DirectAdmin 1.708

fln

Administrator
Staff member
Joined
Aug 30, 2021
Messages
1,462
We are happy to announce the release of DirectAdmin 1.708.

A full release change log is here:

DirectAdmin 1.708


The update should be automatically available for all installations subscribed to the current release channel.

We appreciate all the feedback on forums and issues reported in the ticketing system.

Thanks!
 
MariaDB 10.6.28 rpms are missing for AlmaLinux 8.x

Bash:
download_cached: using cached '/usr/local/directadmin/custombuild/cache/MariaDB-client-10.6.28-1.el8.x86_64.rpm' file
download_cached: using cached '/usr/local/directadmin/custombuild/cache/MariaDB-devel-10.6.28-1.el8.x86_64.rpm' file
download_cached: downloading 'https://mirror.mariadb.org/yum/10.6/rhel/8/x86_64/rpms/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/cache/MariaDB-server-10.6.28-1.el8.x86_64.rpm'
#=#=#
curl: (7) Failed to connect to mirror.ihost.md port 443: Connection refused
safe_download: downloading 'https://mirror.mariadb.org/yum/10.6/rhel/8/x86_64/rpms/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/tmp/tmp.zFCcMPgAF9.safe_download' failed (0/3)
#=#=#
curl: (22) The requested URL returned error: 404
safe_download: downloading 'https://files.directadmin.com/cache/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/tmp/tmp.zFCcMPgAF9.safe_download' failed (0/3)
#=#=#
curl: (7) Failed to connect to mirror.ihost.md port 443: Connection refused
safe_download: downloading 'https://mirror.mariadb.org/yum/10.6/rhel/8/x86_64/rpms/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/tmp/tmp.zFCcMPgAF9.safe_download' failed (1/3)

curl: (22) The requested URL returned error: 404
safe_download: downloading 'https://files.directadmin.com/cache/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/tmp/tmp.zFCcMPgAF9.safe_download' failed (1/3)
#=#=#
curl: (7) Failed to connect to mirror.ihost.md port 443: Connection refused
safe_download: downloading 'https://mirror.mariadb.org/yum/10.6/rhel/8/x86_64/rpms/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/tmp/tmp.zFCcMPgAF9.safe_download' failed (2/3)

curl: (22) The requested URL returned error: 404
safe_download: downloading 'https://files.directadmin.com/cache/MariaDB-server-10.6.28-1.el8.x86_64.rpm' to '/usr/local/directadmin/custombuild/tmp/tmp.zFCcMPgAF9.safe_download' failed (2/3)

but it exists here https://mirrors.n-ix.net/mariadb/yum/10.6/rhel/8/x86_64/rpms/

Kindly advice.
 
Hi

I seems like the new ACME system has still a little bug.
I have been unable to request wildcard certificates.

I need to do indept troubleshooting, I did not have the time yet, sorry for that.

It just feels like DirectAdmin (or lego) already requested the _acme-challenge TXT record BEFORE the record existed in the secondary slave nameservers. I can only speculate, I didn't do any research.

Adding a lower TTL txt _acme-challenge record with the value "persistent-record" does not really fix the problem.
Lowering the negavive TTL value in the SOA record also does not fix the problem.

Maybe the lego client should only request the challenge record after a little latency period that should give enough time for the secondary slave nameservers to pick up the needed DNS changes.
acme.sh does this perfectly, I don't know much about lego.

Example:
2026-08-24T16:35:12.13 - the DNS _acme-challenge record is added
2026-08-24T16:35:12.32 - lego tries to solve the record
not enough time is given for DNS to propagate

Additionally
If you happen to visit the "SSL/TLS Certificates" page in DirectAdmin BEFORE the domain is registered (it can take up to 30 minutes for some TLD's before they update their zone after registration) negative cache exist if DNS records are requested by the DirectAdmin system.
I don't know how DirectAdmin knows if the domain is configured correctly in DNS (?) Is it doing DNS requests to verify so?
DNS records should only be requested after you explicitly click the button "PROVISION NOW", never before.


