Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: hp-web-dev01.transer.com
the domain transer.com point to another IP
i do setup route53 with my domain a text record follow the key that the command generate
I ran this command: certbot-auto certonly --manual --preferred-challenges dns -d *.hp-web-dev01.transer.com
here is the exact error in the log file:
2020-05-22 18:09:13,078:DEBUG:acme.client:Storing nonce: 0102r021rbeESg4xD-f7QNUysfX7wMcqBNzfolSgWZx8_14
2020-05-22 18:09:13,079:INFO:certbot._internal.auth_handler:Performing the following challenges:
2020-05-22 18:09:13,079:CRITICAL:certbot._internal.auth_handler:Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA. You may need to use an authenticator plugin that can do challenges over DNS.
2020-05-22 18:09:13,079:DEBUG:certbot._internal.log:Exiting abnormally:
…
when i ran the command i got a new value of txt entry so i apply it to my route53, at the first time i thought it was not updated yet but i tried the second time while waiting for 10mins more and check in the website https://check-your-website.server-daten.de, but still fail
did i miss something here?
ty sir for reply
transer.com. 900 IN NS ns03.idc.jp.
transer.com. 900 IN NS ns02.idc.jp.
transer.com. 900 IN NS dns2.crosslanguage.co.jp.
You need to set up the validation DNS records at the DNS service that queries from the Internet go to.
Changing the subject, it’s recommended to use Let’s Encrypt with automated renewal, which you can’t do when you’re using manual validation.
Do you really need a wildcard? If you don’t, it might be easier to use HTTP validation.
If you really do need to a wildcard, it would be best if you can set up automated DNS validation. (Route 53 supports it, but the Route 53 plugin for Certbot is not available on all OSes.)
hi sir @mnordhoff
the domain transer.com point to diffirent IP with the domain i’m trying to encrypt now is hp-web-dev01.transer.com and use route53 for this, but im plan to do the transer.com domain later.
And yes, i really need to a wildcard, im using Centos 6 now.