Hi,
i’m having issues creating a certificate for an azure virtual machine using the Win-Acme-client (wacs). I’m using wacs in unattended mode and this worked for different vms (with different hostnames) till this morning.
Now our certificates are not renewing or not able to create a new one. We are getting CAA record for xyz.australiaeast.cloudapp.azure.com prevents issuance
Thank you for your response.
This seems strange, the same certificate creation process worked yesterday.
Just for my unterstanding: This is something i can’t do anything about, because Microsoft set these CAA records for azure.com?
I think it isn’t possible for me to set CAA entries for the complete domain name.
The same with *.westeurope.cloudapp.azure.com. Our one AKS cluster is working using certificate issued by Let`s Encrypt 3 days ago. But another one, created few hours ago, can’t get one. Didn’t find any announcement from Microsoft about coming changes…
I have posted a question to MS about this today, lets see if we can get anything out of them, this has come at a really bad time for us we really need this to be working for our deployments. MS Link