Certbot HTTP-01 Fails Behind a Proxy: Two Options

Symptom

Renewal works locally; fails once traffic goes through a proxy/CDN.

Root cause

The ACME challenge path is being redirected, blocked, or answered by the wrong layer.

Fix, in order

1. Pass the challenge path through untouchedlocation /.well-known/acme-challenge/ { proxy_pass http://origin; }
2. Kill redirect loops on that path# no http->https redirect for /.well-known/acme-challenge
3. If origin is unreachable, switch to DNS-01certbot certonly --preferred-challenges dns --manual

Prevent it coming back

Dry-run renewals after ANY proxy change.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Managed cloud hosting

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog