well-known/acme-challenge
2026-07-25 14:44:09,997:DEBUG:certbot._internal.plugins.webroot:Attempting to save validation to /var/www/html/.well-known/acme-challenge/TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ
2026-07-25 14:44:09,998:DEBUG:acme.client:JWS payload:
b'{}'
2026-07-25 14:44:09,999:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/CdZgHA:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJWblJMdlV5bTFfRHZlNHhWaWh6Z1JMUVhKYnlsRkpmcFA0WTFXa1Y1NE14cEI5WFk4UWciLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2NoYWxsLzMzMzI4NjY3ODYvNzQ2MzEzOTY0NTM1L0NkWmdIQSJ9",
  "signature": "QnIZl1-atOjCdjWnG25ZwT8D80pynntaN7OlWuHpRxnVr45Tdh372V9DI4Pjzj0i8LHEGeBTxT5eU2LPdY1T2wmk2S2bIsJLXqNDPqTuBUAumNnkBtvKi6nMUgVEGu5-wczAyVvKvYeHOx0Kq1i_5sHwTfv1HcfuLLPrmWoUG9B9xOH7MnIkYMYNjP4HpBQRwH8fDkiBTcUs7BW4pqeHgzytGUHT9gsJ5mhvA0ShbD3ykZsCXqwv0qs60SXD4mNd6tbvbn7scZeX_v0_8_L_JtaqNImPZp4I-GV9Cr_ejtw4wrsrwf_R2KdVVgmIPZoFCjKG9r6tVz_OE7wv2yWwqQ",
  "payload": "e30"
}
2026-07-25 14:44:10,124:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/chall/3332866786/746313964535/CdZgHA HTTP/1.1" 200 195
2026-07-25 14:44:10,125:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 18:44:10 GMT
Content-Type: application/json
Content-Length: 195
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index", <https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/746313964535>;rel="up"
Location: https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/CdZgHA
Replay-Nonce: H1zRXMT9UyHeD1S_7PI9MLpdIZhuOmV4SyccOlGo1IW_d0lJmdw
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "type": "http-01",
  "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/CdZgHA",
  "status": "pending",
  "token": "TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ"
}
2026-07-25 14:44:10,125:DEBUG:acme.client:Storing nonce: H1zRXMT9UyHeD1S_7PI9MLpdIZhuOmV4SyccOlGo1IW_d0lJmdw
2026-07-25 14:44:10,125:INFO:certbot._internal.auth_handler:Waiting for verification...
2026-07-25 14:44:11,126:DEBUG:acme.client:JWS payload:
b''
2026-07-25 14:44:11,127:DEBUG:acme.client:Sending POST request to https://acme-v02.api.letsencrypt.org/acme/authz/3332866786/746313964535:
{
  "protected": "eyJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvMzMzMjg2Njc4NiIsICJub25jZSI6ICJIMXpSWE1UOVV5SGVEMVNfN1BJOU1McGRJWmh1T21WNFN5Y2NPbEdvMUlXX2QwbEptZHciLCAidXJsIjogImh0dHBzOi8vYWNtZS12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2F1dGh6LzMzMzI4NjY3ODYvNzQ2MzEzOTY0NTM1In0",
  "signature": "pLojSEqEAX8pa_er4rXKCrXBLuR_jFvvM6ajxFARi95ACNgvkpasuFvRdTZVQ1mNGja6afe59zns8VHdn1hiIksfcVniTuCC1mDB7O50fAdLr0dAuqo1tscHoGBsMCS6V0DYEb0GaECEKU8vRt_wwRz1sefIcVpOwEv9Lv9VsChcdG40dry1QHzxzIMckEdaRJguYL4vieK0B3q4tSWzVws6LBrovUMGkwgvabZryA7BDwrjtG7yfq_Wmnpsi3VN3tZ0LYEcpucpt5qJHXiBJ9U5td7edriIVldzxpPH_sQ_HxOMEMcKwOQKJR99CfGxPlLljrz6U83ot6KXnqRPJg",
  "payload": ""
}
2026-07-25 14:44:11,251:DEBUG:urllib3.connectionpool:https://acme-v02.api.letsencrypt.org:443 "POST /acme/authz/3332866786/746313964535 HTTP/1.1" 200 1032
2026-07-25 14:44:11,252:DEBUG:acme.client:Received response:
HTTP 200
Server: nginx
Date: Sat, 25 Jul 2026 18:44:11 GMT
Content-Type: application/json
Content-Length: 1032
Connection: keep-alive
Boulder-Requester: 3332866786
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
Replay-Nonce: VnRLvUyml8B4yRcyqoxTbh47V_DFuO_tUoo-1KasfzxWx60Qmy8
X-Frame-Options: DENY
Strict-Transport-Security: max-age=604800

{
  "identifier": {
    "type": "dns",
    "value": "mail.espica.me"
  },
  "status": "invalid",
  "expires": "2026-08-01T18:44:09Z",
  "challenges": [
    {
      "type": "http-01",
      "url": "https://acme-v02.api.letsencrypt.org/acme/chall/3332866786/746313964535/CdZgHA",
      "status": "invalid",
      "validated": "2026-07-25T18:44:10Z",
      "error": {
        "type": "urn:ietf:params:acme:error:unauthorized",
        "detail": "51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ: 404",
        "status": 403
      },
      "token": "TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ",
      "validationRecord": [
        {
          "url": "http://mail.espica.me/.well-known/acme-challenge/TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ",
          "hostname": "mail.espica.me",
          "port": "80",
