Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is:just-passed.com
I ran this command:install Lets Encrypt on domain only
The parent zone says: You use DNSSEC. But your zone doesn't send the required DNSKEY.
Result:
Fatal error: Parent zone has a signed DS RR (Algorithm 8, KeyTag 28076, DigestType 2, Digest Mfb5Ps9Qt11xWcbLqQCgWboer9jOM7BKBjsQj1EOwAk=), but the destination DNSKEY doesn't exist or doesn't validate the DNSKEY RR set. No chain of trust created.
Update your DNSSEC or remove it.
PS: Broken DNSSEC -> it's not possible to find an ip address.
Thank you, yes I ran that test from looking at other topics, so just looking into this now but cant find where to update or remove DNSSEC. I am using a reseller account with a host and from there pointing the domain to a dedicated server IP address.
Yes Juergen, it is Heart Internet, they are trying to say its a fault with my server and letsencrypt. Ok I shall raise this with them again, thank you.
I would agree Juergen, this site just went off for no reason this morning and I have been on to support all day long, it took 6 hours to get past first line support who did not know anyting about certificates or DNS. Thank you again for your help, just need to get my customers site back. strange how its only 1 domain on my server out of 300 that I own