We prevalidated this domain with DNS checks, but when we try to retrieve the certificate, we get the answer back from LE that this domain is still “Awaiting”

dig -t TXT

;; ANSWER SECTION: 60 IN TXT “8CwyOU_Xk1rx_QhOuj6F5OxXeE4IE5sx9qZeq7Jl1Y8”

“Awaiting” doesn’t have any meaning in the ACME protocol. What ACME client are you using?

A DNS challenge might be “pending”, in which case the ACME client needs to tell the server to check the challenge.

Or the challenge might be “processing”, in which case the ACME client needs to wait for the server to finish checking the challenge, at which point it will transition to “valid” or “invalid”.

If you have ACME client logs, or an order URL we can look at, that would be useful to identify what is happening.

Hi @tiday

that’s not a typical error message from Letsencrypt. That’s an unknown message from your client.

What client do you use? Is there an update? ACME-v1 or v2?

PS: Your TXT entry looks good -

Is this URL you are requesting?

That’s the authorization URL. I was looking for the order URL (contains /acme/order/).

But, from the authorization URL, we can see that the domain validation did complete successfully (status “valid”). So there was nothing wrong with the validation process or your TXT record.

At this stage, your ACME client should finalize the order, which would result in the certificate being issued. If you can find the order URL, we can check what the status of that process is.

Thanks for your help. I forced our client to retry and this time it successfully retrieved the certificate.

