Certbot errors with `Obtaining a new certificate An unexpected error occurred: The CSR is unacceptable (e.g., due to a short key) :: Error finalizing order :: issuing precertificate: CSR doesn't contain a SAN short enough to fit in CN`

My domain is: xn--auauaiaioaeeiauuouuoouuaieieaiuuaoa-o7c04dhamabgauej1vieciu.eu

I ran this command: certbot certonly --webroot -w /tmp/letsencrypt-auto/ --must-staple -d xn--auauaiaioaeeiauuouuoouuaieieaiuuaoa-o7c04dhamabgauej1vieciu.eu --staple-ocsp --rsa-key-size 4096

It produced this output:

Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator webroot, Installer None
Obtaining a new certificate
An unexpected error occurred:
The CSR is unacceptable (e.g., due to a short key) :: Error finalizing order :: issuing precertificate: CSR doesn't contain a SAN short enough to fit in CN
Please see the logfiles in /var/log/letsencrypt for more details.

The operating system my web server runs on is (include version): Ubuntu 18.04.3

The version of my client is: 0.31.0

Could anyone give me some pointers how I can acquire a certificate for this domain?

Hi @TaaviE

one label may have max. 63 characters, so that label is ok.

But there is an additional limit: The CN can have (if I know it correct) max. 64 characters. Yours has 66.

You may add a second, shorter domain with that domain as first domain name -> so it's used as CN.

Earlier, I've created a certificate with this-is-a-very-long-really-very-long-name-of-this-small-bdomain as subdomain name (63 characters + .server-daten.de). Worked with www.server-daten.de as second domain name and CN.

Ah - there is the old topic

3 Likes

Good to know. Would it be worth opening a GH issue about the error message not saying that?

1 Like

Yep, now it has worked. There is a new check

CN=naide.ee
	04.11.2019
	02.02.2020
expires in 90 days	
naide.ee, 
www.üöauauaiöüöaioüaeüeiauuoõuüuäoouuõöaieiöeaiuuaoüaõöõ.eu 
(www.xn--auauaiaioaeeiauuouuoouuaieieaiuuaoa-o7c04dhamabgauej1vieciu.eu), 

üöauauaiöüöaioüaeüeiauuoõuüuäoouuõöaieiöeaiuuaoüaõöõ.eu 
(xn--auauaiaioaeeiauuouuoouuaieieaiuuaoa-o7c04dhamabgauej1vieciu.eu) - 
3 entries

naide.ee as short CN, then two domains with that 63 character label.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.