Code:
Failed to issue a TLS certificate for redacted.com, *.redacted.com DNS names.
--- Command output
2026-08-24T16:35:11.085586401+02:00 INFO  Obtaining SAN certificate. domains="redacted.com, *.redacted.com"
2026-08-24T16:35:11.836662512+02:00 INFO  Use solver. domain=*.redacted.com type=dns-01
2026-08-24T16:35:11.836727541+02:00 INFO  Use solver. domain=redacted.com type=dns-01
2026-08-24T16:35:11.836746431+02:00 INFO  dns01: preparing to solve the challenge. domain=*.redacted.com
2026-08-24T16:35:11.960891378+02:00 INFO  2026/08/24 16:35:11  info executing task            task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&ttl=120&type=TXT&value=%22persistent-record%22
2026-08-24T16:35:12.046960211+02:00 INFO  2026/08/24 16:35:12  info finished task             duration=91.983252ms task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&ttl=120&type=TXT&value=%22persistent-record%22
2026-08-24T16:35:12.131097081+02:00 INFO  2026/08/24 16:35:12  info executing task            task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&named_reload=yes&ttl=120&type=TXT&value=%22cIS3NzB3eyVlR7gD-1TpCN6O5pHDqwjoEupRoZ382HM%22
2026-08-24T16:35:12.319096896+02:00 INFO  2026/08/24 16:35:12  info finished task             duration=187.974858ms task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&named_reload=yes&ttl=120&type=TXT&value=%22cIS3NzB3eyVlR7gD-1TpCN6O5pHDqwjoEupRoZ382HM%22
2026-08-24T16:35:12.324770859+02:00 INFO  dns01: trying to solve the challenge. domain=*.redacted.com
2026-08-24T16:35:12.326879995+02:00 INFO  dns01: waiting for record propagation timeout=5m0s interval=30s domain=*.redacted.com
2026-08-24T16:35:42.330817759+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:36:12.334104081+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:36:42.365638379+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:37:12.369510988+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:37:42.391890667+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:38:12.423980196+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:38:42.437921848+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:39:12.441835632+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:39:42.463721021+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:40:12.468762654+02:00 INFO  dns01: waiting for record propagation. domain=*.redacted.com
2026-08-24T16:40:42.490723716+02:00 INFO  dns01: cleaning DNS-01 challenge. domain=*.redacted.com
2026-08-24T16:40:42.588164149+02:00 INFO  2026/08/24 16:40:42  info executing task            task=action=dns&do=delete&domain=redacted.com&name=_acme-challenge&named_reload=yes&type=TXT&value=%22cIS3NzB3eyVlR7gD-1TpCN6O5pHDqwjoEupRoZ382HM%22
2026-08-24T16:40:42.812394267+02:00 INFO  2026/08/24 16:40:42  info finished task             duration=224.217657ms task=action=dns&do=delete&domain=redacted.com&name=_acme-challenge&named_reload=yes&type=TXT&value=%22cIS3NzB3eyVlR7gD-1TpCN6O5pHDqwjoEupRoZ382HM%22
2026-08-24T16:40:42.820263028+02:00 INFO  dns01: preparing to solve the challenge. domain=redacted.com
2026-08-24T16:40:42.942027242+02:00 INFO  2026/08/24 16:40:42  info executing task            task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&ttl=120&type=TXT&value=%22persistent-record%22
2026-08-24T16:40:43.023432873+02:00 INFO  2026/08/24 16:40:43  info finished task             duration=89.849846ms task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&ttl=120&type=TXT&value=%22persistent-record%22
2026-08-24T16:40:43.105226939+02:00 INFO  2026/08/24 16:40:43  info executing task            task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&named_reload=yes&ttl=120&type=TXT&value=%22AqNwLZZaz6jYtHiVg2EWJ96X7NmzmIMv119xGqde0WE%22
2026-08-24T16:40:43.482012646+02:00 INFO  2026/08/24 16:40:43  info finished task             duration=376.803552ms task=action=dns&do=add&domain=redacted.com&name=_acme-challenge&named_reload=yes&ttl=120&type=TXT&value=%22AqNwLZZaz6jYtHiVg2EWJ96X7NmzmIMv119xGqde0WE%22
2026-08-24T16:40:43.487519229+02:00 INFO  dns01: trying to solve the challenge. domain=redacted.com
2026-08-24T16:40:43.490016922+02:00 INFO  dns01: waiting for record propagation timeout=5m0s interval=30s domain=redacted.com
2026-08-24T16:41:13.493747987+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:41:43.515815300+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:42:13.547875561+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:42:43.580233833+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:43:13.584152675+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:43:43.607022945+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:44:13.638732885+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:44:43.671050209+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:45:13.675192694+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:45:43.697515196+02:00 INFO  dns01: waiting for record propagation. domain=redacted.com
2026-08-24T16:46:13.726747112+02:00 INFO  dns01: cleaning DNS-01 challenge. domain=redacted.com
2026-08-24T16:46:13.818694602+02:00 INFO  2026/08/24 16:46:13  info executing task            task=action=dns&do=delete&domain=redacted.com&name=_acme-challenge&named_reload=yes&type=TXT&value=%22AqNwLZZaz6jYtHiVg2EWJ96X7NmzmIMv119xGqde0WE%22
2026-08-24T16:46:14.194729088+02:00 INFO  2026/08/24 16:46:14  info finished task             duration=375.995005ms task=action=dns&do=delete&domain=redacted.com&name=_acme-challenge&named_reload=yes&type=TXT&value=%22AqNwLZZaz6jYtHiVg2EWJ96X7NmzmIMv119xGqde0WE%22
2026-08-24T16:46:14.617672876+02:00 INFO  Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/2679300401/765927547641
2026-08-24T16:46:14.933190292+02:00 INFO  Deactivating authorization. url=https://acme-v02.api.letsencrypt.org/acme/authz/2679300401/765927547651
2026-08-24T16:46:15.086399382+02:00 ERROR Error error="obtain certificate: resolver: one or more domains had a problem: [*.redacted.com: dns01: time limit exceeded: last error: recursive nameservers: NS  returned NXDOMAIN for _acme-challenge.redacted.com.] [redacted.com: dns01: time limit exceeded: last error: recursive nameservers: NS  returned NXDOMAIN for _acme-challenge.redacted.com.]"
---

