Lets Encrypt SSL Error (Error: Let's Encrypt validation status 400 (domain.com). Details: 403:"MY-IP: Invalid response

Since Hestia CP started having problems activating SSL Let’s Encrypt, what have I done:

  • I increased the limit of open files in NGINX;
  • I commented in the v-restart-service file;
  • I checked BIND9, according to the screen print sent previously.

All these processes did not help to activate SSL for my websites.

Now, there is this issue of IPV6, which, at the moment, I can’t imagine where to start, due to lack of knowledge.

I did a lot of research to understand this issue of IPV6 on Hestia CP and other panels, but I was unable to make any progress.

Could anyone help me at least so I can better understand the IPV6 settings on Hestia CP?

Thank you in advance.

I am guessing it may be your IPV6 which is interfering and LE is unable to validate. If you are on Debian follow How To Disable IPv6 on Debian 12 - idroot or if you are on Ubuntu follow https://linuxconfig.org/how-to-disable-ipv6-on-ubuntu-24-04 to disable ipv6 first. Reboot the system and retry ssl for one domain first. If it fails in one try, do it again for the same domain after 5 minutes and retry maximum 3 times only in 24 hours. If it passes, please try for the next domain with a gap of minimum 5-10 minutes, suggest 600 seconds.

I had this issue initially myself. Did this and it worked perfectly. Found IPV6 was the issue for only during SSL part. After that the IPv6 caused no issues.

Perfect. I’ve already deactivated it, restarted the server and I’m going to do these tests in relation to the domains. Well, at first, it hasn’t activated yet.

Then I’ll let you know if it worked.

Thank you very much!

1 Like

hi guys

i am having this issue again and seems now nothing helps

  1. i have my ipv6 disabled
  2. i have in /etc/security/limits.conf
    root hard nofile 500000
    root soft nofile 500000
    nginx hard nofile 500000
    nginx soft nofile 500000
    www-data hard nofile 500000
    www-data soft nofile 500000
  3. i have in /etc/systemd/system/nginx.service/override.conf
    [Service]
    LimitNOFILE=65536
  4. i have in /etc/nginx/nginx.conf
    worker_rlimit_nofile 65536;
  5. i have also tried to comment some rows in /usr/local/hestia/bin/v-restart-service
    as mentioned above

but this is not helping. can someone advice please?

1 Like

but now redirect from www to non www does not work as expected. what can i do?

and still facing this error ‘Lets Encrypt SSL Error’

===

ok i’ve found that my dns pointing to another ip

1 Like