Encrypt Renewal Fails in Plesk When Proxying Through Cloudflare?

Discussion about web hosting, domains and Plesk related matters.
Post Reply
taroki
Posts: 1
Joined: Wed Jun 25, 2025 1:46 pm

Hello

I am running several domains on a Plesk-managed VPS and have been using Let’s Encrypt for SSL certificates without issue until I enabled Cloudflare proxy (orange cloud) on a few domains. 8-) Since then; Let’s Encrypt renewals randomly fail with timeout / verification errors; even though the sites are reachable & DNS is correct. Switching Cloudflare to “DNS only” allows the renewal to succeed. :|

It seems like the Let’s Encrypt challenge can’t see the ACME verification files or headers are being stripped by Cloudflare’s reverse proxy. I have tried setting up a .well-known rewrite exclusion in .htaccess & even used the DNS challenge instead of HTTP—but Plesk’s default setup prefers HTTP-01 and doesn’t switch cleanly. 8-) This raises concerns for unattended renewals & automation reliability. Checked https://docs.plesk.com/en-US/onyx/admin ... %20aliases. documentation guide for reference.


Has anyone found a reliable way to use Let’s Encrypt and Cloudflare proxying together in a Plesk environment? :?: Are there CISSP Training module or config tweaks to force DNS challenge or bypass Cloudflare for the challenge route? :?:





Thank you !! 8-)
User avatar
Martin
Staff
Posts: 54
Joined: Sat Jan 13, 2024 12:44 pm

As you don't appear to be an Aquiss customer, this really is a question you need to ask with your hosting company.
Post Reply