          "addressesResolved": [
            "51.75.182.103"
          ],
          "addressUsed": "51.75.182.103"
        }
      ]
    }
  ]
}
2026-07-25 14:44:11,252:DEBUG:acme.client:Storing nonce: VnRLvUyml8B4yRcyqoxTbh47V_DFuO_tUoo-1KasfzxWx60Qmy8
2026-07-25 14:44:11,252:INFO:certbot._internal.auth_handler:Challenge failed for domain mail.espica.me
2026-07-25 14:44:11,252:INFO:certbot._internal.auth_handler:http-01 challenge for mail.espica.me
2026-07-25 14:44:11,253:DEBUG:certbot._internal.display.obj:Notifying user: 
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Domain: mail.espica.me
  Type:   unauthorized
  Detail: 51.75.182.103: Invalid response from http://mail.espica.me/.well-known/acme-challenge/TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ: 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2026-07-25 14:44:11,253:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-25 14:44:11,253:DEBUG:certbot._internal.error_handler:Calling registered functions
2026-07-25 14:44:11,253:INFO:certbot._internal.auth_handler:Cleaning up challenges
2026-07-25 14:44:11,254:DEBUG:certbot._internal.plugins.webroot:Removing /var/www/html/.well-known/acme-challenge/TCtd06f-GnU3Ity_HgFUpHE1e63V545EKZkG3EU65nQ
2026-07-25 14:44:11,254:DEBUG:certbot._internal.plugins.webroot:All challenges cleaned up
2026-07-25 14:44:11,254:ERROR:certbot._internal.renewal:Failed to renew certificate mail.espica.me with error: Some challenges have failed.
2026-07-25 14:44:11,257:DEBUG:certbot._internal.renewal:Traceback was:
Traceback (most recent call last):
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 540, in handle_renewal_request
    main.renew_cert(lineage_config, plugins, renewal_candidate)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1529, in renew_cert
    renewed_lineage = _get_and_save_cert(le_client, config, lineage=lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 130, in _get_and_save_cert
    renewal.renew_cert(config, domains, le_client, lineage)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 399, in renew_cert
    new_cert, new_chain, new_key, _ = le_client.obtain_certificate(domains, new_key)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 429, in obtain_certificate
    orderr = self._get_order_and_authorizations(csr.data, self.config.allow_subset_of_names)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/client.py", line 497, in _get_order_and_authorizations
    authzr = self.auth_handler.handle_authorizations(orderr, self.config, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 108, in handle_authorizations
    self._poll_authorizations(authzrs, max_retries, max_time_mins, best_effort)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/auth_handler.py", line 212, in _poll_authorizations
    raise errors.AuthorizationError('Some challenges have failed.')
certbot.errors.AuthorizationError: Some challenges have failed.

2026-07-25 14:44:11,258:DEBUG:certbot._internal.display.obj:Notifying user: 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-25 14:44:11,258:ERROR:certbot._internal.renewal:All renewals failed. The following certificates could not be renewed:
2026-07-25 14:44:11,258:ERROR:certbot._internal.renewal:  /etc/letsencrypt/live/mail.espica.me/fullchain.pem (failure)
2026-07-25 14:44:11,258:DEBUG:certbot._internal.display.obj:Notifying user: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2026-07-25 14:44:11,258:DEBUG:certbot._internal.log:Exiting abnormally:
Traceback (most recent call last):
  File "/usr/bin/certbot", line 8, in <module>
    sys.exit(main())
  File "/usr/lib/python3.9/site-packages/certbot/main.py", line 19, in main
    return internal_main.main(cli_args)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1873, in main
    return config.func(config, plugins)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/main.py", line 1621, in renew
    renewed_domains, failed_domains = renewal.handle_renewal_request(config)
  File "/usr/lib/python3.9/site-packages/certbot/_internal/renewal.py", line 568, in handle_renewal_request
    raise errors.Error(
certbot.errors.Error: 1 renew failure(s), 0 parse failure(s)
2026-07-25 14:44:11,258:ERROR:certbot._internal.log:1 renew failure(s), 0 parse failure(s)