simplificare
Verified User
- Joined
- Jul 10, 2019
- Messages
- 52
I've been seeing Let's Encrypt, automatic SSL renewals fail across my servers over the past two months and I'm not sure why... I've been racking my brain at the issue and need another set of eyes.
It all starts with an Auto SSL renewal failing -- Getting a notification in the message system saying the renewal failed, upon investigation it looks like the DNS Propagation is the failure point. -- When I try to renew manually, I get the same error.
I'm able to test while a renewal is in progress using dig or nslookup (both at 8.8.8.8 and at the local NS) that the acme record is published. I can also see it using whatsmydns.com, however for some reason Let's Encrypt isn't seeing it.
Does anyone see anything else that I might be missing?
Thanks!
It all starts with an Auto SSL renewal failing -- Getting a notification in the message system saying the renewal failed, upon investigation it looks like the DNS Propagation is the failure point. -- When I try to renew manually, I get the same error.
Code:
Found wildcard domain name and http challenge type, switching to dns-01 validation.
2024/02/29 00:11:28 [INFO] [*.heartstrong.life, heartstrong.life] acme: Obtaining SAN certificate
2024/02/29 00:11:29 [INFO] [*.heartstrong.life] AuthURL: https://acme-v02.api.letsencrypt.org/acme/authz-v3/320713853717
2024/02/29 00:11:29 [INFO] [heartstrong.life] AuthURL: https://acme-v02.api.letsencrypt.org/acme/authz-v3/320713853727
2024/02/29 00:11:29 [INFO] [*.heartstrong.life] acme: use dns-01 solver
2024/02/29 00:11:29 [INFO] [heartstrong.life] acme: Could not find solver for: tls-alpn-01
2024/02/29 00:11:29 [INFO] [heartstrong.life] acme: Could not find solver for: http-01
2024/02/29 00:11:29 [INFO] [heartstrong.life] acme: use dns-01 solver
2024/02/29 00:11:29 [INFO] [*.heartstrong.life] acme: Preparing to solve DNS-01
2024/02/29 00:11:31 2024/02/29 00:11:29 info executing task task=action=dns&do=delete&domain=heartstrong.life&name=_acme-challenge&type=TXT
2024/02/29 00:11:30 info executing task task=action=dns&do=add&domain=heartstrong.life&name=_acme-challenge&named_reload=yes&ttl=5&type=TXT&value=%22toiETefFq5iH6VuzpJBnqgvBhfXtk6P7PmuQu6bPEKI%22
2024/02/29 00:11:31 [INFO] [*.heartstrong.life] acme: Trying to solve DNS-01
2024/02/29 00:11:31 [INFO] [*.heartstrong.life] acme: Checking DNS record propagation using [8.8.8.8:53]
2024/02/29 00:12:01 [INFO] Wait for propagation [timeout: 5m0s, interval: 30s]
2024/02/29 00:12:01 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:12:31 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:13:02 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:13:32 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:14:02 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:14:32 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:15:02 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:15:32 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:16:02 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:16:32 [INFO] [*.heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:17:02 [INFO] [*.heartstrong.life] acme: Cleaning DNS-01 challenge
2024/02/29 00:17:03 2024/02/29 00:17:02 info executing task task=action=dns&do=delete&domain=heartstrong.life&name=_acme-challenge&type=TXT
2024/02/29 00:17:03 [INFO] [heartstrong.life] acme: Preparing to solve DNS-01
2024/02/29 00:17:05 2024/02/29 00:17:03 info executing task task=action=dns&do=delete&domain=heartstrong.life&name=_acme-challenge&type=TXT
2024/02/29 00:17:04 info executing task task=action=dns&do=add&domain=heartstrong.life&name=_acme-challenge&named_reload=yes&ttl=5&type=TXT&value=%22tG7lgcYoyHmv6PdGoas-I5ChZK_fAvoi7Q378XZTGV4%22
2024/02/29 00:17:05 [INFO] [heartstrong.life] acme: Trying to solve DNS-01
2024/02/29 00:17:05 [INFO] [heartstrong.life] acme: Checking DNS record propagation using [8.8.8.8:53]
2024/02/29 00:17:35 [INFO] Wait for propagation [timeout: 5m0s, interval: 30s]
2024/02/29 00:17:35 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:18:05 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:18:36 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:19:06 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:19:36 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:20:06 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:20:36 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:21:06 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:21:36 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:22:06 [INFO] [heartstrong.life] acme: Waiting for DNS record propagation.
2024/02/29 00:22:36 [INFO] [heartstrong.life] acme: Cleaning DNS-01 challenge
2024/02/29 00:22:37 2024/02/29 00:22:36 info executing task task=action=dns&do=delete&domain=heartstrong.life&name=_acme-challenge&type=TXT
2024/02/29 00:22:37 [INFO] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz-v3/320713853717
2024/02/29 00:22:37 [INFO] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz-v3/320713853727
2024/02/29 00:22:37 Could not obtain certificates:
error: one or more domains had a problem:
[*.heartstrong.life] time limit exceeded: last error: NS ns2.simplificare-dns.com. returned NXDOMAIN for _acme-challenge.heartstrong.life.
[heartstrong.life] time limit exceeded: last error: NS ns2.simplificare-dns.com. returned NXDOMAIN for _acme-challenge.heartstrong.life.
Failed to issue new certificate
I'm able to test while a renewal is in progress using dig or nslookup (both at 8.8.8.8 and at the local NS) that the acme record is published. I can also see it using whatsmydns.com, however for some reason Let's Encrypt isn't seeing it.
Does anyone see anything else that I might be missing?
Thanks!