从sslforfree.com获取SSL时遭遇acme-challenge错误及Node.js代码求助
Let’s walk through the key issues in your code and setup that are likely causing the ACME verification failure with sslforfree.com, plus how to fix them:
1. Fix the Missing next Parameter
Your route callback tries to call next(err) when there’s an error, but next isn’t defined as a parameter. This will throw a reference error that breaks the verification flow. Update the route handler like this:
app.get('/.well-known/acme-challenge/:name', function(req, res, next) { // Added `next` to parameters var options = { root: __dirname + '/public/', dotfiles: 'deny', headers: { 'x-timestamp': Date.now(), 'x-sent': true } }; var fileName = req.params.name; res.sendFile(fileName, options, function (err) { if (err) { next(err); // Now `next` is properly defined } else { console.log('Sent:', fileName); } }); });
2. Remove the Incomplete Redirect
You have an unfinished res.redirect("...") line at the end of the route. This sends an invalid, partial redirect response right after trying to serve the challenge file, which confuses the ACME validator. Delete that line entirely.
3. Verify Challenge File Placement & Permissions
Double-check these critical details:
- The ACME challenge file (with the random string name from sslforfree.com) must live in
public/.well-known/acme-challenge/relative to your Node.js script. - The file must have read permissions (usually
644) so your server can access it. - The file content must be exactly the verification string provided — no extra spaces, newlines, or characters.
4. Ensure Your Server Runs on Port 80
ACME’s HTTP-01 validation requires your server to be accessible on port 80 (standard HTTP port). Add this code to start your HTTP server correctly:
// Start HTTP server on port 80 (required for ACME validation) http.createServer(app).listen(80, function() { console.log('HTTP server running on port 80 — ready for ACME check'); });
Note: On most systems, binding to port 80 needs root privileges. If you can’t run as root, use a reverse proxy (like Nginx) to forward port 80 traffic to your Node.js server on a higher port.
5. Check Network & Firewall Settings
- Confirm your server’s firewall allows incoming traffic on port 80.
- If your server is behind a NAT or load balancer, ensure port 80 is forwarded to your Node.js instance.
- Verify your domain’s DNS A/AAAA records point to your server’s public IP address.
6. Test Access Manually First
Before re-trying the SSL request, test if the challenge file is accessible:
curl http://your-domain.com/.well-known/acme-challenge/your-challenge-filename
If this returns the exact verification string, your setup is correct. If you get a 404, 500, or other error, fix that issue first.
内容的提问来源于stack exchange,提问作者Domos Suszta

