# Certification failed when trying to get certificate

**URL:** <https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027>\
**Category:** Help\
**Created:** [July 3, 2025, 4:44pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027 "2025-07-03T16:44:40Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aarav](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarav/32/88079_2.png) [@Aarav](https://community.letsencrypt.org/u/Aarav)\
**Post date:** [July 3, 2025, 4:44pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/1 "2025-07-03T16:44:40Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [api.rajshriplastiwood.com](http://api.rajshriplastiwood.com)

I ran this command: `sudo certbot --nginx -d api.rajshriplastiwood.com`

It produced this output: \> Saving debug log to /var/log/letsencrypt/letsencrypt.log

> Requesting a certificate for [api.rajshriplastiwood.com](http://api.rajshriplastiwood.com)
> 
> Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:  
> Domain: [api.rajshriplastiwood.com](http://api.rajshriplastiwood.com)  
> Type: dns  
> Detail: DNS problem: query timed out looking up A for [api.rajshriplastiwood.com](http://api.rajshriplastiwood.com); DNS problem: query timed out looking up AAAA for [api.rajshriplastiwood.com](http://api.rajshriplastiwood.com)
> 
> Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
> 
> Some challenges have failed.  
> Ask for help or search for solutions at [https://community.letsencrypt.org](https://community.letsencrypt.org). See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

My web server is (include version): nginx/1.24.0 (Ubuntu)

The operating system my web server runs on is (include version): Ubuntu 24 LTS

My hosting provider, if applicable, is: Hostinger

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): 2.8.0

---

<div class="post-metadata">

**Author:** ![Aarav](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarav/32/88079_2.png) [@Aarav](https://community.letsencrypt.org/u/Aarav)\
**Post date:** [July 3, 2025, 4:51pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/2 "2025-07-03T16:51:37Z")

</div>

## some addition info

Lets encrypt logs: [https://termbin.com/5k3y](https://termbin.com/5k3y)  
output from `curl -i api.rajshriplastiwood.com/.well-known/acme-challenge/Test123`:

```nohighlight
HTTP/1.1 404 NOT FOUND
Server: nginx/1.24.0 (Ubuntu)
Date: Thu, 03 Jul 2025 16:50:39 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 207
Connection: keep-alive
Access-Control-Allow-Origin: *

<!doctype html>
<html lang=en>
<title>404 Not Found</title>
<h1>Not Found</h1>
<p>The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again.</p>

```

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 3, 2025, 4:52pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/3 "2025-07-03T16:52:46Z")

</div>

Welcome to the Let's Encrypt Community! 🙂

Google is seeing an A record... 🤔

```nohighlight
id 47342
opcode QUERY
rcode NOERROR
flags QR RD RA
;QUESTION
api.rajshriplastiwood.com. IN A
;ANSWER
api.rajshriplastiwood.com. 14392 IN A 31.97.61.130
;AUTHORITY
;ADDITIONAL

```

```nohighlight
id 22273
opcode QUERY
rcode NOERROR
flags QR RD RA
;QUESTION
api.rajshriplastiwood.com. IN AAAA
;ANSWER
;AUTHORITY
rajshriplastiwood.com. 1800 IN SOA ns1.phpcloudserver.com. asheeshrathore.pnpuniverse.com. 2025070116 3600 1800 1209600 86400
;ADDITIONAL

```

> **[Dig (DNS lookup)](https://toolbox.googleapps.com/apps/dig/#A/)**

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 3, 2025, 4:58pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/5 "2025-07-03T16:58:30Z")

</div>

The response from the nameservers is rather slow.

> **[Network Tools: DNS,IP,Email](https://mxtoolbox.com/SuperTool.aspx?action=dns%3aapi.rajshriplastiwood.com&run=toolpage)**
>
> DNS and Network troubleshooting and diagnostic tools integrated into one sweet interface.

