Hello,
We run several hundred domains with top level domains from all over the world with LetsEncrypt certificates on a server located in the US. It looks like for some time now, only Chinese certificates are not renewed any more. I get an error message for several domains now, like this:
Invalid response from https://acme-v02.api.letsencrypt.org/acme/authz-v3/348101101807.
Details:
Type: urn:ietf:params:acme:error:dns
Status: 400
Detail: During secondary validation: DNS problem: query timed out looking up A for mydomain.cn; no valid AAAA records found for mydomain.cn
This is very interesting, as our DNS settings didn't change. When I use other external tools like MXToolbox, the A record is found without problems. I also asked at our DNS provider, they are not aware of any issues. And no, we don't have any geoblocking enabled anywhere, like suggested in another post for the new remote perspectives.
Can anyone help?
Thanks in advance
Udo
My domain is: eucerin.cn (and others)
I ran this command: Automatic SSL renewal via Plesk Control Panel
It produced this output: see above
My web server is (include version): Apache 2.4.52 + nginx 1.24.0 managed by Plesk
The operating system my web server runs on is (include version): Ubuntu 22.04
My hosting provider, if applicable, is: Azure
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): Plesk
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): Unclear, managed via Plesk