# Error issuing certificate when domain and hosting for this domain are from different companies

**URL:** <https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862>\
**Category:** Help\
**Created:** [September 21, 2022, 6:08pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862 "2022-09-21T18:08:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![indubhushan](https://avatars.discourse-cdn.com/v4/letter/i/d78d45/32.png) [@indubhushan](https://community.letsencrypt.org/u/indubhushan)\
**Post date:** [September 21, 2022, 6:08pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/1 "2022-09-21T18:08:46Z")

</div>

Hello, I've bought a domain  
yourhappiness.in.ua  
from company redo.ua,  
and changed IP address there (in DNS settings of domain)  
to redirect to my hosting (other company - ukrline).

Then i went to my hosting panel (Plesk) in UkrLine hosting,  
added there a domain "yourhappiness.in.ua", ok,  
and wanted to add free certificate from letsencrypt  
(I turned on an option "wildcards"for domain like \*.yourhappiness.in.ua.  
Then I was asked to add TXT record in DNS settings for domain.  
I went in Peask to DNS settings of yourhappiness.in.ua,  
Enabled there management of those all records etc,  
and clicked to Add record.  
There I chose "TXT"record,  
added a subdomain  
\_acme-challenge.yourhappiness.in.ua  
Record type: **TXT**  
Domain name: **\_acme-challenge**.yourhappiness.in.ua  
Record: **sE7-zAjS34qw\_zyoVTyvLX7p6fQnpmZqtwnV2OYvxi0**  
or like this (it changes everytime I try).  
So, then when I click "reload" after adding the TXT-record for \_acme-challenge

- I have the same error each time I try:  
=======  
Could not issue an SSL/TLS certificate for **yourhappiness.in.ua**  
Details  
Could not issue a Let's Encrypt SSL/TLS certificate for **yourhappiness.in.ua**. Authorization for the domain failed.  
Details  
Invalid response from [https://acme-v02.api.letsencrypt.org/acme/authz-v3/156004548057](https://acme-v02.api.letsencrypt.org/acme/authz-v3/156004548057).  
Details:  
Type: urn:ietf:params:acme:error:dns  
Status: 400  
Detail: DNS problem: NXDOMAIN looking up TXT for \_acme-challenge.yourhappiness.in.ua - check that a DNS record exists for this domain  
=====

my suspicion is that it happens so, because I have domain bought from other company,  
while hosting is different. So these two companies maybe contradict,  
and so maybe I need some extra settings, but I don't know which.  
Even my support in hosting said that they don't know how to solve certificate problem  
(I tried it for few other domains similarly - they can't help).

If I add certificate for my other main domain in hosting company - it works,  
and also for subdomains - I do same way as I described above,  
but it dont work for some external domain (other than hosting).  
So if domain and hosting for this domain are from different companies,  
can I install your free certificate? If yes, what should I do?

## Below is some extra info in form:

My domain is:  
yourhappiness.in.ua

I ran this command:  
"Reload" after adding TXT record for free letsencrypt-certificate

It produced this output:  
Could not issue an SSL/TLS certificate for **yourhappiness.in.ua**  
Details  
Could not issue a Let's Encrypt SSL/TLS certificate for **yourhappiness.in.ua**. Authorization for the domain failed.  
Details  
Invalid response from [https://acme-v02.api.letsencrypt.org/acme/authz-v3/156004548057](https://acme-v02.api.letsencrypt.org/acme/authz-v3/156004548057).  
Details:  
Type: urn:ietf:params:acme:error:dns  
Status: 400  
Detail: DNS problem: NXDOMAIN looking up TXT for \_acme-challenge.yourhappiness.in.ua - check that a DNS record exists for this domain

My web server is (include version):  
[asp.net](http://asp.net), hosting company is ukrline.com.ua

The operating system my web server runs on is (include version):  
I don't know

My hosting provider, if applicable, is:  
ukrline.com.ua

I can login to a root shell on my machine (yes or no, or I don't know):  
I think no, plesk seems to have no cmd line

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):  
Plesk, i don't know the version and where to see it

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):  
I don't know to check it and run this command, it is probably disabled for me by my hosting company Ukrline

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 21, 2022, 6:21pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/2 "2022-09-21T18:21:20Z")

</div>

> [@indubhushan](#):
>
> (I turned on an option "wildcards"for domain like \*.yourhappiness.in.ua.

