Dns-01 urn:ietf:params:acme:error:unauthorized 403

Found the following certs:
Certificate Name: dev-acme.revmed.com
Serial Number: 3c4aa53c7c39db6f
Key Type: RSA
Domains: dev-acme.revmed.com
Expiry Date: 2024-04-13 02:03:14+00:00 (VALID: 365 days)
Certificate Path: /etc/letsencrypt/live/dev-acme.revmed.com/fullchain.pem
Private Key Path: /etc/letsencrypt/live/dev-acme.revmed.com/privkey.pem

I think I know what I did wrong. I set the --server to point to godaddy's CA which then found and pulled the test certificate. I need to leave it set to https://acme-v02.api.letsencrypt.org/directory

1 Like

That would do it. I didn't realize GoDaddy supported ACME. Is that new? I found this page (link here) and it requires the EAB config for registration. So, you must have done that too.

You could check your renewal conf file in
/etc/letsencrypt/renewal/dev-acme.revmed.com.conf

It should indicate the ACME server and related config values. Each successful issuance of a cert will update the renewal conf file with the latest values.

4 Likes

Your clock is waaaaay behind the correct time.

2 Likes

Actually no. It's a cert from GoDaddy CA

4 Likes

Thank you all for your help! This was quite the learning experience. I believe I am all set now.

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.