A rate limit prevents DCV

On my WHM server, each client has a subdomain under the *.type.pl domain (the base domain).
Recently, I’ve been experiencing an issue with AutoSSL related to rate limits. The error I receive is:
ERROR “Let’s Encrypt™” general error (.type.pl): A rate limit prevents DCV.
Could I kindly ask for the rate limits for this domain to be relaxed?

My domain is:
type.pl
I ran this command:

Manage AutoSSL

It produced this output:
ERROR “Let’s Encrypt™” general error (tomb.type.pl): A rate limit prevents DCV.

My web server is (include version):
cPanel & WHM v110.0.50 (STANDARD)

The operating system my web server runs on is (include version):
cPanel & WHM v110.0.50 (STANDARD)

My hosting provider, if applicable, is:
openhost.pl

I can login to a root shell on my machine (yes or no, or I don't know):
yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

Are you the owner of the type.pl domain? If so, you could ask a rate limit override as per Rate Limits - Let's Encrypt. If not, then you cannot do anything.

2 Likes

It would help to have the actual error message from Let's Encrypt. I don’t know if that’s in an AutoSSL log somewhere you can get at.

4 Likes

I'm suspecting the New Certificates per Registered Domain limit, as I can't even get a list of certs for type.pl from crt.sh (it just times out) and the domain is not on the PSL.

That said, reading this:

This is a good reason to have the domain listed on the Public Suffix List anyway for security reasons. As a side effect, Let's Encrypt would count the New Certificates per Registered Domain rate limit from the subdomain instead of apex domain, but that cannot be the reason for PSL inclusion :slight_smile:

4 Likes

This appears likely. Censys reports 85 certificates for type.pl issued by Let's Encrypt since 2024-12-24 (102 since 2024-12-23).

5 Likes

Hi @W1T3C,

Here is a list of issued certificates for the FQDN crt.sh | tomb.type.pl, the latest being 2024-09-26 and expiring 2024-12-25.

I assume you are aware the previous certificates were issued by C=US, O="cPanel, LLC", CN=cPanel ECC Domain Validation Secure Server CA 3, and that you either want to replace with or add Let’s Encrypt issued certificate.

Presently https://crt.sh/?q=type.pl&exclude=expired&group=none and Let's Debug Toolkit I am not seeing being limited.

And the online tool Let's Debug show "OK"
https://letsdebug.net/tomb.type.pl/2323003

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.