Do you _require_ a wildcard certificate? If not, please try again but without turning on the wildcard option. Changes are, your hosting environment can get a certificate using the `http-01` challenge automatically, but this would not be possible for getting a wildcard certificate.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 21, 2022, 7:15pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/5 "2022-09-21T19:15:45Z")

</div>

```nohighlight
nslookup -q=txt _acme-challenge.yourhappiness.in.ua
*** dns.google can't find _acme-challenge.yourhappiness.in.ua: Non-existent domain

nslookup -q=txt _acme-challenge.yourhappiness.in.ua.yourhappiness.in.ua
_acme-challenge.yourhappiness.in.ua.yourhappiness.in.ua text =
        "o8gyM-TbUzg8jNsYMkIc7WqhGmDvoBDz7_25yuSEVvs"

```

When you create the TXT record entry, use "`_acme-challenge`" not with the domain added.

---

<div class="post-metadata">

**Author:** ![indubhushan](https://avatars.discourse-cdn.com/v4/letter/i/d78d45/32.png) [@indubhushan](https://community.letsencrypt.org/u/indubhushan)\
**Post date:** [September 21, 2022, 7:27pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/6 "2022-09-21T19:27:09Z")

</div>

i think I don't really require wildcards (\*), so yes, I unchecked it, and now it works, thank you.

as for not adding after "\_acme-challenge" a domain name - it is automatically added, i cannot change it. it is not editable in plesk. but anyway, Osiris already helped and now it all seems to work. thank you for free certificates! and may God bless you all with everything

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 21, 2022, 7:42pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/7 "2022-09-21T19:42:16Z")

</div>

> [@indubhushan](#):
>
> i think I don't really require wildcards (\*), so yes, I unchecked it, and now it works, thank you.

You might want to consider configuring a HTTP to HTTPS redirect. That said, I'm not familiar with Plesk, so no idea how one would do that using Plesk 🙄

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 21, 2022, 8:07pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/8 "2022-09-21T20:07:55Z")

</div>

> [@indubhushan](#):
>
> as for not adding after "\_acme-challenge" a domain name - it is automatically added, i cannot change it. it is not editable in plesk.

If you control your domain name, you can change it / delete it.  
And that entry should be deleted - it serves no purpose.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [September 22, 2022, 7:30am UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/9 "2022-09-22T07:30:28Z")

</div>

> [@indubhushan](#):
>
> i think I don't really require wildcards (\*), so yes, I unchecked it, and now it works, thank you.

To understand why this makes a difference here, you can also see the documentation at

> **[Challenge Types - Let's Encrypt](https://letsencrypt.org/docs/challenge-types/)**
>
> When you get a certificate from Let’s Encrypt, our servers validate that you control the domain names in that certificate using “challenges,” as defined by the ACME standard. Most of the time, this validation is handled automatically by your ACME...

(explaining the different kinds of things that need to be done, under Let's Encrypt policy, to prove ownership of a domain name for wildcard vs. non-wildcard certificates)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 22, 2022, 3:45pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/10 "2022-09-22T15:45:43Z")

</div>

> [@schoen](#):
>
> under Let's Encrypt policy

The baseline requirements also require a DNS challenge for wildcard certs nowadays, so it's not _just_ LE policy 😉

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [September 22, 2022, 4:56pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/11 "2022-09-22T16:56:31Z")

</div>

Oh, I didn't realize that!

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 22, 2022, 5:02pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/12 "2022-09-22T17:02:14Z")

</div>

In effect since December 2021:

> 2021‐12‐01  
> 3.2.2.4  
> CAs MUST NOT use methods 3.2.2.4.6, 3.2.2.4.18, or 3.2.2.4.19 to issue wildcard certificates or with Authorization Domain Names other than the FQDN.

3.2.2.4.6 = "Agreed‑Upon Change to Website" (not ACME)  
3.2.2.4.18 = "Agreed‑Upon Change to Website v2" (also not ACME)  
3.2.2.4.19 = "Agreed‑Upon Change to Website ‑ ACME" (well, ACME obviously 😛)

That said, the BR offer enough other challenges that allow wildcard certs, but ACME doesn't implement them. So with ACME, only the `dns-01` challenge is usable for wildcard certs, enforced by the BR. 🙂 [All CAs that voted, voted in favor of this change (n=22) as wel as all browsers/client vendors that voted (n=5)](https://cabforum.org/2021/06/03/ballot-sc45-wildcard-domain-validation/).

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 22, 2022, 5:02pm UTC](https://community.letsencrypt.org/t/error-issuing-certificate-when-domain-and-hosting-for-this-domain-are-from-different-companies/184862/13 "2022-10-22T17:02:31Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
