Fix the 403 unauthorized errors Letโ€™s Encrypt may encounter when it renews your certificate with a GET request to http://your-site.com/.well-known/acme-challenge/a-long-hash-here.

When nginx is set up as a reverse proxy, a location rule in your nginx.conf authorizes this path.

Preparation

  • nginx set up as a reverse proxy in front of your website

Walkthrough

Allow the ACME challenge in nginx.conf

You can add this piece of code in your nginx.conf:

server {
    [...]

    # Allow Let's Encrypt
    location ~ ^/.well-known/acme-challenge {
        allow all;
    }
}
  • ~ means itโ€™s a regex
  • ^/.well-known/acme-challenge is the beginning of the URL used by Letโ€™s Encrypt

With Plesk

If youโ€™re using Plesk, this configuration is found under Apache & Nginx settings of your website:

Plesk Apache & Nginx settings of a website

Which leads to this pretty handy text editor:

Plesk nginx directives text editor

Validation & troubleshooting

Before, a 403 error:

Nginx acme-challenge request returning 403

After, a 404 (which is OK in our case):

Nginx acme-challenge request returning 404

Going further