Kosmik
Honorary Master
So been struggling to use a program locally to create a cert off Let's Encrypt. Tried certbot, using a program called Certify The Web as well.
All the programs function by having a file for the CA to read from a website. These all use standard http on port 80 to check , setup a mini site to have that checked so I can get the cert. Did the normal story of port forwarding and fire wall, all seemed fine but still blocked from external.
Called my isp and had them open the port on their device. Still no joy. Now I already have a few ports open with internal Nats so very sure that my internal network was fine and went through a very painful process with the isp. After much escalation and explaining that if THEIR router can't even see the incoming requests, sonething was wrong, finally got to someone with a decent networking bent who discovered that no matter what was done, port 80 remained closed. He was going to escalate and get back to me.
Now I get a call from the isp, "Sorry, we can't open port 80 because your fno uses it to control their devices". Offered to open another port but told them it won't help because the cert programs all use port 80. Going to escalate and get back to me.
So, firstly, anyone else aware of this restriction by a FNO? And secondly, anyone know of another means? I can't use dns validation as I'm just using no-ip as a dyndns service and want a non self signed cert for consumption locally. They don't show the addition of subdomains unless you pay and I'm really trying to avoid it as is purely for personal use.
All the programs function by having a file for the CA to read from a website. These all use standard http on port 80 to check , setup a mini site to have that checked so I can get the cert. Did the normal story of port forwarding and fire wall, all seemed fine but still blocked from external.
Called my isp and had them open the port on their device. Still no joy. Now I already have a few ports open with internal Nats so very sure that my internal network was fine and went through a very painful process with the isp. After much escalation and explaining that if THEIR router can't even see the incoming requests, sonething was wrong, finally got to someone with a decent networking bent who discovered that no matter what was done, port 80 remained closed. He was going to escalate and get back to me.
Now I get a call from the isp, "Sorry, we can't open port 80 because your fno uses it to control their devices". Offered to open another port but told them it won't help because the cert programs all use port 80. Going to escalate and get back to me.
So, firstly, anyone else aware of this restriction by a FNO? And secondly, anyone know of another means? I can't use dns validation as I'm just using no-ip as a dyndns service and want a non self signed cert for consumption locally. They don't show the addition of subdomains unless you pay and I'm really trying to avoid it as is purely for personal use.
Last edited: