Temat: Openwrt, Let's Encrypt i https
Witajcie
Postanowiłem u-bezpieczyć stronę korzystając z poradnika: https://eko.one.pl/?p=openwrt-letsencrypt
Strona na moim routerze z LEDE 18.06 z dostępem do sh
Zainstalowałem acme, skonfigurowałem, uruchomiłem.
Niestety po bardzo długim logu, zawierającym m.in. helpa komendy socat, wyrzuca błąd:
daemon.err acme: Issuing cert for stronatest.pl failed i przerzuca co zrobił do katalogu failed.
Co poradzicie?
Poniżej podaję całego loga.
W nim nie znalazłem nic istotnego poza: "Verify error:Invalid response from (link strony)" co nie wydaje się istotne bo skrypt pracuje dalej po tym błędzie.
Sprawdzałem dla dwóch swoich przekierowanych domen i jednej obcej. Zawsze kończy się tak samo.
Wed Jan 9 12:19:55 2019 daemon.info acme: Running pre checks for stronatest.pl.
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: acme: Running pre checks for stronatest.pl.
Wed Jan 9 12:19:55 2019 daemon.debug acme: port80 listens:
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: acme: port80 listens:
Wed Jan 9 12:19:55 2019 daemon.debug acme: Nothing listening on port 80.
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: acme: Nothing listening on port 80.
Wed Jan 9 12:19:55 2019 daemon.debug acme: v4 input_rule: Chain input_rule (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */ 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */ 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */ 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: acme: v4 input_rule: Chain input_rule (1 references)
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: pkts bytes target prot opt in out source destination
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:55 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:56 2019 daemon.debug acme: v6 input_rule: Chain input_rule (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */ 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */ 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */ 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: acme: v6 input_rule: Chain input_rule (1 references)
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: pkts bytes target prot opt in out source destination
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80 /* ACME */
Wed Jan 9 12:19:56 2019 daemon.info acme: Running ACME for stronatest.pl
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: acme: Running ACME for stronatest.pl
Wed Jan 9 12:19:56 2019 daemon.info acme: Using standalone mode
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: acme: Using standalone mode
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: Lets find script dir.
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _SCRIPT_='/usr/lib/acme/acme.sh'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _script='/usr/lib/acme/acme.sh'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _script_home='/usr/lib/acme'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: Using config home:/etc/acme
Wed Jan 9 12:19:56 2019 daemon.info run-acme[7842]: https://github.com/Neilpang/acme.sh
Wed Jan 9 12:19:56 2019 daemon.info run-acme[7842]: v2.7.8
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _main_domain='stronatest.pl'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _alt_domains='no'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: Using config home:/etc/acme
Wed Jan 9 12:19:56 2019 daemon.info run-acme[7842]: Using stage ACME_DIRECTORY: https://acme-staging.api.letsencrypt.org/directory
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: ACME_DIRECTORY='https://acme-staging.api.letsencrypt.org/directory'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: DOMAIN_PATH='/etc/acme/stronatest.pl'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: Using ACME_DIRECTORY: https://acme-staging.api.letsencrypt.org/directory
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _init api for server: https://acme-staging.api.letsencrypt.org/directory
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: GET
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: url='https://acme-staging.api.letsencrypt.org/directory'
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: timeout=
Wed Jan 9 12:19:56 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g '
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ret='0'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_KEY_CHANGE='https://acme-staging.api.letsencrypt.org/acme/key-change'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_NEW_AUTHZ='https://acme-staging.api.letsencrypt.org/acme/new-authz'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_NEW_ORDER='https://acme-staging.api.letsencrypt.org/acme/new-cert'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_NEW_ACCOUNT='https://acme-staging.api.letsencrypt.org/acme/new-reg'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_REVOKE_CERT='https://acme-staging.api.letsencrypt.org/acme/revoke-cert'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_AGREEMENT='https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_NEW_NONCE
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_VERSION
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _on_before_issue
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _chk_main_domain='stronatest.pl'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _chk_alt_domains
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Le_LocalAddress
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: d='stronatest.pl'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Check for domain='stronatest.pl'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _currentRoot='no'
Wed Jan 9 12:19:57 2019 daemon.info run-acme[7842]: Standalone mode.
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _checkport='80'
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _checkaddr
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Using: netstat
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: d
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: _saved_account_key_hash is not changed, skip register account.
