It produced this output: During secondary validation: No valid IP addresses found for www.sojer-last.com.futurecms.at
and/or During secondary validation: DNS problem: query timed out looking up CAA for futurecms.at
My web server is: Server version: Apache/2.4.46 (IUS)
The operating system my web server runs on is: CentOS Linux release 7.9.2009 (Core)
My hosting provider, if applicable, is: Futureweb OG (www.futureweb.at)
I can login to a root shell on my machine: yes
I'm using a control panel to manage my site: sort of, custom backend für LE Cert generation
In the past weeks the lets encrypt error messages increased. If i try to renew the cert afterwards, it's working as expected. Seems like a timeout problem. There is always an ip address available, so the "no ip address found" error can't be correct. Do you have any current problems regarding the error messages written above?
I don't know what the problem is exactly.
And it seems to be only intermittent - or is this problem consistent?
And I do have another question: Do you have the same problem with the shorter name?
What confuses me a little is this - Error: "During secondary validation: No valid IP addresses found for www.sojer-last.com.futurecms.at"
However, in the same request:
Could it be possible some of the LE Systems which are used for the second Validation got Problems reaching European Networks? Routing Probs? Something in this Direction?
Hey @MrNovo,
as we are the ISP I would rule out this possibility with a 95% chance ...
Already roamed through DNS & Firewall Logs, also checked our Monitoring. No anomalies found on our Systems. Also 1 of our 3 DNS Servers is hosted outside of our Infrastructure to be sure DNS Resolution still works if there are Problems in our DC. (Hosted on MS Azure Cloud)
Also using this Setup for LE Certs many years now - and we noticed an increase of those Failure over the last few months ... so my guess would either be it's routing related or some kind of sporadically occuring performance issue on LE Servers and they only stand out because we protect thousands of domains with LE ... ?
Happens about 2-10 times a day - with a few dozen/hundreds Cert renewals a Day
It's always working without problems a few Seconds later ...
Hence my assumption that the problem could be on the LE side. Maybe @cpu got a spare second or two and have a look LE Server-Side / Logs if there is a Problem?
I checked DNS and Firewall Logs again - no blocking on our Side. Tested a few dozen CAA Queries of such Domains from outside of our Network.
Shortening CAA checks with CAA entries further down the path sounds like good idea - I'm going to implement that for our automated generated CMS Domains.
But maybe we should/could figure out what's the underlying problem is. Just to be sure LE Servers got no issue with such long sub-sub-sub-Domains? It happens pure randomly - out of the few dozen renews a day we get a few fails ... if I renew the same Domain a few Seconds/Minutes later - it works - so I would rule out some blocking on our side more or less ...
@schoen - we implemented CAA Records further down the Path (ie. at.kunden.ortsinfo.at instead of ortsinfo.at) as @JuergenAuer suggested ( ), since then no more Errors were triggered.
But the Question remains if the Error was caused by some bottleneck on LE Side or something with our DNS Servers. (While I wasn't able to find a single Error/Problem with our DNS Servers nor any blockings in our Firewall), also was not able to reproduce any Error with Unboundtest ...
Error was only triggered by "second validation" ...