How to Troubleshoot ACME HTTP-01 Challenge Failures in Nginx and Apache
Fix ACME HTTP-01 challenge failures by checking DNS, ports, redirects, webroot paths, Nginx, Apache, and firewall rules.
On this page
When an ACME SSL renewal fails, the error often looks complicated. In many cases, the certificate authority simply cannot reach the challenge file on your server.
This article focuses on HTTP-01 validation because it is common on VPS, Nginx, Apache, and many hosting automation setups.
How HTTP-01 validation works
With HTTP-01 validation, your ACME client places a temporary token under the .well-known/acme-challenge path. The certificate authority requests that URL over HTTP to confirm that you control the domain.
If DNS points somewhere else, port 80 is blocked, redirects are broken, or the webroot path is wrong, validation fails.
Check DNS first
Before editing Nginx or Apache, confirm the domain resolves to the server running the ACME client. DNS mistakes are one of the most common reasons validation fails.
Check both the root domain and www version. If IPv6 is enabled, confirm AAAA records also point to the correct server.
- Verify active nameservers.
- Check A records for root and www.
- Check AAAA records if IPv6 is published.
- Confirm CDN proxy behavior if Cloudflare or another CDN is enabled.
Confirm port 80 is reachable
HTTP-01 validation depends on HTTP reachability. Even if your website forces HTTPS, the CA must be able to reach the challenge path on port 80 unless your setup handles redirects correctly.
Check the server firewall, cloud firewall, hosting provider security groups, and any reverse proxy in front of the application.
Check redirects and rewrite rules
A redirect from HTTP to HTTPS is usually fine, but a redirect loop, redirect to another hostname, forced login page, or application-level rewrite can break ACME validation.
Make sure requests to /.well-known/acme-challenge/ are served as static files and are not intercepted by WordPress, Laravel, Next.js, or another application router.
Validate the webroot path
For webroot-based renewals, the ACME client must write the challenge file to the same document root that the public website serves.
A common mistake is running Certbot or another client with an old webroot after a site migration. The file is created, but the public URL points to a different folder.
- Create a test file under .well-known/acme-challenge.
- Open it from an external network.
- Confirm the file content matches.
- Remove the test file after validation.
Nginx-specific checks
In Nginx, verify the correct server block handles the domain. If multiple blocks match the same hostname, the challenge may be served from the wrong root.
Run a syntax test before reload. A failed reload can leave the old configuration active, which makes troubleshooting confusing.
Apache-specific checks
In Apache, check the VirtualHost for port 80, document root, aliases, and .htaccess rules. A restrictive .htaccess file can block challenge access.
If the site uses a CMS, make sure rewrite rules do not capture the ACME challenge path.
Conclusion
ACME HTTP-01 failures are usually not mysterious once you test the path like a public visitor. DNS, port 80, redirects, webroot paths, and virtual host matching should be checked before changing certificate providers.
Quick troubleshooting checklist
- Confirm DNS points to the correct server.
- Check both A and AAAA records.
- Make sure port 80 is reachable.
- Test the .well-known/acme-challenge path publicly.
- Review redirects and application rewrites.
- Verify Nginx server block or Apache VirtualHost.
- Check ACME client logs.
- Reload the web server only after syntax checks pass.
FAQ
Can HTTP-01 validation work if my site redirects to HTTPS?
Yes, if the redirect is valid and the challenge path remains reachable. Redirect loops or redirects to another hostname can break validation.
Why does Certbot say unauthorized?
Usually the CA reached a different server, the challenge file was not served from the expected webroot, or a redirect/rewrite blocked the challenge URL.
Should I use DNS-01 instead of HTTP-01?
DNS-01 is useful for wildcard certificates or locked-down servers, but it requires reliable DNS API access. For many simple VPS websites, HTTP-01 is easier.
Related articles
- SSL ManagementFree SSL Certificate Alternatives for Hosting Users: What to Check Before SwitchingCompare free SSL certificate options and learn what hosting users should verify before switching from their current SSL provider.
- SSL ManagementWhat to Do When SSL Auto-Renewal Fails on Shared Hosting or VPSA practical SSL troubleshooting guide for fixing failed certificate renewals on shared hosting, cPanel, VPS, and Nginx environments.
- Developer SecurityAI Agent Sandboxing: A Practical Safety Checklist for Developer LaptopsProtect repositories, credentials, network access, and local tools when running AI coding agents on developer machines.
- Developer ToolsApple Container vs Docker Desktop, Colima, and OrbStack for Mac DevelopersCompare Apple container with Docker Desktop, Colima, and OrbStack for Mac Apple Silicon development workflows.
- WordPress HostingCommon WordPress Errors on Shared Hosting and How to Fix ThemA support-focused guide to common WordPress errors on shared hosting, including white screen, database connection errors, 500 errors, plugin conflicts, and memory limits.
- DNS ManagementDNS Propagation Explained for Non-Technical UsersA simple explanation of DNS propagation, why website or email changes take time, and what domain owners can check after updating DNS records.