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [July 3, 2025, 4:59pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/6 "2025-07-03T16:59:57Z")

</div>

> **[api.rajshriplastiwood.com | DNSViz](https://dnsviz.net/d/api.rajshriplastiwood.com/dnssec/)**

Looks like some of the DNS servers aren't working, and/or the delegation is wrong.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [July 3, 2025, 5:00pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/7 "2025-07-03T17:00:20Z")

</div>

I concur, @petercooperjr.

---

<div class="post-metadata">

**Author:** ![Aarav](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarav/32/88079_2.png) [@Aarav](https://community.letsencrypt.org/u/Aarav)\
**Post date:** [July 3, 2025, 5:07pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/8 "2025-07-03T17:07:07Z")

</div>

Sorry, I'm a bit new to this. What can/should I do?  
I've been waiting for 2 days for it to propagate.

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [July 3, 2025, 5:18pm UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/9 "2025-07-03T17:18:10Z")

</div>

There's nothing to "propagate", but you need your domain name to be working before you can get a certificate (or before anyone can access your web site).

The `.com` nameservers say that your DNS server is `ns1.phpcloudserver.com` & `ns2.phpcloudserver.com` which are both (!) at 192.177.75.10. But that IP isn't actually responding.

What you should do is configure your DNS servers with your registrar, and ensure that any glue records needed are correct. But we don't know what your correct configuration is supposed to be.

---

<div class="post-metadata">

**Author:** ![Aarav](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarav/32/88079_2.png) [@Aarav](https://community.letsencrypt.org/u/Aarav)\
**Post date:** [July 4, 2025, 1:53am UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/10 "2025-07-04T01:53:14Z")

</div>

The domain name correctly points to the API and is working in the browser.  
I'm using cPanel to manage my domain, I tried reading the record.

I tried checking on: [DNS Checker - DNS Check Propagation Tool](https://dnschecker.org/?camp_opt=exact_match#A/api.rajshriplastiwood.com)

A lot of them are invalid, I'm unsure why.

---

<div class="post-metadata">

**Author:** ![webprofusion](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/webprofusion/32/85310_2.png) [@webprofusion](https://community.letsencrypt.org/u/webprofusion)\
**Post date:** [July 4, 2025, 2:16am UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/11 "2025-07-04T02:16:07Z")

</div>

The problem seems to be that [ns1.phpcloudserver.com](http://ns1.phpcloudserver.com) etc are not responding to UDP queries like a normal DNS server would (but they are answering on TCP). You could raise this with them (assuming you are not the administrator) or you could move to a different DNS provider like cloudflare etc.

[edit, a yep, one of the "glue" records is a private IP]

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [July 4, 2025, 2:16am UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/12 "2025-07-04T02:16:34Z")

</div>

> [@Aarav](#):
>
> A lot of them are invalid, I'm unsure why.

Probably because of the wrong "glue" records as Peter noted earlier. From the DNSviz link he posted

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/c/d/cdb77530e34fe4c6641432aab130102315e7ad57.png)

For example, using the IP address for your ns1 name server works. But, using the IP in the glue record fails. This is the first thing you should fix

```nohighlight
# Using IP in glue record
dig +noall +answer A api.rajshriplastiwood.com @192.177.75.10
;; communications error to 192.177.75.10#53: timed out
;; communications error to 192.177.75.10#53: timed out
;; communications error to 192.177.75.10#53: timed out
;; no servers could be reached

# Using IP from DNS for ns1.phpcloudserver.com
dig +noall +answer A api.rajshriplastiwood.com @103.131.24.11
api.rajshriplastiwood.com. 14400 IN A 31.97.61.130

```

You can easily reproduce this DNS query problem using [https://unboundtest.com](https://unboundtest.com)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 3, 2025, 2:17am UTC](https://community.letsencrypt.org/t/certification-failed-when-trying-to-get-certificate/239027/13 "2025-08-03T02:17:03Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
