Hello,
my LE renewal fails despite nothing changed on my side since last successful renewal 2 months ago.
Tests on https://unboundtest.com and https://letsdebug.net showing all ok.
pi@pihole:[~] $ certbot --version
certbot 2.11.0
pi@pihole:[~] $ # sudo certbot renew -v --dry-run
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Processing /etc/letsencrypt/renewal/miharu.dedyn.io.conf
Certificate not due for renewal, but simulating renewal for dry run
Plugins selected: Authenticator dns-desec, Installer None
Simulating renewal of an existing certificate for *.miharu.dedyn.io and miharu.dedyn.io
Reusing existing private key from /etc/letsencrypt/live/miharu.dedyn.io/privkey.pem.
Performing the following challenges:
dns-01 challenge for miharu.dedyn.io
dns-01 challenge for miharu.dedyn.io
Waiting 80 seconds for DNS changes to propagate
Waiting for verification...
Challenge failed for domain miharu.dedyn.io
dns-01 challenge for miharu.dedyn.io
Certbot failed to authenticate some domains (authenticator: dns-desec). The Certificate Authority reported these problems:
Domain: miharu.dedyn.io
Type: caa
Detail: CAA record for miharu.dedyn.io prevents issuance
Hint: The Certificate Authority failed to verify the DNS TXT records created by --dns-desec. Ensure the above domains are hosted by this DNS provider, or try increasing --dns-desec-propagation-seconds (currently 80 seconds).
Cleaning up challenges
Failed to renew certificate miharu.dedyn.io with error: Some challenges have failed.
All simulated renewals failed. The following certificates could not be renewed:
/etc/letsencrypt/live/miharu.dedyn.io/fullchain.pem (failure)
1 renew failure(s), 0 parse failure(s)
CAA is set to
even by setting from 128 to 0 it is not working