I have 8 certificates, 50 hostnames. I run my own DNS server (and have for the last 30+ years).
I don't have the option of running acme on my web-server. So I use the DNS challenge. I've been doing using Let's Encrypt for the last couple of years, and I am incredibly grateful for the Let's Encrypt service.
But wholly flapp… why should it take hours and hours, of renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing, renewing, editing, reloading, checking, failing?
I just need the last of 50 hosts validated. I've got 49 of 50 validated. Why is this so hard? Why does this happen every time? I have to go through the same hours long process of doing everything right and still failing. I am doing everything correctly. I've been at this for the last 4.75 hours.
Come on guys. This is so frustrating.
Why do I get punished for your servers having problems?
Renew, edit zone, reload server, verify acme-challenge TXT record, renew, FAIL, RINSE, REPEAT!
WOOHOO! FINALLY GOT THE LAST HOST VERIFIED 5 HOURS LATER!
Come on. There has to be a better way.