Let's Encrypt http-01 Fails: "Invalid Response From /.well-known/acme-challenge"

Let's Encrypt fetched your challenge URL and got the wrong answer: another server answered, a proxy intercepted it, or your web server doesn't serve the file. Follow the path the challenge takes.

What you'll see

Root causes

Web server/proxy doesn't serve the challenge path to LE

A redirect to HTTPS (creating a loop), an auth wall, a SPA catch-all swallowing /.well-known/acme-challenge/*, or a proxy returning a 404. curl the URL yourself: it should return the raw token text.

Port 80 blocked or redirected before reaching the right server

The challenge MUST arrive on port 80 of the host the DNS points to. A firewall, CDN in front (check proxy/origin rules), or another service on 80 answering instead.

Fix it

  1. Reproduce the challenge fetch locally
    curl -s -o - -w '\n%{http_code}\n' http://<domain>/.well-known/acme-challenge/test123   # should serve the literal token (200)
  2. nginx: allow the path before any redirect/auth
    # location /.well-known/acme-challenge/ { root /var/www/certbot; } — and EXCLUDE it from the 301-to-https redirect
  3. Verify port 80 reaches that server
    nc -zv -w 5 <domain> 80 ; sudo ss -ltnp | grep ':80 '
  4. CDN in front: ensure challenge requests hit origin, not a cached/authed edge
    # Cloudflare: a Page Rule / cache rule bypassing /.well-known/acme-challenge/* solves cached-edge answers

Field note

http-01 must use port 80 — no way around it. If 80 is impossible, switch to dns-01. curl-ing the challenge URL and reading what ACTUALLY comes back (SPA HTML? 301 loop? 404?) identifies the intercepting layer instantly.

Common questions

Why does it fail when the site itself works?

The site works on 443 through your normal stack, but the challenge comes in on port 80 and hits whatever answers THERE — a redirect, an auth prompt, or a catch-all that wasn't part of your testing.

Can I use dns-01 instead?

Yes — dns-01 avoids port 80 entirely and is required for wildcards anyway. It needs DNS API credentials (certbot-dns-cloudflare etc.) but is the more robust long-term choice.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.