# Defer acme certificate challenge until first http request

**URL:** <https://community.traefik.io/t/defer-acme-certificate-challenge-until-first-http-request/19273>\
**Category:** Traefik v2\
**Tags:** letsencrypt-acme\
**Created:** [July 18, 2023, 6:39pm UTC](https://community.traefik.io/t/defer-acme-certificate-challenge-until-first-http-request/19273 "2023-07-18T18:39:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [July 18, 2023, 7:48pm UTC](https://community.traefik.io/t/defer-acme-certificate-challenge-until-first-http-request/19273/2 "2023-07-18T19:48:28Z")

</div>

Running multiple Traefik instances with LetsEncrypt is not easily possible with Traefik v2 open source (using Docker Swarm). Paid Traefik EE or Traefik running in k8s support it.

The issue is that the newly started Traefik will try to create a cert and the next LE validation request might end up with the other instance, not knowing about the token, therefore failing the request. Not sure if this is different with dnsChallenge.

There have been a couple of workarounds discussed in the community about "clustered LetsEncrypt". (some examples: [1](https://community.traefik.io/t/docker-swarm-global-proxy-and-lets-encrypt/17663), [2](https://community.traefik.io/t/traefik-proxy-on-docker-swarm-multiple-managers/16642), [3](https://community.traefik.io/t/using-certbot-to-manage-certs-independently-from-traefik-possible/16199))

---

_[View the full topic](https://community.traefik.io/t/defer-acme-certificate-challenge-until-first-http-request/19273)._
