Page 1 of 1

Unable to create Let's Encrypt Account

Posted: 2023-03-29 17:27
by s7th
CleanShot 2023-03-29 at 13.25.12.png
CleanShot 2023-03-29 at 13.25.12.png (43.58 KiB) Viewed 1889 times
I'm able to view that acme website mentioned in the log file via browser with no problems. It shows there is a valid cert on the acme endpoint. Unsure why FileZilla is saying Certificate is Trusted: No.

I was able to download certbot and provision a certificate via their tool, so it seems like the issue is with FileZilla.

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-29 17:59
by botg
Which version of FileZilla Server are you using? Are you by chance using a firewall or other snake-oil product that performs TLS inspection?

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-29 18:02
by s7th
I'm using server version 1.6.7 just downloaded it a few hours ago this is a new setup. Windows firewall is turned off for testing trying to get this to work.

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-30 10:04
by botg
Cannot reproduce, works over here just fine.

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-30 10:18
by oibaf
If from the server's machine you try to connect to https://acme-v02.api.letsencrypt.org/ with a browser, what does it say about the certificate?

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-30 13:18
by botg
Going on a hunch here: Outdated Windows system trust store?

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-30 13:34
by s7th
The certificate is valid via browser as mentioned in the first post.

It's a brand new install of server 2019, latest updates. It works fine using https://certbot.eff.org/

No idea why it doesn't work inside filezilla. I'll just use certbot and have it restart the service post-deploy.
CleanShot 2023-03-30 at 09.30.43.png
CleanShot 2023-03-30 at 09.30.43.png (70.73 KiB) Viewed 1848 times

Re: Unable to create Let's Encrypt Account

Posted: 2023-03-30 13:47
by botg
Your web browser uses its own trust store. You need to use at your operating system's trust store.

Please check whether your operating system's trust store is up-to-date, containing the trust anchors for the Let's Encrypt certificates and remove any expired certificates.