What are Let's Encrypt and Certbot?
Let's Encrypt is a free, automatic and open certificate authority (CA). Certbot is the most popular ACME client that automatically obtains and renews Let's Encrypt certificates.
The fact that it is free and automatic has made it the most widely used CA, but it has some limitations and common errors. In this guide, we will discuss the most common Certbot/Let's Encrypt errors and their solutions in detail.
Error 1: Challenge Failed — Port 80 Closed
For the HTTP-01 challenge, Let's Encrypt servers must access your domain via port 80.
# Error message:
# "Connection refused" or "Timeout during connect"
# "Failed authorization procedure. domain.com (http-01): urn:ietf:params:acme:error:connection"
Solution
- Open port 80 in Firewall:
sudo ufw allow 80/tcp - Make sure Nginx/Apache is listening on port 80
- If you are using Cloudflare, temporarily turn off the proxy (DNS Only mode)
- If port 80 cannot be opened, use DNS-01 challenge:
certbot --manual --preferred-challenges dns
Error 2: Rate Limit Exceeded
Let's Encrypt imposes rate limits to prevent overuse:
| Limit Type | Limit | Duration |
|---|---|---|
| Certificate / Domain Name | 50 | Weeks |
| Registration / IP | 10 | 3 hours |
| Duplicate Certificate | 5 | Weeks |
| Failed Verification | 5 | Hours |
Solution
- Use
--stagingenvironment in testing:certbot --staging - If you are stuck at the rate limit, wait for the waiting period to expire
- Check your existing certificates via crt.sh
- Get a certificate from a paid CA (via DATASSL) in case of emergency
Error 3: DNS Resolution Problem
# "DNS problem: NXDOMAIN looking up A for domain.com"
# "DNS problem: query timed out"
Solution
- Verify that the DNS A record points to your server IP:
dig +short domain.com A - Wait for DNS propagation (may take 24-48 hours for new domains)
- If you are using DNS-01 challenge, verify that the TXT record is propagated:
dig +short _acme-challenge.domain.com TXT
Error 4: Nginx/Apache Configuration Error
# "Could not automatically find a matching server block / virtual host"
# certbot --nginx or certbot --apache cannot find the configuration
Solution
- Nginx: Make sure that the line
server_name domain.com;is written correctly in the server block - Apache:
ServerName domain.commust be defined in VirtualHost - Configuration syntax check:
nginx -torapachectl configtest - Manual installation:
certbot certonly --webroot -w /var/www/html -d domain.com
Error 5: Automatic Renewal Failed
Let's Encrypt certificates are valid for 90 days. Certbot tries to refresh with cron/systemd timer every day but sometimes fails.
# Refresh test
sudo certbot renew --dry-run
# Cron job control
sudo systemctl status certbot.timer
# or
crontab -l | grep certbot
Common Refurbishment Problems and Solutions
- Web server stopped: Set pre/post refresh hook:
--pre-hook "systemctl stop nginx" --post-hook "systemctl start nginx" - Certbot version is old:
check with sudo certbot --version, update - File permissions: Check
/etc/letsencrypt/directory permissions - Port 80 is closed: If you are using Standalone mode, port 80 must be open during renewal
Error 6: DNS-01 Required for Wildcard Certificate
Wildcard certificates (*.domain.com) can only be obtained with the DNS-01 challenge.
# Obtaining a Wildcard certificate
sudo certbot certonly --manual --preferred-challenges dns -d "*.domain.com" -d "domain.com"
# Certbot will ask you to create a TXT record:
# _acme-challenge.domain.com → "xxxxxxxxxxxx"
# After adding the DNS record, wait for propagation and confirm
Automatic DNS-01 Challenge
Certbot plugins are available for DNS providers such as Cloudflare, Route53, DigitalOcean:
# Automatic wildcard with Cloudflare plugin
sudo certbot certonly --dns-cloudflare --dns-cloudflare-credentials /etc/cloudflare.ini -d "*.domain.com" -d "domain.com"
Error 7: "Too Many Certificates Already Issued"
No more than 5 duplicate certificates can be obtained per week for the same domain set.
Solution
- List available certificates:
certbot certificates - Instead of getting a new certificate, renew the existing one:
certbot renew - To expand the certificate:
certbot --expand -d domain.com -d www.domain.com
Let's Encrypt Limitations
| Feature | Let's Encrypt | Paid CA |
|---|---|---|
| Validity Period | 90 days | Up to 200 days (since 15 March 2026) |
| Verification | DV Only | DV, OV, EV |
| Warranty | None | Depends on the product |
| Support | Community | Professional |
| Site Seal | None | Trust seal |
Conclusion
Let's Encrypt is a great solution for small sites and personal projects, but is limited by rate limits, a 90-day period, and DV-only support. Most Certbot errors are related to port access, DNS configuration and file permissions. For corporate projects, e-commerce sites or in cases requiring warranty, a paid certificate from a reliable CA should be preferred.