Hi Folks,
This is a new one for me, a user of Certify The Web is repeatedly having trouble renewing their certs and the HTTP validation either times out waiting for LE to complete domain validation or it fails to finalize with Unable to meet CA SCT embedding requirement
.
To my knowledge this is perhaps something to do with LE not being able to submit the cert to CT logs and it appears to only affect this one user. Failing to submit to CT logs wouldn't explain why http validation takes a long time to complete but assuming it eventually passes then presumably the two issues are not connected?
2025-05-28 15:18:42.514 -07:00 [INF] ---- Beginning Request [neilssilkscreen.com] ----
2025-05-28 15:18:42.514 -07:00 [INF] Certify/6.1.5.0 (Windows; Microsoft Windows NT 10.0.17763.0)
2025-05-28 15:18:42.514 -07:00 [INF] Beginning certificate request process: neilssilkscreen.com using ACME provider Anvil
2025-05-28 15:18:42.514 -07:00 [INF] The selected Certificate Authority is: Let's Encrypt
2025-05-28 15:18:42.514 -07:00 [INF] Requested identifiers to include on certificate: neilssilkscreen.com;www.neilssilkscreen.com
2025-05-28 15:18:43.947 -07:00 [INF] Created ACME Order: https://acme-v02.api.letsencrypt.org/acme/order/263893630/388709530197
2025-05-28 15:18:44.535 -07:00 [INF] Order is ready and valid. Auth challenges will not be re-attempted.
2025-05-28 15:18:44.536 -07:00 [INF] [Progress] Order authorizations already completed.
2025-05-28 15:18:44.536 -07:00 [INF] Resuming certificate request using CA: Let's Encrypt
2025-05-28 15:18:44.536 -07:00 [INF] [Progress] Requesting certificate via Certificate Authority
2025-05-28 15:19:20.419 -07:00 [ERR] Failed to finalize certificate order: Error finalizing order :: Unable to meet CA SCT embedding requirements
2025-05-28 15:19:20.419 -07:00 [ERR] The certificate order failed to complete. Failed to finalize certificate order: Error finalizing order :: Unable to meet CA SCT embedding requirements
Does anyone have any suggestions?