Hi, I did install livekit server with init script ...
# ask-ai
b
Hi, I did install livekit server with init script and caddy is setup to listen only on port 443, do I need to add 80 too? Because now lets encrypt fails to create certificates
t
Thanks for reaching out, Vytautas. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
I’m glad you asked! To help Let's Encrypt create and renew your TLS certificates, you’ll need to open port 80. That’s because Caddy uses the ACME protocol’s HTTP-01 challenge by default, which checks domain ownership by serving a challenge response over HTTP on port 80. Without opening this port, Let's Encrypt won’t be able to complete the certificate issuance process. If opening port 80 isn’t something you’re comfortable with, no worries! You can reconfigure Caddy to use the DNS-01 challenge instead, though it does involve a bit more setup. I’m here to help if you decide to go that route! Sources: Deploy to a VM | LiveKit Docs
b
how do I "open port 80", caddy config has: listen: [":443"] do I need to append it there?
t
Thanks for reaching out! Could you please let me know if you're using Caddy in a standalone setup, with LiveKit's deployment tools, or maybe in a different integration? Understanding this will really help me guide you on the best way to configure it to listen on port 80. Sources: Deploy to a VM | LiveKit Docs
b
I am using caddy installed by using init_script when setting up livekit I also read that caddy should be automatically using: TLS-ALPN challenge That just needs port 443.
t
By default, the LiveKit
init_script
sets up Caddy to use Let's Encrypt for certificate provisioning, usually relying on the HTTP-01 challenge, which needs port 80 to be open. I understand that sometimes port 80 might be blocked, which can be a bit tricky. While Caddy does support the TLS-ALPN-01 challenge (using only port 443), this isn't enforced by default in the configuration. If you find that port 80 is blocked and want to make sure TLS-ALPN-01 is used, you might need to tweak the generated
caddy.yaml
file to explicitly specify the ACME challenge method. On the bright side, Caddy can often automatically switch to TLS-ALPN-01 if port 80 isn’t available. Would you like me to walk you through how to customize the Caddy configuration to enforce TLS-ALPN-01 challenges? I’m here to help! Sources: Deploy to a VM | LiveKit Docs
b
yes, please
how to customize the Caddy configuration to enforce TLS-ALPN-01 challenges