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Read key length:
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Using config home:/etc/acme
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: ACME_DIRECTORY='https://acme-staging.api.letsencrypt.org/directory'
Wed Jan 9 12:19:57 2019 daemon.info run-acme[7842]: Creating domain key
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Use length 2048
Wed Jan 9 12:19:57 2019 daemon.err run-acme[7842]: Using RSA: 2048
Wed Jan 9 12:19:59 2019 daemon.info run-acme[7842]: The domain key is here: /etc/acme/stronatest.pl/stronatest.pl.key
Wed Jan 9 12:19:59 2019 daemon.info run-acme[7842]: Single domain='stronatest.pl'
Wed Jan 9 12:19:59 2019 daemon.err run-acme[7842]: _createcsr
Wed Jan 9 12:20:00 2019 daemon.info run-acme[7842]: Getting domain auth token for each domain
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: d='stronatest.pl'
Wed Jan 9 12:20:00 2019 daemon.info run-acme[7842]: Getting webroot for domain='stronatest.pl'
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: _w='no'
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: _currentRoot='no'
Wed Jan 9 12:20:00 2019 daemon.info run-acme[7842]: Getting new-authz for domain='stronatest.pl'
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: _init api for server: https://acme-staging.api.letsencrypt.org/directory
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: Try new-authz for the 0 time.
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: url='https://acme-staging.api.letsencrypt.org/acme/new-authz'
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: payload='{"resource": "new-authz", "identifier": {"type": "dns", "value": "stronatest.pl"}}'
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: RSA key
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: GET
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: url='https://acme-staging.api.letsencrypt.org/directory'
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: timeout=
Wed Jan 9 12:20:00 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g '
Wed Jan 9 12:20:01 2019 daemon.err run-acme[7842]: ret='0'
Wed Jan 9 12:20:02 2019 daemon.err run-acme[7842]: POST
Wed Jan 9 12:20:02 2019 daemon.err run-acme[7842]: _post_url='https://acme-staging.api.letsencrypt.org/acme/new-authz'
Wed Jan 9 12:20:02 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g '
Wed Jan 9 12:20:03 2019 daemon.err run-acme[7842]: _ret='0'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: code='201'
Wed Jan 9 12:20:04 2019 daemon.info run-acme[7842]: The new-authz request is ok.
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: entry='"type":"http-01","status":"pending","uri":"https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017","token":"b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0"'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: token='b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: uri='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: keyauthorization='b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0.o-hE1vKc4QJJ4hIo9P4Vt7LnBzReWDGhC0FNbHB8snw'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: dvlist='stronatest.pl#b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0.o-hE1vKc4QJJ4hIo9P4Vt7LnBzReWDGhC0FNbHB8snw#https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017#http-01#no'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: d
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: vlist='stronatest.pl#b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0.o-hE1vKc4QJJ4hIo9P4Vt7LnBzReWDGhC0FNbHB8snw#https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017#http-01#no,'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: d='stronatest.pl'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: ok, let's start to verify
Wed Jan 9 12:20:04 2019 daemon.info run-acme[7842]: Verifying:stronatest.pl
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: d='stronatest.pl'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: keyauthorization='b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0.o-hE1vKc4QJJ4hIo9P4Vt7LnBzReWDGhC0FNbHB8snw'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: uri='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: _currentRoot='no'
Wed Jan 9 12:20:04 2019 daemon.info run-acme[7842]: Standalone mode server
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: ncaddr
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: startserver: 7895
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: Le_HTTPPort='80'
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: Le_Listen_V4
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: Le_Listen_V6
Wed Jan 9 12:20:04 2019 daemon.err run-acme[7842]: _NC='socat TCP-LISTEN:80,crlf,reuseaddr,fork'
Wed Jan 9 12:20:05 2019 daemon.err run-acme[7842]: serverproc='8402'
Wed Jan 9 12:20:05 2019 daemon.err run-acme[7842]: url='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:05 2019 daemon.err run-acme[7842]: payload='{"resource": "challenge", "keyAuthorization": "b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0.o-hE1vKc4QJJ4hIo9P4Vt7LnBzReWDGhC0FNbHB8snw"}'
Wed Jan 9 12:20:05 2019 daemon.err run-acme[7842]: POST
Wed Jan 9 12:20:05 2019 daemon.err run-acme[7842]: _post_url='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:05 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g '
Wed Jan 9 12:20:06 2019 daemon.err run-acme[7842]: _ret='0'
Wed Jan 9 12:20:06 2019 daemon.err run-acme[7842]: code='202'
Wed Jan 9 12:20:06 2019 daemon.err run-acme[7842]: sleep 2 secs to verify
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: checking
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: GET
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: url='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: timeout=
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g '
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: ret='0'
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: stronatest.pl:Verify error:Invalid response from http://stronatest.pl/.well-known/acme-challenge/b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0:
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: Debug: get token url.
