From b33f12405277bd0074da341739f0b7da4535aa23 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Sun, 13 Sep 2026 23:04:15 -0400 Subject: [PATCH] lith: let certbot's challenge through before the :80 redirect MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The named site block answered the challenge itself, and a bare `redir` sorts ahead of `handle` in Caddy's directive order — so the challenge file never got served. No site block for the host; two ordered handles on :80. Co-Authored-By: Claude Fable 5.1 --- lith/Caddyfile | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/lith/Caddyfile b/lith/Caddyfile index 6676ba13a0..2f8bbde0b2 100644 --- a/lith/Caddyfile +++ b/lith/Caddyfile @@ -1253,16 +1253,18 @@ gym.anthonyzollo.com { # origin cert loaded above is a self-issued *.aesthetic.computer wildcard, and # Caddy skips ACME for any name a loaded cert already covers. So certbot # fetches it by HTTP-01 through the webroot served below (:80), and the door -# reads /etc/letsencrypt/live/inbound.aesthetic.computer/. -inbound.aesthetic.computer { - respond "Amail inbound — SMTP on :25" 200 -} +# reads /etc/letsencrypt/live/inbound.aesthetic.computer/. There is no site +# block for the host on purpose: one would answer the challenge itself. :80 { # certbot's HTTP-01 challenge files, before the redirect swallows them. + # Both are `handle`s on purpose: a bare `redir` sorts ahead of `handle` + # in Caddy's directive order and would answer first. handle /.well-known/acme-challenge/* { root * /var/lib/amail-acme file_server } - redir https://{host}{uri} 301 + handle { + redir https://{host}{uri} 301 + } } -- 2.51.2