i do have an automatic scripts that ask for let’s encrypt certs.
I already use it hundred and hundreds of time without any trouble.
for only one domain (and only this one) i do have a challenge error. DNS is ok and all let’s encryts request are directed to the right directory as usual.
so only for this domain it is not working without any obvious reasons:
Domain: www.berry-savoie.com
Type: unauthorized
Detail: The key authorization file from the server did not match
this challenge
[JEu7WAw6WUIpMJWGUv3Xub5KIVvd3S0Z6rCpVxS_9iM.ADb-m5uCjdUb8UAInHnMxEScZIOWeofJPoJ3XQxzVqc]
!=
[JEu7WAw6WUIpMJWGUv3Xub5KIVvd3S0Z6rCpVxS_9iM.4E3VCTFsySjUrqnCg0ooULx-3kbdPBygi0aWkvg5Gd8]
Domain: berry-savoie.com
Type: unauthorized
Detail: The key authorization file from the server did not match
this challenge
[QLToxtPwBFgw3AA2mY35ACRwE2u2eR34M890Fbg9mTk.ADb-m5uCjdUb8UAInHnMxEScZIOWeofJPoJ3XQxzVqc]
!=
[QLToxtPwBFgw3AA2mY35ACRwE2u2eR34M890Fbg9mTk.4E3VCTFsySjUrqnCg0ooULx-3kbdPBygi0aWkvg5Gd8]
Let’s Encrypt prefers IPv6 over IPv4 and your domain is advertising an AAAA record so Let’s Encrypt is trying to validate it using the IPv6 address but you are not serving the same content for IPv4 and IPv6.