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: GET
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: url='http://stronatest.pl/.well-known/acme-challenge/b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0'
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: timeout=1
Wed Jan 9 12:20:09 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g --connect-timeout 1'
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <html>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <head>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <title></title>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <meta name="viewport" content="width=device-width,initial-scale=1">
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: </head>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]:
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <!-- This site "stronatest.pl" is using the free URL redirection service at http://freedns.afraid.org/ -->
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <!-- The real (cloaked URL) site can be found directly at http://(tu ip:port)/.well-known/acme-challenge/b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0 -->
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <!-- Please report any abuse of this free service -->
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]:
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <frameset frameborder="0" border="0" rows="*,100%" cols="100%" marginwidth="0" marginheight="0">
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <frame target="random_name_not_taken1" name="random_name_not_taken1" marginwidth="0" marginheight="0" border="0" noresize scrolling="no">
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <frame target="random_name_not_taken2" name="random_name_not_taken2" src="http://(tu ip:port)/.well-known/acme-challenge/b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0" border="0" noresize>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <noframes>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: <a href="http://(tu ip:port)/.well-known/acme-challenge/b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0">NOFRAMES: Click here to visit the actual site</a>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: </noframes>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]: </frameset>
Wed Jan 9 12:20:10 2019 daemon.info run-acme[7842]:
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: ret='0'
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: Skip for removelevel:
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: pid='8402'
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: No need to restore nginx, skip.
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: _clearupdns
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: skip dns.
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: _on_issue_err
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: Please add '--debug' or '--log' to check more details.
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: See: https://github.com/Neilpang/acme.sh/wiki/How-to-debug-acme.sh
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: url='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:10 2019 daemon.err run-acme[7842]: payload='{"resource": "challenge", "keyAuthorization": "b_-iDjQ03tmGscj-_3tqZ3oXyBOv91EA-2gfMR5pwD0.o-hE1vKc4QJJ4hIo9P4Vt7LnBzReWDGhC0FNbHB8snw"}'
Wed Jan 9 12:20:11 2019 daemon.err run-acme[7842]: POST
Wed Jan 9 12:20:11 2019 daemon.err run-acme[7842]: _post_url='https://acme-staging.api.letsencrypt.org/acme/challenge/tP0tCaGUoKXxpplZfdDBCWRQU1HCFtHuoVW04iyPxcc/220069017'
Wed Jan 9 12:20:11 2019 daemon.err run-acme[7842]: _CURL='curl -L --silent --dump-header /etc/acme/http.header -g '
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: _ret='0'
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: code='400'
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: Diagnosis versions:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: openssl:openssl
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: OpenSSL 1.0.2p 14 Aug 2018
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: apache:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: apache doesn't exists.
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: nginx:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: nginx doesn't exists.
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socat:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socat by Gerhard Rieger and contributors - see www.dest-unreach.org
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: Usage:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socat [options] <bi-address> <bi-address>
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: options:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -V print version and feature information to stdout, and exit
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -h|-? print a help text describing command line options and addresses
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -hh like -h, plus a list of all common address option names
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -hhh like -hh, plus a list of all available address option names
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -d increase verbosity (use up to 4 times; 2 are recommended)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -D analyze file descriptors before loop
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -ly[facility] log to syslog, using facility (default is daemon)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -lf<logfile> log to file
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -ls log to stderr (default if no other log)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -lm[facility] mixed log mode (stderr during initialization, then syslog)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -lp<progname> set the program name used for logging
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -lu use microseconds for logging timestamps
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -lh add hostname to log messages
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -v verbose data traffic, text
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -x verbose data traffic, hexadecimal
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -b<size_t> set data buffer size (8192)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -s sloppy (continue on error)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -t<timeout> wait seconds before closing second channel
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -T<timeout> total inactivity timeout in seconds
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -u unidirectional mode (left to right)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -U unidirectional mode (right to left)
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -g do not check option groups
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -L <lockfile> try to obtain lock, or fail
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -W <lockfile> try to obtain lock, or wait
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -4 prefer IPv4 if version is not explicitly specified
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: -6 prefer IPv6 if version is not explicitly specified
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: bi-address:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: pipe[,<opts>] groups=FD,FIFO
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: <single-address>!!<single-address>
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: <single-address>
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: single-address:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: <address-head>[,<opts>]
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: address-head:
