Error creating new order :: too many certificates (5)

hi all,
I'm italian and sorry for my english.
I request a ssl but i have this error
An unexpected error occurred:
There were too many requests of a given type :: Error creating new order :: too many certificates (5) already issued for this exact set of domains in the last 168 hours: priceguardian.it,www.priceguardian.it, retry after 2023-09-06T19:42:24Z: see Duplicate Certificate Limit - Let's Encrypt
i didn't know the existence of a staging endpoint and so i created too many certificates for the same domain,the error indicates a date from which i can request a new certificate.The date has been passed but i still have the same error.Someone can help me?thanks

The date is UTC (notice the "Z"), so there's 28 more minutes to go.

Also, can't you just use one of the previous 5 certificates?

1 Like

I think you must wait much longer than 28 minutes. You got 5 certs with those 2 names yesterday. You have 6 more days to wait.

Glad you found Staging system now and discovered the work-around for changing the set of domain names.

3 Likes

Hm, I doubt the error message from the LE ACME API is incorrect, maybe old?

The message is odd. It lists both domain names with a time of 19:42 Z.

But, I don't see any cert history for 19:42 (or 18:42) as NotBefore for any domain name (root or root/www). There was a cert issued today at 18:24 UTC just for the root domain but that's the closest time match I see (link below).

I don't know how they'll get a 6th cert for both names for at least another 6 days or so.

Today's cert
https://crt.sh/?id=10312975327

Sorry for all the edits. Weird formatting stuff happening only some of my fault :slight_smile:

3 Likes

Thanks all for the support.
I have request with success with more time new certificate for both domain and subdomain because the last inhave forgot.

2 Likes

How i can access this data?

Usually https://crt.sh is a good way to view certs. But, it is having problems with some of its logs which happens to affect your domain.

The pic I showed above uses censys.io which requires an account with them.

There are various other CT log search tools. I don't often use them but one example is

https://ui.ctsearch.entrust.com/ui/ctsearchui

3 Likes

Excellent. I see your server using a new cert for both names and it was created just after the time in the error message. I guess I should have trusted the message.

I still do not understand why you were allowed that 6th cert. Maybe someone else can explain.

3 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.