# Certbot rfc2136 error

**URL:** <https://community.letsencrypt.org/t/certbot-rfc2136-error/201848>\
**Category:** Help\
**Created:** [July 14, 2023, 6:56pm UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848 "2023-07-14T18:56:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lexanic](https://avatars.discourse-cdn.com/v4/letter/l/85e7bf/32.png) [@lexanic](https://community.letsencrypt.org/u/lexanic)\
**Post date:** [July 14, 2023, 6:56pm UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/1 "2023-07-14T18:56:28Z")

</div>

domain:  
norvester . ru

run:  
certbot certonly --dns-rfc2136 --dns-rfc2136-credentials /usr/local/etc/letsencrypt/ns.norvester.ru-rfc2136.ini -d "[norvester.ru](http://norvester.ru)" -d "\*.norvester.ru"

Certbot failed to authenticate some domains (authenticator: dns-rfc2136). The Certificate Authority reported these problems:  
Domain: [norvester.ru](http://norvester.ru)  
Type: dns  
Detail: DNS problem: looking up TXT for \_acme-challenge.norvester.ru: DNSSEC: RRSIGs Missing

Domain: [norvester.ru](http://norvester.ru)  
Type: dns  
Detail: DNS problem: looking up TXT for \_acme-challenge.norvester.ru: DNSSEC: RRSIGs Missing

Hint: The Certificate Authority failed to verify the DNS TXT records created by --dns-rfc2136. Ensure the above domains are hosted by this DNS provider, or try increasing --dns-rfc2136-propagation-seconds (currently 60 seconds).

OS FreeBSD 12  
Bind 9.18+DNSSEC  
key "keyname." {  
algorithm hmac-sha512;  
secret ......;  
};

key "rndc-key" {  
algorithm hmac-sha256;  
secret "....";  
};

controls {  
inet 127.0.0.1 port 953  
allow { 127.0.0.1; } keys { "rndc-key"; };  
};

acl certbot-keys { key keyname.; };

dnssec-policy "mypolicy" {  
keys {  
ksk lifetime unlimited algorithm ECDSAP256SHA256;  
zsk lifetime unlimited algorithm ECDSAP256SHA256;  
};  
};  
view "external" {

match-clients { certbot-keys; !internal; any; };  
allow-recursion { localhost; };

zone "[norvester.ru](http://norvester.ru)" {  
type master;  
file "/usr/local/etc/namedb/master/norvester.ru";  
allow-transfer { };  
allow-query { any; };  
inline-signing yes;  
dnssec-policy mypolicy;  
update-policy {  
grant keyname. name \_acme-challenge.norvester.ru. txt;  
};  
};

Help me

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 14, 2023, 8:11pm UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/2 "2023-07-14T20:11:10Z")

</div>

> [@lexanic](#):
>
> Help me

Say "please" first?

> [@lexanic](#):
>
> DNSSEC: RRSIGs Missing

This part of the error message is pretty clear: your DNSSEC is messed up.

That said, I have very little knowledge of BIND (although I run it myself on my server..), so I wouldn't know where to start to debug it. Maybe it has something to do with "dynamic DNSSEC updates" or something like that? As the TXT RR is added "dynamically", BIND needs to be able to update/add the DNSSEC stuff for these dynamic RRs too.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [July 14, 2023, 8:44pm UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/3 "2023-07-14T20:44:36Z")

</div>

Hi @lexanic, and welcome to the LE community forum 🙂

> [@lexanic](#):
>
> DNSSEC: RRSIGs Missing

If you can't fix that yourself, you should find someone who can [your DSP].  
[we can't]

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [July 14, 2023, 11:06pm UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/4 "2023-07-14T23:06:37Z")

</div>

Well, if they're running Bind then they're probably their own DNS provider.

And it seems reasonable to ask here if anyone has experience setting up the Certbot RFC2136 plugin to connect to Bind and configure Bind to properly sign the responses. Someone just might.

But it's not me.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [July 15, 2023, 2:24am UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/5 "2023-07-15T02:24:31Z")

</div>

@lexanic There might be a more officially correct solution to this, but you could consider making a CNAME record for `_acme-challenge` within your DNS zone. (The CNAME record could be signed with DNSSEC.) It could then point to a different DNS zone which is not, itself, DNSSEC-signed. Then you could use the `--dns-rfc2136` method to update that (unsigned) zone. In that case, Let's Encrypt would not need to validate DNSSEC signatures on the target zone.

This is just a theoretical workaround from my point of view, as I've never used this exact setup.

It's also possible that the "officially correct" solution would require updating the code of the `--dns-rfc2136` implementation to add some more functionality to it. I think this is very likely to be the case, but I'm not certain.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [July 15, 2023, 8:10am UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/6 "2023-07-15T08:10:28Z")

</div>

> [@schoen](#):
>
> It's also possible that the "officially correct" solution would require updating the code of the `--dns-rfc2136` implementation to add some more functionality to it. I think this is very likely to be the case, but I'm not certain.

It's perfectly possible to use the `dns-rfc2136` plugin _with_ DNSSEC, I run it myself. But as I said earlier, it requires dynamic DNSSEC updates from BINDs part, which, I believe, needs special configuration. I can look into that later today on my own BIND configuration, but configuring BIND is, well, not the easiest thing to do, so my own config might not actually help OP.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 14, 2023, 8:10am UTC](https://community.letsencrypt.org/t/certbot-rfc2136-error/201848/7 "2023-08-14T08:10:39Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
