Not having CAA records is fine. But when Let’s Encrypt asks your DNS servers instead of saying “no, I don’t have any records like that” they report an error. In this circumstance there’s no way for Let’s Encrypt to be sure if you have any CAA records they need to examine so they can’t proceed.
Reporting SERVFAIL instead of 0 records found is a common bug in DNS software, your supplier can and should rectify this bug even if they’ve no interest in some feature like CAA. This has happened before and I must say it’s very disappointing that people charge actual money for DNS services that can’t get such a basic thing right.
@jared.m you are right
the TXT record I added is _acme-challenge.orthohandboek.alearn.nl dnssectest.net doesnt show any errors as far as i can see but far from an expert.
Definitely something wrong with that zone’s DNSSEC. More specifically negative responses. It smells like the PowerDNS bug mentioned at the link above – or possibly something different but similar – but i don’t know enough to be sure.
You can ask the Your hosting.nl tech guys to please upgrade their DNS servers to a version with this bug fixed. It is not vital that they know anything about CAA. If you aren’t sure how to explain to them you could direct them to this discussion thread, assuming they are happy reading English (I am not sure if we have contributors watching the thread who are confident in Dutch).
can anyone explain why querying the authoritative nameservers themselves give a NOERROR but querying through other nameservers gives a SERVFAIL?
If i tell those guys there is something wrong with their dnssec setup they might will say it isn’t and show me a dig to their own nameservers to substantiate it… (it would return NOERROR.) correct?
dig isn't a DNS resolver. It... doesn't work like that. There are any number of issues that it wouldn't be aware of (e.g. incorrect DS record) or that it will display (e.g. AA bit not set). dig does a DNS query and shows the response if there is one and it's reasonably close to valid. A recursive DNS server iteratively resolves a name and sends a valid response, containing either correct data or a SERVFAIL error. They're not comparable.
ok,
so in that case, what would give me the result that i can show to the guys at yourhosting to demonstrate the problem at hand?
i mean, if they are not aware of the problem and i can not show them evidence of the problem then i would look a bit stupid and probably say the problem is with the letsencrypt verification process.
iow, how can i get a decent problem report of what seems to be going wrong.
i already showed them the error report from certbot but that actually only says:
Failed authorization procedure. orthohandboek.alearn.nl (dns-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: DNS problem: SERVFAIL looking up CAA for orthohandboek.alearn.nl
and their response was like we have no idea what you are talking about.
to me it seems strange to show the output of of another nameserver to demonstrate the problem that is caused by their own nameserver set up but i guess my knowledge falls short here to see the relevance.
anyway, ill give it a try.
don’t get me wrong, really appreciate you trying to help out here.
its just that i’m also trying my to wrap my head around what is actually happening on the technical level of things.
I sent them an email explaining exactly what was the problem two days ago and they dont even bother to respond.
The problem with yourhosting is that they are a provider for just home and small business and have a business model just milking out domain registrations and cheap websites.
Therefor we have decided we will make a plan to move our business to a professional party.
problem solved.
In the mean time got a cert from somewhere else but i noticed something funny,
if i do a dig to the subdomain i get SERVFAIL but i i query the main domain itself i get NOERROR
I have the same problem with Yourhosting but only for new records.
All my old records give a NOERROR, but when I create a new record I get a SERVFAIL,.
I worked around it by reusing a old testing record and changed the ip.