Solved Acme and wildcard certificates

jigster

Verified User
Joined
Jul 23, 2021
Messages
123
Since switching to the new Acme SSL certificate system, no wildcard certs are being issued. Instead subdomain SSL certs are being issued.

'Prefer wildcard certificates' is on for all domains.

We use PowerDNS to sync the local DNS to our own nameservers on separate servers. This works perfectly.

/etc/resolv.conf has:
nameserver 1.1.1.1
nameserver 1.0.0.1

If I debug I get (I've changed the domains for privacy):

Code:
# da taskq --debug 1 --run 'action=rewrite&value=letsencrypt&domain=testdomain.com
2026/09/28 12:41:53 debug comparing external NS records with local NS records acme-mode=domain domain=testdomain.com local_ns=[] match=false public_ns=[ns1.ournameservers.net. ns2.ournameservers.net.] user=testuser zone=testdomain.com
2026/09/28 12:41:53 debug NS records do not match, check for DNS challenge redirects with CNAME acme-mode=domain domain=testdomain.com user=testuser
2026/09/28 12:41:53 debug fake identity CNAME record, deny DNS challenge acme-mode=domain domain=testdomain.com query=_acme-challenge.testdomain.com. user=testuser

It seems to think local ns is blank, even though it's not. What could be causing this? The nameservers in the local /var/named/testdomain.com.db are the same as those at our external nameservers (as they're synced with PowerDNS)? Any help is appreciated, as we're getting a lot of customer support requests as a result of this! Thanks
 
Always happens, you spend ages looking for a fix before posting here, then the second you do, you find the solution! I just needed to add localhost to allow-query in /etc/named.conf. I didn't need that before so only had my external nameserver IPs in there.
 
Back
Top