Now in such domain I have
_acme-challenge-test="0"
_acme-challenge="xxxxxxxxxxxxxxxxxxxx" (proper token)
at the moment I only hope SMtalk has not already joined the alaskan bush people...And I hope you don't have to run to the bush people on renewing.
Thank you for update, but I don't know why my server still same problem:
Found wildcard domain name and http-01 challenge type, switching to dns-01 validation.
DNS challenge test fail for _acme-challenge-test.xxxxxx.net IN TXT "pre-check", retrying...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
Retry failed, trying again in 15s...
DNS validation failed. Exiting...
He says it's not a problem because the DNS about the acme challenge could exists or not, doesn't matter.So I will just wait and be curious to the result of smtalk's investigations.
Thanks for the update!
@Richard
He says it's not a problem because the DNS about the acme challenge could exists or not, doesn't matter.
In the end I understand the obvious: the important thing to have a certificate no matter how.
Let's hope for the renewal of the 60+ domains that, being a migration, it will happen basically in 1 day for all of them. I'm getting ready to join the alaskan bush people, just in case....
You're using external DNS correct? He says wildcard does not work with external DNS, but you have it working so I don't understand what this means.He says it's not a problem because the DNS about the acme challenge could exists or not, doesn't matter.
Basically it's all ok regardless of the presence of the acme challenge record and regardless of its value.He says it's not a problem because the DNS about the acme challenge could exists or not, doesn't matter.Sorry I don't understand this sentence (I'm not native English):
Since halloween is coming let's add some weirdness: I don't even need to create _acme-challenge-test manually anymore.You're using external DNS correct? He says wildcard does not work with external DNS, but you have it working so I don't understand what this means.
Ofcourse it's important to have a certificate, but it's odd you got it renewed with creating a -test challenge entry yourself
Yes but what is ok? The script or the fact that in your case things are working while they should not work since you use external DNS?Basically it's all ok regardless of the presence of the acme challenge record and regardless of its value.
Yes oke, but is this new behaviour being "as designed" so did SMtalk fix it so it will work now with wildcards when using external nameservers?It's a total new behaviour.
CT Precertificate Poison: critical
0000 - 05 00
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1(0)
From your question depends me joining the alaskan bush people or not. I reckon/hope yes. At the moment I only know for sure that relaunching LE for the second time returns no errors.And is this only working when creating new domains or is this also working on renewal?
Maybe it's working since LE 1.1.31did SMtalk fix it so it will work now with wildcards when using external nameservers?
That could be the case. Thank you in any case for sharing your test results. I don't have another domain to create at this moment on the vps with external DNS but will test as soon as I do.Maybe it's working since LE 1.1.31
Just in case... get acquainted!Due to your positive results I've decided to stay for the moment and not join the alaskan bush people, maybe on the next crisis.