# Can you help me understand why I've been rate limited?

**URL:** <https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200>\
**Category:** Help\
**Created:** [June 25, 2018, 3:28pm UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200 "2018-06-25T15:28:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dfv](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dfv](https://community.letsencrypt.org/u/dfv)\
**Post date:** [June 25, 2018, 3:28pm UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/1 "2018-06-25T15:28:37Z")

</div>

```
My domain is: mon.svc.worten.net (worten.net)

I ran this command: certbot certonly -d mon.svc.worten.net --dns-route53 --agree-tos -m <email-address>

It produced this output: There were too many requests of a given type :: Error creating new cert :: too many certificates already issued for exact set of domains: mon.svc.worten.net: see https://letsencrypt.org/docs/rate-limits/

My web server is (include version): NA

The operating system my web server runs on is (include version): NA

My hosting provider, if applicable, is: NA

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): NA

```

I tried to create the certificate for the domain [mon.svc.worten.net](http://mon.svc.worten.net) more than once which might have explained the rate limit but, as far as I can see in crt.sh I didn’t reach any of them (lectl shows I should have been able to issue 17 more certificates).

Can someone help me understand what was the rate limit I reached and, more importantly, when could I issue a new certificate?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [June 25, 2018, 3:35pm UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/2 "2018-06-25T15:35:10Z")

</div>

> [@dfv](#):
>
> There were too many requests of a given type :: Error creating new cert :: too many certificates already issued for exact set of domains: [mon.svc.worten.net](http://mon.svc.worten.net): see [Rate Limits - Let's Encrypt](https://letsencrypt.org/docs/rate-limits/)

That's the **Duplicate Certificate** rate limit.

> **[Rate Limits - Let's Encrypt](https://letsencrypt.org/docs/rate-limits/)**
>
> Let’s Encrypt provides rate limits to ensure fair usage by as many people as possible. We believe these rate limits are high enough to work for most people by default. We’ve also designed them so renewing a certificate almost never hits a...

You've issued 5 identical certificates over the last few days.

[https://crt.sh/](https://crt.sh/) is running behind and only knows about 3 of them, but for example Google's CT search page shows all of them:

[https://transparencyreport.google.com/https/certificates?cert\_search\_auth=&cert\_search\_cert=&cert\_search=include\_expired:false;include\_subdomains:false;domain:mon.svc.worten.net&lu=cert\_search](https://transparencyreport.google.com/https/certificates?cert_search_auth=&cert_search_cert=&cert_search=include_expired:false;include_subdomains:false;domain:mon.svc.worten.net&lu=cert_search)

---

<div class="post-metadata">

**Author:** ![dfv](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dfv](https://community.letsencrypt.org/u/dfv)\
**Post date:** [June 25, 2018, 5:26pm UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/3 "2018-06-25T17:26:22Z")

</div>

Thank you @mnordhoff! I last created a certificate request a few days ago so I assumed that wasn’t the problem but it seems you’re right.

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [June 25, 2018, 5:45pm UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/4 "2018-06-25T17:45:15Z")

</div>

> [@mnordhoff](#):
>
> [https://crt.sh/](https://crt.sh/) is running behind and only knows about 3 of them

That is not good, usually, pre certificates appear on crt.sh db in a few minutes or a couple of hours after you issued them. Final certificates appear on crt.sh from a few hours till a few days but it isn't normal that after 3 days there are no pre certificates logged for last 2 issued certs covering `mon.svc.worten.net`. Maybe crt.sh is experiencing some technical issues 😏

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [June 25, 2018, 5:56pm UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/5 "2018-06-25T17:56:09Z")

</div>

> [@sahsanu](#):
>
> That is not good, usually, pre certificates appear on crt.sh db in a few minutes or a couple of hours after you issued them. Final certificates appear on crt.sh from a few hours till a few days but it isn’t normal that after 3 days there are no pre certificates logged for last 2 issued certs covering `mon.svc.worten.net` . Maybe crt.sh is experiencing some technical issues 😏

I don't know how crt.sh's architecture works, but it feels overloaded. Some searches I did were timing out. (Seems to have gotten better since.)

The monitoring page usually shows a little bit of "backlog" on the busiest logs, but now it's millions of certs:

[https://crt.sh/monitored-logs](https://crt.sh/monitored-logs)

If you search Let's Encrypt, the latest precertificates are from the 22nd:

[https://crt.sh/?Identity=%25&iCAID=16418](https://crt.sh/?Identity=%25&iCAID=16418)

(There are a few newer leaf certificates that people must have manually submitted to less popular -- and therefore more quickly processed -- logs.)

But it's processed like half an hour worth of Mammoth precertificates while I've been writing this post, so maybe it's getting better.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [June 26, 2018, 5:22am UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/6 "2018-06-26T05:22:55Z")

</div>

I’m not convinced the crt.sh backlog is actually going down over time. I’ve noticed that it really got slower this year. Hopefully the ingestion can be made faster and it’s not a problem with database load.

 ![Screenshot_2018-06-26_15-20-50](https://global.discourse-cdn.com/letsencrypt/original/3X/2/e/2e6851a88d6e04193b1c9409c30ac7a60e50f7f9.png)

There are alternatives at Google, Censys and SSLMate, but none are both free and API-able like crt.sh ☹ . I’d love to maintain a database myself but the storage requirements for even 90 days of certificates are too expensive to fund personally.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 26, 2018, 5:22am UTC](https://community.letsencrypt.org/t/can-you-help-me-understand-why-ive-been-rate-limited/65200/7 "2018-07-26T05:22:59Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
