Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM 9.707-5 - Let’s Encrypt failed: Failed to retrieve the current Terms of Service link

Hello, 

I appear to be having issues trying to renew LE Certificates. This started a few days ago (when due for renewal) and initially I did come to this forum for answers and found that one post suggested to update to the latest UTM version. I'm now up to 9.707-5 but still have the same issue. 

Patterns also up to date:

Current pattern version: 204063
Latest available pattern version: 204063

It appears to be related to being unable to find the TOS but all links it shows resolve fine. The certificates I have are used for UTM Management and WAF.

Looking at the logs I see the following after turning the service off and back on...

2021:10:10-09:15:14 utm letsencrypt[9881]: I Create account: creating new Let's Encrypt acccount
2021:10:10-09:15:15 utm letsencrypt[9881]: E Create account: Incorrect response code from ACME server: 500
2021:10:10-09:15:15 utm letsencrypt[9881]: E Create account: URL was: acme-v02.api.letsencrypt.org/directory
2021:10:10-09:15:15 utm letsencrypt[9881]: E Create account: TOS_UNAVAILABLE: Failed to retrieve the current Terms of Service URL
2021:10:10-09:15:15 utm letsencrypt[9881]: E Create account: failed to create account

Prior to that, an attempt at renewing:

2021:10:10-08:44:02 utm letsencrypt[1020]: E Renew certificate: Incorrect response code from ACME server: 500
2021:10:10-08:44:02 utm letsencrypt[1020]: E Renew certificate: URL was: acme-v02.api.letsencrypt.org/directory
2021:10:10-08:44:02 utm letsencrypt[1020]: I Renew certificate: handling CSR REF_CaCsrXXXXLetsEncry for domain set [DOMAINS]
2021:10:10-08:44:02 utm letsencrypt[1020]: E Renew certificate: TOS_UNAVAILABLE: Could not obtain the current version of the Let's Encrypt Terms of Service
2021:10:10-08:44:02 utm letsencrypt[1020]: I Renew certificate: sending notification WARN-603
2021:10:10-08:44:02 utm letsencrypt[1020]: [WARN-603] Let's Encrypt certificate renewal failed accessing Let's Encrypt service
2021:10:10-08:44:02 utm letsencrypt[1020]: I Renew certificate: execution failed

The UTM has been rebooted, no change. I've turned off Web protection, no change...

Any ideas appreciated.

Thanks!


This thread was automatically locked due to age.
Parents
  • Seems LE is broken once again.

    We exchanged certificates last time this came up, and the correct certificate is installed, as instructed in this thread. Whenever I try to manually renew the certs, logs throws errors:

    2022:03:10-11:47:58 mail letsencrypt[793]: E Renew certificate: COMMAND_FAILED: ERROR: Challenge is invalid! (returned: invalid) (result: ["type"]	"http-01"
    2022:03:10-11:47:58 mail letsencrypt[793]: E Renew certificate: COMMAND_FAILED: ["validated"]	"2022-03-10T10:47:44Z")
    2022:03:10-11:47:58 mail letsencrypt[793]: I Renew certificate: sending notification WARN-603
    2022:03:10-11:47:58 mail letsencrypt[793]: [WARN-603] Let's Encrypt certificate renewal failed accessing Let's Encrypt service
    2022:03:10-11:47:58 mail letsencrypt[793]: I Renew certificate: execution completed (CSRs renewed: 0, failed: 1)
  • So this seems to just have been a hickup. About 1 AM tonight, the certs finally renewed without user intervention. It is good that it is working now, but I kinda hate I can't figure out what is causing this issue.

Reply
  • So this seems to just have been a hickup. About 1 AM tonight, the certs finally renewed without user intervention. It is good that it is working now, but I kinda hate I can't figure out what is causing this issue.

Children