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: abstract-client:<filename> groups=FD,SOCKET,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: abstract-connect:<filename> groups=FD,SOCKET,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: abstract-listen:<filename> groups=FD,SOCKET,LISTEN,CHILD,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: abstract-recv:<filename> groups=FD,SOCKET,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: abstract-recvfrom:<filename> groups=FD,SOCKET,CHILD,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: abstract-sendto:<filename> groups=FD,SOCKET,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: create:<filename> groups=FD,REG,NAMED
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: exec:<command-line> groups=FD,FIFO,SOCKET,EXEC,FORK,TERMIOS,PTY,PARENT,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: fd:<num> groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: gopen:<filename> groups=FD,FIFO,CHR,BLK,REG,SOCKET,NAMED,OPEN,TERMIOS,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: interface:<interface> groups=FD,SOCKET
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip-datagram:<host>:<protocol> groups=FD,SOCKET,RANGE,IP4,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip-recv:<protocol> groups=FD,SOCKET,RANGE,IP4,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip-recvfrom:<protocol> groups=FD,SOCKET,CHILD,RANGE,IP4,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip-sendto:<host>:<protocol> groups=FD,SOCKET,IP4,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip4-datagram:<host>:<protocol> groups=FD,SOCKET,RANGE,IP4
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip4-recv:<protocol> groups=FD,SOCKET,RANGE,IP4
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip4-recvfrom:<protocol> groups=FD,SOCKET,CHILD,RANGE,IP4
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip4-sendto:<host>:<protocol> groups=FD,SOCKET,IP4
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip6-datagram:<host>:<protocol> groups=FD,SOCKET,RANGE,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip6-recv:<protocol> groups=FD,SOCKET,RANGE,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip6-recvfrom:<protocol> groups=FD,SOCKET,CHILD,RANGE,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: ip6-sendto:<host>:<protocol> groups=FD,SOCKET,IP6
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: open:<filename> groups=FD,FIFO,CHR,BLK,REG,NAMED,OPEN,TERMIOS
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: pipe:<filename> groups=FD,FIFO,NAMED,OPEN
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: proxy:<proxy-server>:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,HTTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: pty groups=FD,NAMED,TERMIOS,PTY
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: sctp-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: sctp-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,IP6,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: sctp4-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: sctp4-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: sctp6-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP6,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: sctp6-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP6,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socket-connect:<domain>:<protocol>:<remote-address> groups=FD,SOCKET,CHILD,RETRY
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socket-datagram:<domain>:<type>:<protocol>:<remote-address> groups=FD,SOCKET,RANGE
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socket-listen:<domain>:<protocol>:<local-address> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socket-recv:<domain>:<type>:<protocol>:<local-address> groups=FD,SOCKET,RANGE
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socket-recvfrom:<domain>:<type>:<protocol>:<local-address> groups=FD,SOCKET,CHILD,RANGE
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socket-sendto:<domain>:<type>:<protocol>:<remote-address> groups=FD,SOCKET
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socks4:<socks-server>:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,SOCKS4
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: socks4a:<socks-server>:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,SOCKS4
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: stderr groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: stdin groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: stdio groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: stdout groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: system:<shell-command> groups=FD,FIFO,SOCKET,EXEC,FORK,TERMIOS,PTY,PARENT,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tcp-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tcp-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,IP6,TCP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tcp4-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,TCP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tcp4-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,TCP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tcp6-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP6,TCP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tcp6-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP6,TCP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: tun[:<ip-addr>/<bits>] groups=FD,CHR,NAMED,OPEN,INTERFACE
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp-connect:<host>:<port> groups=FD,SOCKET,IP4,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp-datagram:<host>:<port> groups=FD,SOCKET,RANGE,IP4,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RANGE,IP4,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp-recv:<port> groups=FD,SOCKET,RANGE,IP4,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp-recvfrom:<port> groups=FD,SOCKET,CHILD,RANGE,IP4,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp-sendto:<host>:<port> groups=FD,SOCKET,IP4,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp4-connect:<host>:<port> groups=FD,SOCKET,IP4,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp4-datagram:<remote-address>:<port> groups=FD,SOCKET,RANGE,IP4,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp4-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RANGE,IP4,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp4-recv:<port> groups=FD,SOCKET,RANGE,IP4,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp4-recvfrom:<host>:<port> groups=FD,SOCKET,CHILD,RANGE,IP4,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp4-sendto:<host>:<port> groups=FD,SOCKET,IP4,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp6-connect:<host>:<port> groups=FD,SOCKET,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp6-datagram:<host>:<port> groups=FD,SOCKET,RANGE,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp6-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RANGE,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp6-recv:<port> groups=FD,SOCKET,RANGE,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp6-recvfrom:<port> groups=FD,SOCKET,CHILD,RANGE,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: udp6-sendto:<host>:<port> groups=FD,SOCKET,IP6,UDP
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: unix-client:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: unix-connect:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: unix-listen:<filename> groups=FD,SOCKET,NAMED,LISTEN,CHILD,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: unix-recv:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: unix-recvfrom:<filename> groups=FD,SOCKET,NAMED,CHILD,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: unix-sendto:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
Wed Jan 9 12:20:12 2019 daemon.err acme: Issuing cert for stronatest.pl failed. Moving state to /etc/acme/stronatest.pl.failed-1547032812
Wed Jan 9 12:20:12 2019 daemon.err run-acme[7842]: acme: Issuing cert for stronatest.pl failed. Moving state to /etc/acme/stronatest.pl.failed-1547032812