Kind regards
Dries
 
Last edited:
I seems like the new ACME system has still a little bug.
I have been unable to request wildcard certificates.

Which dns resolvers do you use in /etc/resolv.conf? You might try this one for testing purposes:

Code:
nameserver 1.1.1.1
nameserver 1.0.0.1
nameserver 8.8.8.8

Update the file and try again to request a wildcard certificate. Keep me updated)
 
I haven't tried it, but I'm most certainly sure this will fix the problem.
Still, this is not the right fix.

lego should wait a couple of seconds for the DNS changes to propagate
AND the dns placeholder "persistent-record" is not a fix
AND the decrease of the negative ttl in the SOA record is not a fix as well

Kr
Dries
 
@Driesp, the persistent record with 2min TTL is working workaround for this problem, but it works only on the second certificate issue attempt (on the first attempt NXDOMAIN can be cached before persistent record is added). However this is workaround for DNS caching, not a proper solution as you mentioned.

In the next DA version 1.709 we have a more reliable solution. The ACME client will stop using the system resolver when checking for DNS records propagation. This will allow us to detect the added records faster and avoid DNS caching completely. However it might not be good in some corner cases (servers that can not communicate with external DNS servers due to network filtering). We are adding a new directadmin.conf option, that makes ACME client to use local resolver if needed.

You could switch to alpha release channel to check if this helps in your case.
 
Thank you, this is a good solution. I will check later today if this fixes our problem, but I'm confident it will.
letsencrypt.sh was using public dns as well before for this purpose, I suppose most already have exceptions in their firewall if it was needed.

Will you consider removing the dns placeholder "persistent-record" in time again?

If I understand correctly, lego checks the authoritative servers and the resolvers for record propagation before the acme provider is given a go signal, is this right? This should be default lego behaviour.

Edit:
It seems like this is a bug in lego, there is no option to let lego wait a bit for propagation to happen. It feels like the only right way for DirectAdmin is using manual mode and do the dns checks ourselves until lego implements a real fix.
Using public non caching resolvers in lego is perfect as well.

Kr
Dries
 
Last edited:
You could switch to alpha release channel to check if this helps in your case.
Hi fln, I switched to the alpha release, and it works if you request it via DirectAdmin.
I can see the request uses --dns.propagation.disable-rns when using the DNS-01 challenge.

This is the correct fix, lego will still query the authoritative servers to check if the record exists and not the local resolvers.

But the automated, background ACME system still try to request the wildcard certificate without the option --dns.propagation.disable-rns, so these are still failing. This bug still needs to be addressed.

Kr
Dries
 
You are likely seeing old executions of lego started with and older DA (prior upgrade to alpha). The background tasks and on demand provision requests uses the same logic (code to prepare lego execution arguments).
 
Back
Top