ACME staging server fails with IPv6 and HTTPS redirect: “Timeout during connect”

No, not really. HTTP->HTTPS redirects are common even though not optimal.

And, Flexential is the primary center which must succeed to grant certs. At over 300 million certs issued per day it is not likely a routine comms problem in or near Flexential. Also, IPv4 is more common than IPv6.

You got a cert from production so had to pass Flexential validation at least once. And, in fact twice because you have separate certs for your 2 domain names.

I suggested avoiding the redirect as we saw IPv4 reach you just fine - at least once. Reducing the traffic increases the odds of success. Agree that something seems wrong in a comms config somewhere but it more likely is nearer OVH than originating at Flexential center.

Do you have a good working relationship with OVH network support? Because they could check the logs at their network edges to see what traffic arrives destined for you. That would help isolate where in the path this is going wrong. We won't necessarily know the originating IP at Let's Encrypt (as they rotate frequently) but they know your destination IP's and could filter for that.

4 Likes