Skip to content
SSL Management3 min read

How to Troubleshoot ACME HTTP-01 Challenge Failures in Nginx and Apache

Fix ACME HTTP-01 challenge failures by checking DNS, ports, redirects, webroot paths, Nginx, Apache, and firewall rules.

Written by Abdul AbrorTechnical Hosting Support Engineer
On this page

When an ACME SSL renewal fails, the error often looks complicated. In many cases, the certificate authority simply cannot reach the challenge file on your server.

This article focuses on HTTP-01 validation because it is common on VPS, Nginx, Apache, and many hosting automation setups.

How HTTP-01 validation works

With HTTP-01 validation, your ACME client places a temporary token under the .well-known/acme-challenge path. The certificate authority requests that URL over HTTP to confirm that you control the domain.

If DNS points somewhere else, port 80 is blocked, redirects are broken, or the webroot path is wrong, validation fails.

Check DNS first

Before editing Nginx or Apache, confirm the domain resolves to the server running the ACME client. DNS mistakes are one of the most common reasons validation fails.

Check both the root domain and www version. If IPv6 is enabled, confirm AAAA records also point to the correct server.

  • Verify active nameservers.
  • Check A records for root and www.
  • Check AAAA records if IPv6 is published.
  • Confirm CDN proxy behavior if Cloudflare or another CDN is enabled.

Confirm port 80 is reachable

HTTP-01 validation depends on HTTP reachability. Even if your website forces HTTPS, the CA must be able to reach the challenge path on port 80 unless your setup handles redirects correctly.

Check the server firewall, cloud firewall, hosting provider security groups, and any reverse proxy in front of the application.

Check redirects and rewrite rules

A redirect from HTTP to HTTPS is usually fine, but a redirect loop, redirect to another hostname, forced login page, or application-level rewrite can break ACME validation.

Make sure requests to /.well-known/acme-challenge/ are served as static files and are not intercepted by WordPress, Laravel, Next.js, or another application router.

Validate the webroot path

For webroot-based renewals, the ACME client must write the challenge file to the same document root that the public website serves.

A common mistake is running Certbot or another client with an old webroot after a site migration. The file is created, but the public URL points to a different folder.

  • Create a test file under .well-known/acme-challenge.
  • Open it from an external network.
  • Confirm the file content matches.
  • Remove the test file after validation.

Nginx-specific checks

In Nginx, verify the correct server block handles the domain. If multiple blocks match the same hostname, the challenge may be served from the wrong root.

Run a syntax test before reload. A failed reload can leave the old configuration active, which makes troubleshooting confusing.

Apache-specific checks

In Apache, check the VirtualHost for port 80, document root, aliases, and .htaccess rules. A restrictive .htaccess file can block challenge access.

If the site uses a CMS, make sure rewrite rules do not capture the ACME challenge path.

Conclusion

ACME HTTP-01 failures are usually not mysterious once you test the path like a public visitor. DNS, port 80, redirects, webroot paths, and virtual host matching should be checked before changing certificate providers.

Quick troubleshooting checklist

  • Confirm DNS points to the correct server.
  • Check both A and AAAA records.
  • Make sure port 80 is reachable.
  • Test the .well-known/acme-challenge path publicly.
  • Review redirects and application rewrites.
  • Verify Nginx server block or Apache VirtualHost.
  • Check ACME client logs.
  • Reload the web server only after syntax checks pass.

FAQ

Can HTTP-01 validation work if my site redirects to HTTPS?

Yes, if the redirect is valid and the challenge path remains reachable. Redirect loops or redirects to another hostname can break validation.

Why does Certbot say unauthorized?

Usually the CA reached a different server, the challenge file was not served from the expected webroot, or a redirect/rewrite blocked the challenge URL.

Should I use DNS-01 instead of HTTP-01?

DNS-01 is useful for wildcard certificates or locked-down servers, but it requires reliable DNS API access. For many simple VPS websites, HTTP-01 is easier.