How to disable `etesync.lemnoslife.com` in:

```bash
certbot --nginx-ctl /usr/sbin/nginx --force-renew renew -v
```
```
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/gitea.lemnoslife.com-0001.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Plugins selected: Authenticator nginx, Installer nginx
Renewing an existing certificate for v.lemnoslife.com and 6 more domains
Performing the following challenges:
http-01 challenge for etesync.lemnoslife.com
Waiting for verification...
Challenge failed for domain etesync.lemnoslife.com
http-01 challenge for etesync.lemnoslife.com

Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: etesync.lemnoslife.com
Type: unauthorized
Detail: 54.37.228.22: Invalid response from https://etesync.lemnoslife.com/.well-known/acme-challenge/JxUZthdTFmA9D0E5q16rfs2DNdtokJVPm3m9jrl3vXc: 404

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Cleaning up challenges
Failed to renew certificate gitea.lemnoslife.com-0001 with error: Some challenges have failed.
```

?
Sep 30, 10:52pm

You can't renew "some of" a certificate — etesync.lemnoslife.com is one of the SANs in the gitea.lemnoslife.com-0001 certificate, so Certbot must validate it every time. To get rid of it you have to reissue the certificate without that domain:

1. See which domains are in the cert

bash
certbot certificates
# or
grep 'Domains' /etc/letsencrypt/renewal/gitea.lemnoslife.com-0001.conf

2. Reissue with the same cert-name, minus etesync

List every domain except etesync.lemnoslife.com — passing -d with an existing --cert-name replaces the domain set:

bash
certbot --nginx-ctl /usr/sbin/nginx \
  --cert-name gitea.lemnoslife.com-0001 \
  -d v.lemnoslife.com -d gitea.lemnoslife.com -d <...other domains...> \
  --force-renewal

Afterwards, plain certbot renew will no longer touch etesync.

Alternative: keep the domain, fix the 404

The error shows the challenge is being redirected to HTTPS and then 404s — typically because the etesync vhost proxies everything to the etesync backend. Adding an ACME location block before the proxy in that server block fixes it without removing the domain:

nginx
location ^~ /.well-known/acme-challenge/ {
    root /var/www/certbot;   # or /var/www/html
    default_type "text/plain";
}

If you just want to skip that certificate entirely

bash
certbot renew --cert-name <some-other-cert>    # renew only that one
# or disable it permanently:
certbot disable --cert-name gitea.lemnoslife.com-0001   # Certbot ≥ 2.0

Note the disable command skips the whole certificate (all 7 domains), not just etesync — so option 2 is the right one if you only want etesync gone.

Sep 30, 10:52pm

This is a shared conversation and may include unverified content that doesn't reflect Mistral AI's views. Login to resume chatting.

Vibe can make mistakes. Check answers. Learn more