We are experiencing a strange issue where, when including the accountURI within our CAA record, AutoSSL via cPanel, with Let's Encrypt as the provider, fails to issue certificates, citing that it is forbidden via the CAA. We have confirmed that the listed Provider ID in cPanel matches the accountURI listed in the CAA record itself. We have rebooted the server, as well as waited 24+ hours in the event any old DNS records have been cached on Let's Encrypt's end, but we are still experiencing the same issue.
https://unboundtest.com/m/CAA/spicertransmission.com/GYXHYUXC
Current Provider: Let’s Encrypt™
Provider Account ID: https://acme-v02.api.letsencrypt.org/acme/acct/2355938557
We have reached out to our server provider, but they seem stumped, and are recommending simply removing the accountURI from the CAA record. This seems to work properly based on our initial testing with an alternate domain, but our IT team would like to require the accountURI for security hardening purposes, so we are hoping to find a solution here that will allow us to continue to include it while also using Let's Encrypt for SSL certificates.
Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: spicertransmission.com
I ran this command: AutoSSL via cPanel
It produced this output: DNS CAA records forbid "Let's Encrypt" from issuing certificates
My web server is (include version):
The operating system my web server runs on is (include version): AlmaLinux v8.10.0 STANDARD virtuozzo
My hosting provider, if applicable, is: KnownHost
I can login to a root shell on my machine (yes or no, or I don't know): Yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): Yes, cPanel 126.0.14
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):
