# Error creating new order on Acme Staging

**URL:** <https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418>\
**Category:** Help\
**Created:** [October 7, 2021, 7:47am UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418 "2021-10-07T07:47:55Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![kedar031](https://avatars.discourse-cdn.com/v4/letter/k/df788c/32.png) [@kedar031](https://community.letsencrypt.org/u/kedar031)\
**Post date:** [October 7, 2021, 7:47am UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/1 "2021-10-07T07:47:55Z")

</div>

Hi Team,

We are frequently facing this issue for almost two weeks(or more), which happens roughly 1/5 times.  
Has something changed?  
{  
"type":"urn:ietf:params:acme:error:serverInternal",  
"detail":"Error creating new order",  
"status":500  
}

Client: acme4j  
sample domain request failed: 98e4b25b2f3ba887.dim-s9m3.svbr-nqvp.int.cldr.work  
Any suggestions?

Essentially the POST request for the create order is failing with 500 response , below is the trace from Acme4j

```nohighlight
Exception from the ACME server while executing the order. Problem : Error creating new order Exception: {} org.shredzone.acme4j.exception.AcmeServerException: Error creating new order
	at org.shredzone.acme4j.connector.DefaultConnection.throwAcmeException(DefaultConnection.java:548)
	at org.shredzone.acme4j.connector.DefaultConnection.performRequest(DefaultConnection.java:479)
	at org.shredzone.acme4j.connector.DefaultConnection.sendSignedRequest(DefaultConnection.java:407)
	at org.shredzone.acme4j.connector.DefaultConnection.sendSignedRequest(DefaultConnection.java:161)
	at org.shredzone.acme4j.OrderBuilder.create(OrderBuilder.java:314)

```

Thank you,  
Kedarnath

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 7, 2021, 7:48am UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/2 "2021-10-07T07:48:57Z")

</div>

Is there anything else in the logs?

Sorry, now I see:

> [@kedar031](#):
>
> Client: acme4j

I'm totally unfamiliar with it.  
But do add anything else for others that might know more to see.

---

<div class="post-metadata">

**Author:** ![kedar031](https://avatars.discourse-cdn.com/v4/letter/k/df788c/32.png) [@kedar031](https://community.letsencrypt.org/u/kedar031)\
**Post date:** [October 7, 2021, 10:12am UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/3 "2021-10-07T10:12:19Z")

</div>

Thanks for the response. Updated more details, hope that helps.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 7, 2021, 3:12pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/4 "2021-10-07T15:12:54Z")

</div>

Since no one else has posted...  
Let's try solving this generically.  
Presuming the problem started recently and you haven't made any change to warrant this error...

- Which OS and version is this running?

- Which version of OpenSSL is being used?

- Have you updated `ca-certificates`?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 7, 2021, 3:44pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/5 "2021-10-07T15:44:33Z")

</div>

Internal server errors are not something the user can fix nor cause as far as I know. Maybe there's something going on with the servers, although currently I don't see an active incident.

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [October 7, 2021, 4:45pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/6 "2021-10-07T16:45:48Z")

</div>

The only thing the spec says for "serverInternal" is that it means "The server experienced an internal error". Generally retrying should work. Are these "complicated" certificates in any way, like having lots of domain names on them that would need validation? When you say it fails roughly 1/5 times, is that with the same certificate or domain list? How big of a sample size of failures are we talking about? Does retrying the same order usually work?

---

<div class="post-metadata">

**Author:** ![kedar031](https://avatars.discourse-cdn.com/v4/letter/k/df788c/32.png) [@kedar031](https://community.letsencrypt.org/u/kedar031)\
**Post date:** [October 7, 2021, 5:27pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/7 "2021-10-07T17:27:31Z")

</div>

There isn't anything special with the certificate/domains, I say this because some of them have passed on retries. There are at most 2 domains in the request.  
It fails for different certificates and domain lists, so this is not something specific to domain names I think.  
There were around 30 such failures yesterday.  
There is a sample domain I have mentioned in the description for which the issue happened, I can add more of those if that helps.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 7, 2021, 5:29pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/8 "2021-10-07T17:29:14Z")

</div>

@kedar031  
Is there a common timeframe when the errors occur?

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [October 7, 2021, 5:55pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/9 "2021-10-07T17:55:46Z")

</div>

So, you had roughly 30 failures and (extrapolating from you saying 1/5 of your requests fail) roughly 120 successful requests yesterday, all to the staging environment, all for certificates with just 1 or 2 domains? That does sound like something odd going on. While I hate to suggest any testing in production, do you make a similar level of requests to the production environment? If so, what portion of requests to production work? And you've been having roughly this level of requests per day for weeks, and notice something change a couple weeks ago? Can you narrow down more specifically when it started?

---

<div class="post-metadata">

**Author:** ![jillian](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jillian/32/11635_2.png) [@jillian](https://community.letsencrypt.org/u/jillian)\
**Post date:** [October 7, 2021, 7:33pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/10 "2021-10-07T19:33:25Z")

</div>

> [@kedar031](#):
>
> We are frequently facing this issue for almost two weeks(or more), which happens roughly 1/5 times.  
> Has something changed?

Yes, we are making changes to our staging environment that we hope will bring better quality of service and stability. However, the current change needs some fine tuning and is causing a little more impact on the new-order endpoint for some use cases. In general, we've noticed the endpoint has a better success rate but it's still not where we want it to be.

This is on our radar and we are working on it!

---

<div class="post-metadata">

**Author:** ![kedar031](https://avatars.discourse-cdn.com/v4/letter/k/df788c/32.png) [@kedar031](https://community.letsencrypt.org/u/kedar031)\
**Post date:** [October 11, 2021, 7:47am UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/11 "2021-10-11T07:47:01Z")

</div>

On production, this is significantly lesser requests and thankfully have not noticed this issue there. Unfortunately, I don't have older logs to pin down from when exactly started seeing this.

---

<div class="post-metadata">

**Author:** ![kedar031](https://avatars.discourse-cdn.com/v4/letter/k/df788c/32.png) [@kedar031](https://community.letsencrypt.org/u/kedar031)\
**Post date:** [October 11, 2021, 7:49am UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/12 "2021-10-11T07:49:46Z")

</div>

Thanks, @jillian. will be great if you can update the thread once that is done and I can check back on the same.

---

<div class="post-metadata">

**Author:** ![jillian](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jillian/32/11635_2.png) [@jillian](https://community.letsencrypt.org/u/jillian)\
**Post date:** [October 11, 2021, 4:45pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/13 "2021-10-11T16:45:48Z")

</div>

We made some changes at the end of last week that should remediate the problems you were seeing. We have seen improvements in our testing and metrics.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 10, 2021, 4:46pm UTC](https://community.letsencrypt.org/t/error-creating-new-order-on-acme-staging/162418/14 "2021-11-10T16:46:37Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
